September 9, 2026
All Eyes Are On CUI
How interesting! Last week, the Office of the DoW Chief Information Officer posted on LinkedIn a summary of industry responses to the CMMC Reform RFI:
Industry stakeholders and defense leaders have identified government CUI designation and marking practices as a primary operational challenge for the defense supply chain.
Yep! I know that was a major theme of TNE’s comments. The single best way to reduce the compliance burden on small contractors is to stop both overmarking and the unnecessary flowdown of CUI.
This came two days after the Information Security Oversight Office (“ISOO”) – the org tasked with managing the CUI program for the federal government – issued a memo with updated guidance on CUI. After the general guidance on marking, safeguarding and personnel training, came an entire section on Contracts and Information-Sharing Agreements:
For all contracts requiring access to CUI, at a minimum, agencies must provide the prime contractor with specific guidance regarding the following:
- Identification of Specific Government-Furnished Information Designated as CUI;
- Process for identification of Contractor Developed Information as CUI;
- Process for CUI challenges;
- Training requirements and resources;
- Access requirements;
- Marking requirements;
- Safeguarding requirements;
- Decontrol and disposition requirements;
- Reporting requirements;
- Self-Inspection requirements;
- Process for reporting misuse of CUI; and
- Penalties for misuse of CUI.
The second bullet really caught my attention: Process for identification of Contractor Developed Information as CUI -- that is probably the biggest source of confusion for small contractors. Wouldn’t you love to have that clarified in your contracts?
Well, the 60-day review period is drawing to a close. Will the task force report be published? Probably a summary of it, is my guess. When will we know? Good question! What happens next? We’ll all find out together!
Meanwhile, DoD/DoW CIO has made it clear that all contractual obligations to protect both FCI and CUI remain in place. Keep working on those implementations and prepare for recording your self-assessment in SPRS. Need help? Reach out.
Sincerely,
Glenda R. Snodgrass, CCP/CCA/Lead CCA
grs@theneteffect.com
The Net Effect, LLC
www.theneteffect.com
251-433-0196 x107

