I would suspect this is probably intentional, as it's difficult to imagine otherwise why this would be omitted in the latest standard.
The US probably wants the operational capability to spoof the civilian GPS; and signing would provide verifiable attributability.
If there are covert operations going on somewhere in the world, where the US isn't publicly claiming to be (and I don't just mean DoD; but also CIA for example); this would be an irrefutable cryptographic trail.
Another case is unintended collateral damage; e.g. say a civilian airliner (with US citizens perhaps) goes down; the US can't have plausible deniability and suggest it was the enemy doing it.
No, it isn't. Not unless you intentionally design the protocol to be vulnerable to replay attacks.