CUI is the most consequential four-letter acronym in defense contracting, and one of the most misunderstood. This guide explains what Controlled Unclassified Information actually is, how the marking rules work, who applies them, what handling and destruction require, and why getting this right decides whether your company keeps winning DoD work. If your contracts, your primes, or your file shares touch government information, this is the plain-English foundation your whole team should share.

What Is Controlled Unclassified Information (CUI)?

Controlled Unclassified Information is government-created or government-owned information that requires safeguarding or dissemination controls under law, regulations, and government-wide policies, but is not classified. That definition comes straight from the program's founding documents: Executive Order 13556 established the CUI program in 2010, and 32 CFR Part 2002 turned it into binding rules, with the Information Security Oversight Office at the National Archives serving as the government-wide executive agent.

The category exists to fix a real problem. Before CUI, agencies used a zoo of homegrown labels — For Official Use Only, Sensitive But Unclassified, and dozens more — each with its own unwritten rules. Information that requires safeguarding was marked inconsistently, shared nervously, and protected unevenly, so the CUI program replaced the zoo with one system and one registry.

Here's the sentence worth repeating in every training session: CUI is sensitive, but it is not classified. It sits below classification: no clearances, no SCIFs. Access requires a lawful governmental purpose, a lower bar than classified need-to-know, but mishandling it still carries real consequences. Think of CUI as the government saying, "This won't endanger national security by itself, but you must protect it anyway, and here's exactly how."

Filing cabinet drawer of labelled records representing unclassified but controlled government information
CUI is government information you have to protect but that isn't classified — no clearances, no SCIFs, just a lawful governmental purpose and a defined set of controls.

What's the Difference Between CUI Basic and CUI Specified?

Every category of CUI comes in one of two flavors, and the distinction drives your obligations. CUI Basic covers information where the underlying law or regulation says "protect this" without prescribing how. For CUI Basic, the program's uniform baseline applies: the standard handling, marking, and safeguarding rules of 32 CFR Part 2002, and, for contractors, the security requirements of NIST SP 800-171.

CUI Specified is the subset of CUI where the authority does spell out particular controls: specific handling procedures, additional access restrictions, or penalties written into the law itself. Export-controlled technical data is the classic example, since ITAR and EAR impose their own requirements on top of the baseline. In marking terms, Specified categories carry an "SP-" prefix, and the difference between CUI Basic and CUI Specified appears right in the banner.

The practical rule for compliance leads: treat CUI Basic or CUI Specified as a routing decision. Anyone can handle CUI Basic under your standard program controls; CUI Specified triggers a check of the specific authority's added rules before the file moves anywhere. Knowing which type of CUI you hold is the first question, not an afterthought.

What Are the CUI Categories, and Where Are the Registries?

The authoritative catalog is the ISOO CUI Registry at archives.gov, which lists every approved category across roughly twenty groupings, from procurement and privacy to export control and critical infrastructure. Only information falling within a registry category can be considered CUI, which cuts both ways: agencies can't invent labels, and contractors can't dismiss markings that map to real categories.

The Department of Defense maintains its own aligned catalog, the DoD CUI Registry, organized into indexes the defense world actually uses. The most common example of CUI in defense work is Controlled Technical Information: engineering drawings, specifications, and other technical data with military or space application. Procurement-sensitive information and export-controlled data round out the categories most DoD contractors see weekly.

A working tip from the field: build your own short list. Most companies encounter only a handful of the registry's categories, so identify CUI types your contracts actually generate, document them, and train to those. A two-page internal cheat sheet beats sending engineers to browse a federal registry every time a question comes up.

How Does the CUI Marking System Work?

The design goal is uniformity. The CUI policy provides a uniform marking system across the federal government, so a marked file means the same thing at every agency and every contractor. CUI markings alert recipients to the presence of CUI in a document before they read a word of it, which is the entire point: protection travels with the information.

The CUI marking system has three moving parts. First, the CUI banner marking at the top of each page, beginning with "CUI" and optionally adding category and dissemination segments separated by double slashes, such as CUI//SP-CTI//NOFORN. Second, an optional portion scheme for paragraph-level granularity; once you portion-mark a document, every portion gets a mark. Third, the designation indicator, which we'll cover next, telling recipients who controlled the information and how to ask questions about it.

One legacy note that still trips people: old FOUO stamps are not CUI markings. Documents containing CUI need current marks under the current rules, and legacy-marked material gets remarked when it re-enters use. If your shared drives still hold a decade of FOUO, that's a cleanup project, not a technicality.

