CUI is the most consequential four-letter acronym in defense contracting, and one of the most misunderstood. This guide explains what Controlled Unclassified Information actually is, how the marking rules work, who applies them, what handling and destruction require, and why getting this right decides whether your company keeps winning DoD work. If your contracts, your primes, or your file shares touch government information, this is the plain-English foundation your whole team should share.
Controlled Unclassified Information is government-created or government-owned information that requires safeguarding or dissemination controls under law, regulations, and government-wide policies, but is not classified. That definition comes straight from the program's founding documents: Executive Order 13556 established the CUI program in 2010, and 32 CFR Part 2002 turned it into binding rules, with the Information Security Oversight Office at the National Archives serving as the government-wide executive agent.
The category exists to fix a real problem. Before CUI, agencies used a zoo of homegrown labels — For Official Use Only, Sensitive But Unclassified, and dozens more — each with its own unwritten rules. Information that requires safeguarding was marked inconsistently, shared nervously, and protected unevenly, so the CUI program replaced the zoo with one system and one registry.
Here's the sentence worth repeating in every training session: CUI is sensitive, but it is not classified. It sits below classification: no clearances, no SCIFs. Access requires a lawful governmental purpose, a lower bar than classified need-to-know, but mishandling it still carries real consequences. Think of CUI as the government saying, "This won't endanger national security by itself, but you must protect it anyway, and here's exactly how."

Every category of CUI comes in one of two flavors, and the distinction drives your obligations. CUI Basic covers information where the underlying law or regulation says "protect this" without prescribing how. For CUI Basic, the program's uniform baseline applies: the standard handling, marking, and safeguarding rules of 32 CFR Part 2002, and, for contractors, the security requirements of NIST SP 800-171.
CUI Specified is the subset of CUI where the authority does spell out particular controls: specific handling procedures, additional access restrictions, or penalties written into the law itself. Export-controlled technical data is the classic example, since ITAR and EAR impose their own requirements on top of the baseline. In marking terms, Specified categories carry an "SP-" prefix, and the difference between CUI Basic and CUI Specified appears right in the banner.
The practical rule for compliance leads: treat CUI Basic or CUI Specified as a routing decision. Anyone can handle CUI Basic under your standard program controls; CUI Specified triggers a check of the specific authority's added rules before the file moves anywhere. Knowing which type of CUI you hold is the first question, not an afterthought.
The authoritative catalog is the ISOO CUI Registry at archives.gov, which lists every approved category across roughly twenty groupings, from procurement and privacy to export control and critical infrastructure. Only information falling within a registry category can be considered CUI, which cuts both ways: agencies can't invent labels, and contractors can't dismiss markings that map to real categories.
The Department of Defense maintains its own aligned catalog, the DoD CUI Registry, organized into indexes the defense world actually uses. The most common example of CUI in defense work is Controlled Technical Information: engineering drawings, specifications, and other technical data with military or space application. Procurement-sensitive information and export-controlled data round out the categories most DoD contractors see weekly.
A working tip from the field: build your own short list. Most companies encounter only a handful of the registry's categories, so identify CUI types your contracts actually generate, document them, and train to those. A two-page internal cheat sheet beats sending engineers to browse a federal registry every time a question comes up.
The design goal is uniformity. The CUI policy provides a uniform marking system across the federal government, so a marked file means the same thing at every agency and every contractor. CUI markings alert recipients to the presence of CUI in a document before they read a word of it, which is the entire point: protection travels with the information.
The CUI marking system has three moving parts. First, the CUI banner marking at the top of each page, beginning with "CUI" and optionally adding category and dissemination segments separated by double slashes, such as CUI//SP-CTI//NOFORN. Second, an optional portion scheme for paragraph-level granularity; once you portion-mark a document, every portion gets a mark. Third, the designation indicator, which we'll cover next, telling recipients who controlled the information and how to ask questions about it.
One legacy note that still trips people: old FOUO stamps are not CUI markings. Documents containing CUI need current marks under the current rules, and legacy-marked material gets remarked when it re-enters use. If your shared drives still hold a decade of FOUO, that's a cleanup project, not a technicality.
The banner is the headline. At minimum, "CUI" (or "CONTROLLED") appears at the top of every page; DoD practice commonly marks top and bottom. When categories are included, the CUI banner reads in a fixed order: control marking, then category codes, then limited dissemination controls, so a reader can parse CUI//SP-CTI//NOFORN at a glance: Specified controlled technical information, no foreign nationals.
The CUI designation indicator is the accountability block, and it's required on the first page of every marked document. Per the Department of Defense's Instruction 5200.48, it identifies who controlled the material ("Controlled by"), the category, the applicable dissemination or distribution statement, and a point of contact. That block is what lets a recipient two contracts downstream ask the right office whether the material can be shared, decontrolled, or released.
Emails, slides, and spreadsheets follow the same logic as documents: banner at top, indicator with the first transmission. The marking requirements are genuinely learnable in an afternoon, and consistency matters more than artistry. A plain, correct banner beats an elaborate wrong one every time.

