In August 2026, LIFT responded to the Department of War CMMC Reform Task Force's request for information on reducing the compliance burden on the defense industrial base. Our response comes from the shop floor: a seven-person, AS9100-certified Long Island precision manufacturer that builds flight-critical parts for the F-16, C-130, and F-35, handles Controlled Unclassified Information every day, and lives the CMMC compliance problem firsthand. Its central proposal: let small manufacturers demonstrate compliance by adopting pre-approved reference designs — exactly the way the aircraft parts they machine are already certified.
For a seven-person shop, those figures mean the same compliance infrastructure demanded of a company ten times its size, purchased to protect a handful of endpoints — plus a perpetual "subscription tax" as the path of least resistance pushes small firms into rented cloud ecosystems, plus consultants to author documentation the owner cannot staff internally, plus an assessor queue that turns schedule uncertainty into contract risk. And one comparison from our own experience cuts through all of it:
Replacing our entire IT infrastructure — both mail servers, every hardwired drop, every office and shop-floor computer — would cost substantially less than a single third-party assessment cycle. "When assessing a system costs more than building the secure system itself, the burden has plainly detached from the security it is meant to deliver."
The structural flaw is that every small contractor must independently design, document, implement, and separately certify a unique compliance architecture — and then pay to have that one-off evaluated against 320 objectives. Complexity itself becomes the vulnerability: the common settings on a single small-business firewall print out at twenty pages of rules, and no one — not the owner, often not the consultant — can say which line someone once added to "make something work" that quietly opened a hole. The costs scale with the uniqueness of the architecture; the security does not.
We do not independently invent and separately certify a unique design for every flight-critical part; we certify parts to an approved design. Medical devices and listed electrical equipment work the same way. CUI infrastructure should too: adopt a pre-approved, system-level reference design that meets or exceeds NIST SP 800-171, and demonstrate compliance by verifying conformance to the design — not by commissioning a fresh six-figure evaluation of a one-off. The assessment question collapses from "evaluate this unique system against 320 objectives" to "confirm this contractor is using the approved design as issued." The hard engineering is done once, reviewed once, and adopted many times. It requires no new legislation — it is adoptable as NIST and Department guidance — and it directly lowers the barrier to entry: a new firm can join the defense industrial base by adopting an approved design instead of funding a compliance project before its first bid.
A tiered secure-subnet architecture puts the guarantee the Department actually cares about — that CUI cannot escape — at the boundary of the enclave, not on every file, tool, and program inside it. The practical payoff is real: a machinist who writes a useful program at home can run it inside the enclave without a ten-day code review, because protection lives at the perimeter. Pair that with a preference for simple, fixed-function security hardware over hand-configured complexity — "a device that cannot be reconfigured cannot be misconfigured" — and with trust-zone boundaries an assessor can verify by walking the facility, and verification becomes fast, cheap, and honest.
The response also offers reforms available inside the Task Force's 60-day window: recognize a controlled, air-gapped small-business enclave — a single designated custodian moving CUI on encrypted media under a simple log, the certified-mail model in physical form — as presumptively compliant; accept the free cybersecurity training DoD already funds (Cyber Awareness Challenge, Project Spectrum) as satisfying the awareness controls; put ground-based, on-premises designs on equal footing with cloud subscriptions; and establish a good-faith safe harbor so a small firm that adopts an approved design and self-attests honestly is not taking on False Claims Act risk. The reference designs are engineering, not research — and LIFT's submission offers them in the public interest, developed with no federal funding.
The full response — submitted August 14, 2026 to the CMMC Reform Task Force, Office of the DoD Chief Information Officer, Department of War, answering all seven RFI questions from direct Tier 2/3 supplier experience — is available here:
Our position in one sentence: stop making every small shop invent and separately certify its own security architecture — approve good designs once, let firms certify by conformance, and small manufacturers stay in the fight while security actually improves.