CUI rules keep fracturing because the government isn't a business
Former GSA Administrator Emily Murphy says the push for commercial technology runs into procurement requirements that commercial buyers simply don't have.
TL;DR
Former GSA Administrator Emily Murphy told Federal News Network the government's push for commercial technology keeps colliding with the reality that agencies aren't commercial buyers. The fractured CUI landscape illustrates the problem: NIST publishes one standard, but DoD spent a decade building CMMC around it while GSA issued its own procedural guide and the FAR Council's government-wide rule remains unfinished. "We always say we want the government to act more like a business, but at the end of the day, the government isn't a business," Murphy said. The protest rights, cyber requirements, and socioeconomic rules that distinguish federal procurement aren't temporary.
The interview, conducted by Federal News Network's Terry Gerton, pressed Murphy on whether the government genuinely wants to buy technology the way commercial buyers do. Her answer was careful: "Yes, to a point." The government's unique requirements (cybersecurity obligations, trade policy constraints, small-business set-asides, and a protest system that lets losing bidders challenge awards in court) mean the commercial analogy has a hard ceiling.
The CUI rules put that ceiling in sharp relief. NIST Special Publication 800-171 provides the technical standard for protecting controlled unclassified information. But implementation has fractured along agency lines. DoD developed CMMC over roughly a decade, only to see the program placed on temporary hold. GSA released its own IT security procedural guide in January 2026, keyed to a different revision of the NIST standard than CMMC uses, catching industry off guard.1 The FAR Council proposed a government-wide CUI rule in January 2025, but the rulemaking hasn't concluded.2 A DoD inspector general advisory in April 2026 found that nearly half of reviewed CUI documents lacked required designation indicators and 70% used outdated labels, suggesting the marking problem is as unresolved as the contracting problem.3
Murphy's framing doesn't offer a fix. It names the structural tension: the government wants the speed and innovation of commercial markets but operates inside a procurement system designed for accountability, not speed. Contractors caught between DoD's CMMC and GSA's separate guide (with the FAR Council's rule still unfinished) aren't facing a temporary glitch. They're facing the cost of doing business with a buyer that isn't one.
Footnotes #
-
https://federalnewsnetwork.com/acquisition-policy/2026/03/gsas-cmmc-like-rules-raise-concerns-in-industry/ ↩
-
https://federalnewsnetwork.com/contracting/2026/07/a-proposed-far-rule-is-trying-to-fix-one-of-the-governments-most-persistent-data-problems/ ↩
-
https://federalnewsnetwork.com/defense-news/2026/04/dod-still-failing-to-properly-mark-cui-data-years-after-initial-audit/ ↩
Published ·Updated ·Deep Fathom