CMMC architect wants AI to sharpen CUI targeting
Katie Arrington says the standard shouldn't budge, but inconsistent CUI determinations across the defense industrial base are wasting money and leaving real exposure, and AI-assisted triage could fix the mismatch without touching the security bar.
TL;DR
Katie Arrington, who built the CMMC program, argues in a NextGov op-ed that the framework's requirements shouldn't loosen, but its targeting needs sharpening. CUI determinations remain inconsistent across the defense industrial base: some small businesses get assessed for data that isn't really CUI, while others handling sensitive material slide through with lighter requirements. Her fix: use AI to do first-pass sorting of contract language and CUI flow-down, with a human contracting officer making the final call. She also calls for a dedicated SBA loan program to fund cybersecurity investment at small businesses outside the defense supply chain.

Arrington's op-ed, published Monday in NextGov/FCW, is a notable landing point from the program's architect. She isn't asking for a rewrite ("The Defense Federal Acquisition Regulation Supplement requirements behind CMMC should not change, and I would not support it if they did") but she's naming a problem that anyone who's sat through a CUI scoping meeting already knows: the current manual process for determining what counts as controlled unclassified information produces different answers for similar contractors doing similar work.
The AI proposal is modest. Not autonomous classification, not automated assessment. "A human with contracting authority still makes the final call," she writes. "But that human should be working from a much better starting point than we give them now." The idea is first-pass triage: AI flags likely CUI from contract language and statements of work, catches mismatches between what a prime designates and what flows to subs, and surfaces inconsistencies. The human decides.
The split ask
Arrington divides the piece into two fronts. Inside the defense industrial base, sharpen CMMC scoping with AI-assisted CUI targeting. Outside it, build a dedicated SBA loan program for cybersecurity investment (multi-factor authentication rollouts, endpoint detection, incident response, early quantum-resistant encryption migration) available to every small business, not just defense contractors. "Training grants aren't capital," she notes, "and no amount of counseling gets a small manufacturer through a ransomware recovery."
The dual ask reflects her current role. Arrington left the CMMC program in 2021 after the Navy investigated her handling of a personal travel audit and her security clearance was suspended. She now runs a consultancy and sits on SBA's cybersecurity advisory board. The op-ed doesn't mention her departure from DoD.
The targeting critique lands at a practical moment. CMMC requirements are flowing into contracts, and the GAO flagged in March that DoD still hasn't fully assessed external factors that could impede implementation, including assessor availability. Inconsistent CUI scoping compounds that bottleneck: if the assessment burden doesn't match the actual data sensitivity, the program spends credibility and contractor dollars it can't afford to waste.
Published ·Deep Fathom