While there are differing opinions about how the Pentagon could improve the Cybersecurity Maturity Model Certification program, most organizations agree the Defense Department’s inconsistent and unclear process for marking controlled unclassified information continues to be a critical problem driving CMMC costs and confusion. In comments filed to the CMMC Reform Task Force, multiple industry groups highlighted CUI identification and marking as one of the main cost drivers of the cyber evaluation program. The Pentagon has paused CMMC third-party assessment requirements to address cost and compliance concerns, especially for small businesses. CUI is sensitive government data that doesn’t meet strict criteria for national security classification, but still requires special protection and handling controls under federal laws or policies. CMMC is intended to verify whether contractors are protecting CUI in line with federal cyber standards. But industry organizations say both DoD and prime contractors often improperly mark CUI or apply blanket CMMC requirements across subcontractors, regardless of whether companies will handle CUI. They say that in turn requires companies, including smaller firms, to unnecessarily comply with costlier CMMC standards. The Office of Advocacy, an independent organization within the Small Business Administration, highlighted CUI uncertainty as the “most frequently cited concern” for small businesses when it comes to CMMC. “This uncertainty has downstream consequences,” Advocacy wrote in reply to the CMMC Reform Task Force’s request for information. “When a contractor cannot confidently determine what information is CUI, they will generally err on the side of including all of it into their compliance boundary. Small businesses expressed numerous times that CUI is being overmarked, inconsistently marked, or improperly flowed down through the supply chain.” The office said DoD in some cases has even treated publicly available information as CUI. Likewise, the National Defense Industrial Association said its members have identified “multiple instances where inconsistencies,