The authorized holder who creates the material, at the moment of creation. That's the rule from the DoD instruction: whoever originates a document decides whether to treat the information as CUI, and if so, that person is responsible for applying CUI markings and dissemination instructions before it moves. This is not a security-office cleanup function; it's an authoring step.
For contractors, two flows matter. Inbound, the government should identify CUI it provides to you, typically through contract documents and the marks themselves; if material arrives unmarked but smells like CUI, ask the contracting officer in writing rather than guessing. Outbound and internal, anything your team creates that contains CUI — derived drawings, analysis, test data — inherits the obligation, and your people must mark CUI they generate just as a government author would.
This is why designation authority deserves a named owner inside your company. Someone has to answer "is this marked as CUI correctly?" in minutes, not weeks, and to keep the presence of CUI from silently spreading into folders where nobody is managing it. Most mid-sized defense contractors give that hat to the same person who owns their compliance program, which works when that person has real training and real authority.
Dissemination controls are the "who can see this" layer riding on top of the category. The registry defines a limited set, and the common ones do most of the work: NOFORN (no foreign nationals), FED ONLY (federal employees only), FEDCON (federal employees and contractors), REL TO (releasable to named countries), and DL ONLY (limited to a distribution list). DoD material frequently pairs CUI markings with distribution statements as well.
Two rules keep companies out of trouble. First, dissemination controls must come from the approved set and be justified by the underlying authority; a designator can't invent restrictions, and CUI may not be restricted simply because it's embarrassing or inconvenient. Second, controls bind everyone downstream: a NOFORN mark on a drawing means your foreign-national engineer can't be on that project's share, full stop, and access control lists have to reflect it.
Where this bites in practice is teaming. Before you forward CUI to a subcontractor or partner, confirm the recipient is within the marked dissemination, has a lawful governmental purpose, and will protect the material under equivalent controls. Thirty seconds of checking the banner prevents the most common and most preventable class of CUI incidents.
Handling is where markings become obligations. To safeguard CUI, the government-wide standard for contractors is NIST SP 800-171, whose entire purpose is protecting the confidentiality of CUI in nonfederal systems: 110 security requirements covering access control, encryption, incident response, and more, flowed to DoD contractors through DFARS 252.204-7012. For contractors handling CUI, those requirements for CUI protection are already baked into your contracts.
The 2026 wrinkle every compliance lead should note: July's CMMC Phase 2 pause changed the certification timeline, not the substance. The requirement to protect CUI under NIST SP 800-171, report incidents, and maintain an accurate SPRS score continues in full force during the review, so the marking and safeguarding work described here remains contract-critical regardless of how the assessment regime settles. Our current CMMC preparation guidance tracks that moving picture for the defense industrial base.
Day to day, the protection of CUI looks unglamorous: CUI stored only in designated, access-controlled locations; encryption in transit and at rest; clean-desk habits for printed material; and cover sheets on physical documents in shared spaces. Companies that manage CUI well shrink where it lives; a well-scoped enclave makes both marking and handling dramatically easier, a theme our guide to choosing a CMMC consultant explores in depth.

Decontrol is the designator's call, not the holder's. Only the designating agency can decontrol CUI, whether by a date or event stated in the indicator, by an authorized disclosure decision, or on request. Contractors never simply strip the labels because material seems old or harmless; if you believe something no longer warrants control, the path runs through the designating office listed in that first-page block.
Destruction has a standard, and a recycling bin doesn't meet it. When CUI reaches end of life, CUI must be destroyed so the information is unreadable, indecipherable, and irrecoverable. For paper, that means cross-cut shredding to accepted specifications rather than tearing or general recycling; for electronic media, sanitization per NIST SP 800-88 practices — wiping, degaussing, or physical destruction, matched to the media type and documented.
Build both into ordinary operations. A destruction log, marked collection bins, and a records-retention schedule that knows which files contain CUI turn end-of-life handling from an annual panic into routine hygiene. Auditors and assessors ask about this exact lifecycle, and "we shred quarterly and log it" is a satisfying answer that takes little effort to make true.

Everyone who touches the material, trained at hire and refreshed annually — that's the DoD's own cadence, and it's the right one for contractors too. Effective CUI training covers the short list that prevents most incidents: what the categories in your world look like, how to read a banner, how to mark what you create, who to ask when unsure, and what mishandling CUI costs the company. The free awareness materials on the DoD's CUI site make a solid foundation to build your program on.
Make it concrete rather than ceremonial. Use your company's real documents as examples, walk through the type of information your contracts actually generate, and rehearse the awkward scenarios: the unmarked email from a prime, the vendor asking for a drawing, the engineer's home laptop. Ten minutes on "here's how we handle CUI in this company" outperforms an hour of regulation recitation.
And close the loop with accountability. Training plus spot checks plus a no-blame reporting path for mistakes creates the culture where a mismarked file gets caught in days instead of discovered in an audit. Sensitive information is protected by habits, and habits are built, not announced.
Understanding CUI is step one; proving you protect it is the game. VisioneerIT Security helps defense contractors protect Controlled Unclassified Information by turning these rules into working programs — scoping where CUI lives, aligning systems to NIST SP 800-171, and building the marking, handling, and training routines assessors expect. Our GovCon security team works with DIB firms across the mid-market, and our guide to how expert CMMC consultants protect contracts explains what outside help should deliver.
Request the CMMC readiness checklist — a practical, level-keyed worksheet covering CUI identification, marking, safeguarding, and the evidence that proves it. One afternoon with it will tell you exactly where you stand.
At VisioneerIT Security, we're committed to safeguarding your business. Reach out to us with your questions or security concerns, and our team will provide tailored solutions to protect your digital assets and reputation.