cmmctrade-pressNewsThe Broadside2 min read

NDIA: DoD's own CUI marking failures drive CMMC costs

The comment-period pause gives industry a rare opening to name the Pentagon's own CUI marking failures as the hidden cost driver in CMMC, not contractor immaturity.


TL;DR

NDIA told DoD during the CMMC reform comment window that inconsistent Pentagon CUI marking is the root cause of compliance costs running $100K to $5M+ for individual contractors. Nearly half of NDIA's survey respondents spent over $100,000 implementing NIST 800-171, costs that can't be amortized across contracts for small firms. The filing names what contractors have said quietly for years: you can't protect information the government itself can't consistently label.

NDIA: DoD's own CUI marking failures drive CMMC costs
Editorial illustration · drawn by The Broadside

The National Defense Industrial Association used DoD's rare CMMC reform comment window to deliver an uncomfortable message: the Pentagon's own inconsistent CUI marking practices are a primary driver of the compliance costs the program was designed to address, and no amount of contractor investment will fix a system where the government can't reliably identify what needs protecting.

NDIA's August 14 filing responds to DoD's July 13 RFI, issued alongside the pause of CMMC phase two implementation. That pause (and the CMMC Reform Task Force now reviewing the program) gives industry a rare opening to name the asymmetry at the heart of the framework: contractors are being assessed on their ability to protect CUI that DoD components mark inconsistently, ambiguously, or not at all.

The filing points to a 2022 GAO report that found DoD "was not fully compliant with CUI requirements across four areas," and a 2023 DoD Inspector General report documenting inconsistent CUI marking across DoD components. "Without addressing the underlying CUI program, the current inconsistent marking process will continue to lead to increased costs and burdens on industry and degraded security for Department information," NDIA wrote.

The costs aren't theoretical. NDIA's 2024 cyber survey found that nearly half of respondents spent more than $100,000 on NIST 800-171 implementation; 27.5% spent over $500,000; nearly 12% exceeded $2 million; and almost 5% passed $5 million in non-recurring costs. For small businesses with fewer contracts to spread costs across, the filing notes, these figures become "a competitive decision", not just a compliance one.

What NDIA wants

The filing's policy recommendations go beyond asking DoD to mark CUI more carefully. NDIA urges Congress to direct NARA to streamline CUI marking requirements and "re-focus CUI expenditure on securing IT systems, rather than on non-value-added, onerous markings." It also calls for tax credits and SBA-guaranteed loans for companies that can't afford cybersecurity investments, and backs a Senate NDAA provision that would create grants of up to $100,000 for small businesses to offset C3PAO assessment costs.

The root-cause question

Whether the task force addresses DoD's own CUI marking failures or produces reforms that place additional interpretive burden on contractors remains the central question. NDIA's filing makes clear industry's answer: fix the marking first, then assess the protection.


Published ·Deep Fathom

NDIA: DoD's own CUI marking failures drive CMMC costs — The Broadside