PSC
Comments on Reforming CMMC and Reducing Compliance Burden for the DIB
August 14,
2026 | By PSC Staff
On August 14,
2026, PSC submitted comments to the Department of War (DoW) in response
to its request for information (RFI) entitled, “Reforming CMMC and Reducing
Compliance Burden for the Defense Industrial Base (DIB).” The RFI sought industry
input to inform the Department’s review of the Cybersecurity Maturity Model
Certification (CMMC) Program, including ways to protect federal data and
strengthen operational resilience while reducing compliance costs and
administrative burdens.
PSC identified three overarching
priorities for CMMC reform: (1) establish a single, standardized
cybersecurity framework that is current and applies uniformly across defense
and civilian contractors; (2) reduce the cost and administrative burden
of demonstrating compliance without weakening implementation of cybersecurity
controls; and (3) move toward a risk-based CMMC model that recognizes
contractors’ existing investments in Level 2 certification. Click here to access PSC’s comments.