Updated
Updated · Federal News Network · Aug 19
DoD's 100-Category CUI System Drives CMMC Costs as Contractors Over-Scope Compliance
Updated
Updated · Federal News Network · Aug 19

DoD's 100-Category CUI System Drives CMMC Costs as Contractors Over-Scope Compliance

1 articles · Updated · Federal News Network · Aug 19

Summary

  • Industry comments to the CMMC Reform Task Force say DoD’s inconsistent marking of controlled unclassified information is a main driver of CMMC cost and confusion, especially for small contractors.
  • Small businesses often expand their compliance boundary to cover nearly all data when CUI is unclear, while primes also impose blanket Level 2 certification demands on subcontractors that may never handle CUI.
  • The Pentagon has already paused CMMC third-party assessment requirements over cost and compliance concerns, and groups including SBA Advocacy, NDIA and PSC urged clearer contract-level guidance, training and periodic reviews of legacy markings.
  • More than 100 CUI categories exist under the governmentwide program created in 2010, and audits including a DoD inspector general report this year have flagged both overmarking and failures to mark sensitive data.
  • The task force closed comments last week and is expected to deliver recommendations in about 1 month, with industry also watching a proposed governmentwide CUI acquisition rule for clearer scoping.

Insights

Could blanket cybersecurity mandates force essential small-business suppliers out of the defense industrial base before the rules are even fixed?
Is the Pentagon's habit of over-classifying everyday emails actually weakening national security by stretching contractor cyber defenses too thin?