CMMC's First Step Is Broken — The Pentagon Still Can't Mark Its Own Data
CMMC’s real problem sits one step before the certification. The Cybersecurity Maturity Model Certification exists to verify that defense contractors and subcontractors protect Controlled Unclassified Information and Federal Contract Information to NIST SP 800-171 standards. Verification only matters if the thing being protected is clearly defined. For a decade, the Pentagon has not been able to say, on any given document, what is CUI and what is not. Every cost CMMC is accused of imposing on the defense industrial base, the enclaves, the assessor fees, the blanket flow-downs to subcontractors, traces back to a contractor who cannot tell where the CUI boundary is.
The CMMC Reform Task Force, convened after the Pentagon (formally the Department of War since this year) suspended Phase 2 third-party assessments on July 13, closed its public comment window on August 14 and now has until roughly mid-September to deliver recommendations to the department’s CIO. Reading the comment letters, the alignment is hard to miss. The Small Business Administration’s Office of Advocacy called uncertainty over what constitutes CUI “the most frequently cited concern” from small businesses. NDIA flagged “multiple instances where inconsistencies, ambiguities and inaccuracies” in CUI marking. The Professional Services Council said inconsistent marking is “creating confusion about what requires protection.” The Alliance for Digital Innovation said primes impose blanket Level 2 flow-downs on every subcontractor, including machine shops that never touch CUI, because primes “default to over-inclusion to avoid audit liability.” The NDIA and Alliance positions are reported by Federal News Network; I could not pull the primary letters directly.
The consensus is narrower than it looks, and I want to be careful not to overstate it. Nobody is asking to gut the certification. PSC’s stated priority is to “bring greater clarity and consistency to how CUI is identified, marked, and flowed down”, and its position is that “the solution is to improve execution, not to postpone or weaken the requirements”. The complaint is about the input, not the machinery. You cannot build a cheaper CMMC on top of an undefined data boundary and expect the cost to match the risk.
The inspector general already proved it
The contractors are not being hypothetical. Two inspector general reports, an audit in 2023 and a management advisory in February 2026, document the same failure from the inside. In 2023 the IG found that 48% of a nonstatistical sample of documents containing CUI did not include the required designation indicator block. Of 40 recurring document types from the same originator supporting the same operation, 28, or 70%, had no designation block or still carried the “For Official Use Only” label, a marking retired more than a decade ago. The department’s own CUI program office claimed only 9% of documents were missing the block in 2023 and 11% in 2024. The IG read that self-reported figure as “minor deficiencies” and called the real problem “more pervasive”.
I am presenting both numbers because the gap between them is the finding. A self-reported metric of 9 to 11% and an independent sample at 48% means the department’s own count is measuring something different from what an auditor finds when it opens the drawers.
The February 2026 advisory found the department frequently fails to mark CUI correctly, and that when it does mark it, it “may have unintentionally restricted dissemination by defaulting” to “Federal Employees and Contractors Only (FEDCON)” or “Federal Employees Only (FED ONLY)” rather than leaving dissemination unrestricted. The IG traced that partly to “conflicting and insufficient” guidance and training, including website guidance that contradicted itself on whether those markings permit sharing with Congress. The advisory surfaced during the IG’s review of then-Defense Secretary Pete Hegseth’s use of the Signal messaging app, which raised broader questions about how components mark CUI.
The audit and the advisory both came with recommendations, and the follow-through is the part worth watching. The 2023 audit made 14 recommendations; as of April 2026, eight were closed and six remained open. The 2026 advisory made five; two were closed and three were resolved-but-open at publication. A program that has generated a decade of findings and still has half of its oldest recommendations open is a management problem, not a technical one.
A decade of failing the same instruction
The CUI program itself was an attempt to fix this. Executive Order 13556, signed in November 2010, created the governmentwide CUI framework to replace what it called an “inefficient, confusing patchwork” of agency markings. The order’s instruction was direct: “if there is significant doubt about whether information should be designated as CUI, it shall not be so designated.” That is a when-in-doubt-don’t-mark standard. The inspector general’s findings suggest the department has spent the years since doing roughly the opposite, over-marking and then over-restricting what it marked.
The registry that defines CUI does not make this easy. NARA’s CUI Registry lists more than 100 categories across roughly 20 groupings, from defense controlled technical information to proprietary business information, law enforcement, tax, and nuclear. Sandeep Kathuria of Saul Ewing made the point that consolidation is the fix: “If you get it to a manageable number, people can actually apply it consistently.” Alex Major of McCarter & English described the practical result, that department officials include default CUI markings in email headers and footers “regardless of whether a particular message carries such data,” because they are not able or willing to tie the data to a specific law or regulation.
