CMMC review: DoD’s inconsistent CUI marking continues to plague program
The US Department of Defense's (DoD) inconsistent marking of Controlled Unclassified Information (CUI) continues to be a major issue for the Cybersecurity Maturity Model Certification (CMMC) program. This inconsistency is causing problems for contractors and assessors, leading to contract cancellations and layoffs. The issue has been ongoing, and despite efforts to address it, the DoD has not yet found a solution.
Listen to Live Briefing
Real-time synthesized voice briefing · Live Feeds Desk
- ✓ DoD's inconsistent CUI marking continues to plague the CMMC program
- ✓ Contract cancellations and layoffs have resulted from the CMMC pause
- ✓ Defense contractors' self-reported cybersecurity scores are rising
- ✓ Confidence in the accuracy of cybersecurity scores has plunged 24 points
What changed
The DoD's inconsistent CUI marking has led to a pause in the CMMC program, resulting in contract cancellations and layoffs.
Live updates
-
DoD's inconsistent CUI marking plagues CMMC program
The US Department of Defense's (DoD) inconsistent marking of Controlled Unclassified Information (CUI) continues to be a major issue for the Cybersecurity Maturity Model Certification (CMMC) program. This inconsistency is causing problems for contractors and assessors, leading to contract cancellations and layoffs. The issue has been ongoing, and despite efforts to address it, the DoD has not yet found a solution.
Why it matters
The CMMC program is a critical component of the DoD's efforts to improve the cybersecurity of its supply chain. The program requires contractors to demonstrate their cybersecurity capabilities through a series of assessments. However, the inconsistent marking of CUI is making it difficult for contractors to accurately assess their cybersecurity capabilities and for assessors to evaluate them.
What is confirmed
- DoD's inconsistent CUI marking continues to plague the CMMC program
- Contract cancellations and layoffs have resulted from the CMMC pause
- Defense contractors' self-reported cybersecurity scores are rising
- Confidence in the accuracy of cybersecurity scores has plunged 24 points
Still unconfirmed
- The DoD has not yet found a solution to the CUI marking issue
What to watch next
- DoD's plan to address the CUI marking issue
- Impact of the CMMC pause on contractors and the supply chain
- Progress on implementing a solution to the CUI marking issue
confidence 85%Sources used for this update (5)
- Federal News Network — CMMC review: DoD’s inconsistent CUI marking continues to plague program
- National Defense Magazine — JUST IN: Assessors Report Contract Cancellations, Layoffs After CMMC Pause
- Nextgov/FCW — CMMC Works. Now let’s sharpen it.
- Business Wire — New Report Shows Defense Contractors’ Self-Reported Cybersecurity Scores Are Rising as Confidence in Their Accuracy Plunges 24 Points
- BankInfoSecurity — DoD Regulatory Pause: No Excuse to Weaken Supply Chain Trust
Community Sentiment: How do you assess this situation?
Voice your perspective · Real-time aggregated sentiment from the Live Feeds community