CMMC’s CUI Problem: Cybersecurity Compliance Begins With Knowing What Information Must Be Protected

The Department’s current review of the Cybersecurity Maturity Model Certification program is exposing a problem that sits upstream of cybersecurity certification itself: contractors cannot reliably scope CMMC obligations if the Government does not reliably identify the information requiring protection.

Reporting by Justin Doubleday of Federal News Network describes substantial industry concern over inconsistent identification and marking of Controlled Unclassified Information, or CUI. Organizations responding to the CMMC Reform Task Force have argued that uncertain CUI boundaries can cause contractors to include more systems, users, facilities, and subcontractors within their compliance environments than may actually be necessary. That can materially increase the cost and complexity of CMMC, particularly for smaller businesses.

The concern is supported by government oversight. In a January 2026 management advisory, the DoD Inspector General reported recurring deficiencies in CUI marking. Reviews encompassing more than 48,000 documents from 2023 and 26,000 from 2024 found that required CUI designation indicator blocks were absent from 9 percent of reviewed documents in 2023 and 11 percent in 2024. Additional documents contained incomplete designation information. The Inspector General also found circumstances in which dissemination controls may have been applied more restrictively than necessary.

That matters because CMMC follows the information. If a contractor processes, stores, or transmits CUI, the cybersecurity requirements associated with that information can determine which systems fall within the compliance boundary and, consequently, the expense of protecting and assessing those systems. Ambiguous CUI identification therefore does not remain an internal government records-management problem. It becomes a contractor architecture, pricing, subcontracting, and compliance problem.

The Department’s July 13 decision to suspend advancement to CMMC Phase II gives it an opportunity to address the issue. Phase I self-assessment requirements remain in effect, however, and the Department has expressly stated that the suspension does not eliminate contractors’ existing obligations to protect covered information under DFARS 252.204-7012. The distinction is critical: certification reform is underway, but underlying cybersecurity obligations have not disappeared.

Industry recommendations reveal substantial agreement about the problem. The Professional Services Council has urged greater consistency in how CUI is identified, marked, and flowed down so contractors are not forced to guess what requires protection. PSC has also argued for reducing documentation burdens while preserving substantive cybersecurity protections. Other industry commenters have similarly questioned blanket Level 2 flow-downs to subcontractors that may never receive or handle CUI.

For contractors, that should change the compliance conversation. The question is not simply, “Do we have CMMC?” Contractors should also ask what information a particular contract will require them to protect, where that information will reside, which employees will access it, and which subcontractors will receive it. Those questions belong in solicitation review, contract formation, system scoping, and subcontract flow-down analysis.

CMMC can evaluate whether cybersecurity controls operate effectively. It cannot, by itself, correct an improperly defined information boundary. The current reform effort therefore presents an important opportunity to distinguish the genuine cost of meaningful cybersecurity from avoidable cost created by uncertain CUI identification. Contractors, meanwhile, should continue satisfying existing safeguarding obligations while documenting CUI assumptions and promptly raising unclear contract requirements with their contracting officers.

If the Department wants a CMMC program that is both secure and economically sustainable, clearer CUI identification may be one of the most consequential reforms available.

Recommended FedContractPros Tool: FedClause360 — useful for identifying and organizing cybersecurity clauses, DFARS requirements, information-protection obligations, and subcontract flow-downs before those requirements become operational compliance problems. Clause analysis should complement, not replace, technical cybersecurity and CMMC assessment.

Disclaimer:
This article is provided for general informational and educational purposes only and does not constitute legal, cybersecurity, or CMMC compliance advice. CMMC, CUI, DFARS, NIST, and subcontract flow-down requirements depend on the applicable solicitation, contract, information involved, system architecture, and current regulatory guidance.

Previous
Previous

SBA’s Proposed Size-Standard Overhaul Could Reshape Small-Business Competition

Next
Next

AbilityOne Scrutiny Signals a Broader Shift Toward Auditable Domestic-Sourcing Compliance