Over-marking is a cost, not a minor annoyance
None of this is abstract for the businesses on the other end. The Advocacy office put the cost numbers next to the marking problem. Level 1 self-assessment runs about $5,977 a year, against $101,752 for a Level 2 certification by a third-party assessor every three years. A contractor who cannot tell whether CUI is in scope has to assume it is, and that assumption is expensive. Advocacy’s recommendation was to make the department “identify the anticipated CUI categories, markings, data flows, systems, deliverables, and other activities involving CUI before imposing CMMC requirements on a contractor,” because “no small business should have to build and price expensive cybersecurity architecture around an undefined category of information.”
Kate Growley of Crowell & Moring put the mechanism in one line: “CMMC follows the data. If CUI is being over- or under-scoped, so will the scope of CMMC.” Michael Lowell of Reed Smith described the downstream effect, that contractors “tend to protect more information, systems and people than may actually be necessary,” which “increases the cost and complexity of CMMC, particularly for small businesses, without necessarily producing a corresponding cybersecurity benefit.” Bill Greenwalt of the American Enterprise Institute was blunter, calling CUI “completely out of control” and saying it is “already costing the government and industry billions a year to comply with it just through the CMMC process.”
The base is shrinking while this drags on. Small-business prime contractors working with the department fell from 43,621 in 2014 to 29,584 in 2024, a 32% decline. I am not attributing all of that to CUI marking. But a compliance regime whose first input is undefined will keep pushing the smallest contractors, the ones with the least margin to absorb over-scoping, out of the base.
What September actually tests
The task force’s recommendations land in mid-September, and they are not public yet. Anything I say about what they will contain is a forecast, not a fact. The volume and unanimity of the comment letters still make one thing likely: the recommendations will have to say something about CUI identification and marking, because that is what almost every respondent spent their words on.
There is one development that could blunt the problem before the task force even reports. A long-awaited governmentwide CUI acquisition rule was proposed June 23 as part of a broader Federal Acquisition Regulation overhaul, and experts say it could help clarify CUI scope at the contract level. That is the right place to fix it, at the point where a specific contract says what specific data is covered, rather than at the level of a registry with more than 100 categories.
Here is the test I will apply when the recommendations come out. Do they change how CUI is identified, marked, and flowed down before a contractor has to decide what to protect, or do they just make the certification cheaper and call it reform? Cheaper on top of an undefined boundary relocates the over-scoping. It does not remove it.
Bottom line
CMMC’s first input is broken, and it has been broken since before CMMC existed. Two inspector general reports and a near-unanimous set of comment letters say the same thing: the Pentagon cannot reliably mark its own CUI, and contractors pay for that failure in over-built enclaves and over-broad flow-downs. The task force’s September recommendations are the department’s chance to fix the input before it reworks the machine. PSC is right that the answer is execution, not weakening. Execution on a decade-old marking failure is a specific, boring, administrative job, and it is the one that determines whether a reformed CMMC costs what the risk actually justifies.
Sources
- CMMC review: DoD’s inconsistent CUI marking continues to plague program — Federal News Network, Justin Doubleday, Aug. 19, 2026
- With CMMC Comment Period Ending, What Happens Next for Defense Contractors? — ClearanceJobs, Peter Suciu, Aug. 17, 2026
- Reforming CMMC and Reducing Compliance Burden for the DIB — SBA Office of Advocacy comment letter, Aug. 14, 2026 (PDF)
- PSC Submits Comments to Dept. of War on CMMC Reform — Professional Services Council press release, Aug. 17, 2026
- DoD still failing to properly mark CUI data years after initial audit — Federal News Network, Anastasia Obis, Apr. 2, 2026
- Management Advisory DODIG-2026-047: DoD Policy and Training on Dissemination Controls for CUI — DoD Office of Inspector General, Feb. 4, 2026 (PDF)
- Audit DODIG-2023-078: Audit of the DoD’s Implementation and Oversight of the CUI Program — DoD Office of Inspector General, June 1, 2023 (PDF)
- Executive Order 13556: Controlled Unclassified Information — Nov. 4, 2010
- CUI Registry Category List — National Archives and Records Administration
- PSC Comments on CMMC Review RFI — Professional Services Council, Aug. 14, 2026
- Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul — Federal Register, June 23, 2026