As the Department of Defense reviews potential reforms to the Cybersecurity Maturity Model Certification (CMMC) program, industry stakeholders continue to identify inconsistent and unclear marking of Controlled Unclassified Information (CUI) as a significant driver of compliance costs and confusion.
In comments submitted to the CMMC Reform Task Force, organizations cited uncertainty around CUI identification, over-marking, and inconsistent flow-down requirements as challenges that can force contractors, particularly small businesses, to implement unnecessarily broad cybersecurity controls. The Task Force is expected to submit recommendations to the DoD Office of the Chief Information Officer in the coming weeks.
McCarter partner Alexander Major noted that greater clarity around how CUI is defined in contracts could help businesses more accurately scope CMMC assessments and control compliance costs. In speaking with Federal News Network, Alex explained that a proposed Governmentwide CUI acquisition rule could also help address uncertainty surrounding CUI identification and handling requirements.
“It at least allows the conversation to start, ‘Wait, what are you expecting to send to me? How are you expecting to send it to me?’ And then allows contractors to ask the question, ‘What type of CUI are you sending me?’ That is something we’ve been trying to encourage clients to do for quite some time now,” he said.
