cmmctrade-pressNewsThe Broadside2 min read

ITI pushes DOD to accept FedRAMP controls under CMMC

Reciprocity would end the wasteful re-auditing of controls FedRAMP already validated; the AI fast-track is a separate ask entirely.


TL;DR

ITI urged DOD to establish formal FedRAMP-CMMC reciprocity in comments filed during the Phase Two pause, arguing that re-auditing controls already validated under FedRAMP produces "duplicative cost without a proportionate increase in security." The filing proposes a "commercial solutions equivalency" pathway where contractors inherit platform-level FedRAMP assurances rather than re-certifying per project. DOD already recognized FedRAMP Moderate equivalency for cloud providers handling CUI in a January 2024 memo, ITI wants that extended to commercial software platforms broadly and codified in a common control matrix.

ITI's core argument is one compliance directors have been making for years: if a control has been assessed under one NIST-derived framework, re-assessing it under another doesn't improve security, it just burns money. The filing points to certifications like ISO 27001, SOC 2, and CSA STAR Level 2 that overlap with CMMC requirements, and argues DOD should publish a common control matrix so assessments focus on the delta rather than "re-litigating overlaps organization by organization."

DOD has already moved partway down this road. A January 2024 memo established that a FedRAMP Moderate baseline for cloud service offerings could help contractors meet CMMC requirements, but only for CSPs storing, processing, or transmitting CUI. ITI wants that recognition extended to any platform meeting the FedRAMP Moderate baseline, and wants it formalized as true reciprocity rather than case-by-case equivalency. The current setup means a DIB company using a FedRAMP-authorized platform still has to document and certify that platform's controls independently, project by project. That's exactly the kind of duplication that turns compliance into overhead rather than security.

The filing also proposes transitioning CMMC to NIST SP 800-171 Revision 3, which would align the program with NIST SP 800-53 Revision 5 and reduce the dual-framework burden on organizations operating in both defense and civilian federal spaces. That transition is already in DOD's pipeline via a separate rulemaking; ITI's recommendation here is more endorsement than novel proposal.

Then there's the AI section. ITI wants the Reform Task Force to "explicitly account for AI-assisted and agentic software development tools," create a 90-day expedited authorization pathway for AI-driven defensive capabilities, and formally recognize AI-assisted continuous monitoring outputs as valid compliance evidence. These are substantial asks (a 90-day authorization timeline would be radically faster than the current 18-to-36-month window) and they feel like a separate policy submission that found its way into a CMMC reform filing. The arguments about adversarial speed are real, but the CMMC Reform Task Force wasn't stood up to solve AI authorization. The reciprocity recommendations stand on their own; the AI section reads like ITI making sure the ask is in the record while the window is open.


Published ·Updated ·Deep Fathom