EDUCAUSE responded to a July 2026 Department of Defense (DoD) request for information on a task force review of the Cybersecurity Maturity Model Certification program. EDUCAUSE emphasized that more flexible cybersecurity requirements would facilitate institutional compliance and called for greater institutional access to DoD compliance experts and resources.
In mid-July, the U.S. Department of Defense (DoD) announced two actions aimed at easing the compliance burden associated with the Cybersecurity Maturity Model Certification (CMMC) program:
- Suspension of the November 2026 deadline by which institutions would have to have third-party certification of their compliance with CMMC Level 2 requirements, which track with the NIST SP 800-171 controlled unclassified information (CUI) cybersecurity standards.
- Launch of a task force to review the CMMC program and make recommendations for reducing the cost and administrative burden that its mandates present for Defense Industrial Base (DIB) entities, particularly small, midsized, and nontraditional organizations.Footnote1
To help the task force with its work, the department posted a request for information (RFI) inviting stakeholder feedback on ways to improve the CMMC program and cybersecurity among DIB participants more generally.Footnote2 EDUCAUSE organized a working group of Regulated Information Security Compliance (RISC) Community Group members to inform the association's response to the CMMC program review and submitted public comments regarding the RFI on August 14, 2026.
The EDUCAUSE submission emphasized the uniqueness of higher education institutions as DIB participants compared to traditional defense contractors. Unlike standard corporate facilities, colleges and universities often conduct DoD-sponsored research in relatively open, multiuse facilities where teaching and learning occur alongside a variety of fundamental and applied research activities. Likewise, the projects themselves may regularly involve one or more collaborative relationships, both within and between disciplines, institutions, and even countries. Thus, EDUCAUSE stressed that revisiting CMMC requirements provides the DoD with the opportunity to consider more flexible approaches to promoting cybersecurity and compliance that would allow higher education institutions to better fit DoD requirements into nontraditional environments.
EDUCAUSE also noted that the DoD announcement seemed to imply that the department might move away from third-party certification of NIST 800-171 compliance toward greater reliance on self-assessment backed by False Claims Act enforcement. Should that ultimately be the case, it would free institutions from a significant documentation and assessment process burden, but it would not relieve the costs of implementing and maintaining 800-171 in academic research contexts. Furthermore, it would introduce considerable litigation risk, even for institutions diligently trying to comply. With that in mind, we asked the DoD to incorporate into its cybersecurity requirements "a safe harbor for good-faith compliance efforts where organizations have followed published guidance and documented reasonable due diligence."Footnote3
While our comments discussed several areas in which the CMMC program and NIST SP 800-171 controls create undue burdens on colleges and universities, one key overarching theme was that the costs of managing and documenting compliance with program requirements often outweigh the costs of implementing and maintaining security measures themselves. In particular, we noted that reducing the administrative overhead of DoD cybersecurity requirements would likely improve cybersecurity:
Institutions must sustain a variety of systems security plans (SSPs), plans of action and milestones (POA&Ms), overlapping policies and procedures, and ongoing evidence gathering and audit preparation. Streamlining these requirements to limit administrative overhead would allow institutions to reallocate resources to reduce cybersecurity risk.Footnote4
Thanks to extensive analysis by the working group, the EDUCAUSE response provides a detailed list of NIST SP 800-171, Revision 2 (800-171r2), controls that should be revised or reconsidered. In many cases, the identified controls fail to account for the extent to which many DIB participants, particularly small- to midsized and nontraditional entities, rely on cloud services for their information systems and related cybersecurity needs. In those contexts, controls that assume direct, on-premises management of systems and associated technology impose requirements that covered entities either cannot meet or should not realistically have to satisfy, particularly when the relevant information and documentation could be, or may have to be, forwarded from the provider. With other controls, the degree to which small entities may lack the staff and internal expertise to identify and modify specific measures and therefore rely on software or platform provider default settings for software, system, or platform security is not taken into account. As a result, these controls can impose unrealistic expectations and potentially unmanageable burdens on affected organizations. In our comments, we argued that the DoD should modify its cybersecurity requirements, either through changes to the CMMC program or other steps that the department may consider, to better fit contemporary methods of provisioning technology and services.Footnote5
In keeping with the review questions posed by the DoD, we concluded our RFI comments by identifying several ways the DoD could promote effective cybersecurity while reducing administrative overhead and associated costs that might discourage small, midsize, and nontraditional organizations from participating in DoD contracting. We again stressed that better training and support for DoD program and contracting officers in relation to CUI management, as well as fundamental research, would likely have a significant impact in reducing the misapplication of DoD cybersecurity requirements, saving the DoD and institutions a great deal of time and money. We particularly emphasized the value of the DoD taking proactive steps to prevent the inappropriate introduction of CUI security requirements into contracts and subcontracts that do not entail, and do not have a reasonable expectation of producing, CUI or federal contract information (FCI), the latter of which is the basis for CMMC Level 1 requirements.Footnote6
Additional recommendations include the following:
- The DoD should provide small, midsized, and nontraditional organizations with greater access to departmental compliance experts who can help them navigate DoD requirements in their unique contexts. Making available more knowledge resources on compliance that are contextualized for different major stakeholder categories, such as colleges and universities, would be very helpful.
- The department should also develop implementation models for its requirements that better align compliance mandates with risk management considerations, such as the type and size of the institution involved and the level of risk associated with the research being conducted.
- EDUCAUSE urged the DoD to engage directly with representatives of small, midsized, and nontraditional DIB participants to more strategically identify and pursue options for bolstering cybersecurity while minimizing administrative overhead. Similarly, the department should work with major categories of stakeholders to foster greater and more consistent threat intelligence sharing and cybersecurity collaboration.
- In establishing implementation timeframes for cybersecurity requirements, the DoD should ensure that it understands and takes into account the budgetary cycles and processes of stakeholders such as colleges and universities so that they can realistically meet the department's needs and expectations.Footnote7
The RFI for the CMMC program review process indicated that the DoD task force involved should complete its work by mid-September. With any luck, EDUCAUSE members as well as DIB participants in general will know more about DoD plans for CMMC and CUI/FCI cybersecurity by early October. In the meantime, the EDUCAUSE policy team will continue to watch for signs or official releases that will help colleges and universities understand what is coming next in terms of DoD cybersecurity mandates.
Notes
- U.S. Department of Defense, "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements," press release, July 13, 2026. Jump back to footnote 1 in the text.
- U.S. Department of Defense, "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base," request for information, July 13, 2026.Jump back to footnote 2 in the text.
- EDUCAUSE, letter to Leanne M. Condren, Contracting Officer, U.S. Department of Defense, "Reforming CMMC and Reducing Compliance Burden for the DIB (Notice ID: DoDCIOReformingCMMCforDIB001," August 14, 2026. Jump back to footnote 3 in the text
- Ibid., 2.Jump back to footnote 4 in the text.
- Ibid., 9.Jump back to footnote 5 in the text.
- Ibid.Jump back to footnote 6 in the text.
- Ibid., 8–10.Jump back to footnote 7 in the text.
Jarret Cummings is Senior Advisor, Policy and Government Relations at EDUCAUSE.
© 2026 EDUCAUSE. The content of this work is licensed under a Creative Commons BY-NC-ND 4.0 International License.