What Goes in the Banner and Designation Indicator?

The banner is the headline. At minimum, "CUI" (or "CONTROLLED") appears at the top of every page; DoD practice commonly marks top and bottom. When categories are included, the CUI banner reads in a fixed order: control marking, then category codes, then limited dissemination controls, so a reader can parse CUI//SP-CTI//NOFORN at a glance: Specified controlled technical information, no foreign nationals.

The CUI designation indicator is the accountability block, and it's required on the first page of every marked document. Per the Department of Defense's Instruction 5200.48, it identifies who controlled the material ("Controlled by"), the category, the applicable dissemination or distribution statement, and a point of contact. That block is what lets a recipient two contracts downstream ask the right office whether the material can be shared, decontrolled, or released.

Emails, slides, and spreadsheets follow the same logic as documents: banner at top, indicator with the first transmission. The marking requirements are genuinely learnable in an afternoon, and consistency matters more than artistry. A plain, correct banner beats an elaborate wrong one every time.

Rubber stamp on an official document, illustrating CUI banner marking and the designation indicator
Every page carries a CUI banner; the first page carries the designation indicator naming who controls the information and who to ask about release.

Who Is Responsible for Applying CUI Markings?

The authorized holder who creates the material, at the moment of creation. That's the rule from the DoD instruction: whoever originates a document decides whether to treat the information as CUI, and if so, that person is responsible for applying CUI markings and dissemination instructions before it moves. This is not a security-office cleanup function; it's an authoring step.

For contractors, two flows matter. Inbound, the government should identify CUI it provides to you, typically through contract documents and the marks themselves; if material arrives unmarked but smells like CUI, ask the contracting officer in writing rather than guessing. Outbound and internal, anything your team creates that contains CUI — derived drawings, analysis, test data — inherits the obligation, and your people must mark CUI they generate just as a government author would.

This is why designation authority deserves a named owner inside your company. Someone has to answer "is this marked as CUI correctly?" in minutes, not weeks, and to keep the presence of CUI from silently spreading into folders where nobody is managing it. Most mid-sized defense contractors give that hat to the same person who owns their compliance program, which works when that person has real training and real authority.

What Are the Dissemination Controls on CUI?

Dissemination controls are the "who can see this" layer riding on top of the category. The registry defines a limited set, and the common ones do most of the work: NOFORN (no foreign nationals), FED ONLY (federal employees only), FEDCON (federal employees and contractors), REL TO (releasable to named countries), and DL ONLY (limited to a distribution list). DoD material frequently pairs CUI markings with distribution statements as well.

Two rules keep companies out of trouble. First, dissemination controls must come from the approved set and be justified by the underlying authority; a designator can't invent restrictions, and CUI may not be restricted simply because it's embarrassing or inconvenient. Second, controls bind everyone downstream: a NOFORN mark on a drawing means your foreign-national engineer can't be on that project's share, full stop, and access control lists have to reflect it.

Where this bites in practice is teaming. Before you forward CUI to a subcontractor or partner, confirm the recipient is within the marked dissemination, has a lawful governmental purpose, and will protect the material under equivalent controls. Thirty seconds of checking the banner prevents the most common and most preventable class of CUI incidents.

How Should Defense Contractors Handle and Safeguard CUI?

Handling is where markings become obligations. To safeguard CUI, the government-wide standard for contractors is NIST SP 800-171, whose entire purpose is protecting the confidentiality of CUI in nonfederal systems: 110 security requirements covering access control, encryption, incident response, and more, flowed to DoD contractors through DFARS 252.204-7012. For contractors handling CUI, those requirements for CUI protection are already baked into your contracts.

The 2026 wrinkle every compliance lead should note: July's CMMC Phase 2 pause changed the certification timeline, not the substance. The requirement to protect CUI under NIST SP 800-171, report incidents, and maintain an accurate SPRS score continues in full force during the review, so the marking and safeguarding work described here remains contract-critical regardless of how the assessment regime settles. Our current CMMC preparation guidance tracks that moving picture for the defense industrial base.

Day to day, the protection of CUI looks unglamorous: CUI stored only in designated, access-controlled locations; encryption in transit and at rest; clean-desk habits for printed material; and cover sheets on physical documents in shared spaces. Companies that manage CUI well shrink where it lives; a well-scoped enclave makes both marking and handling dramatically easier, a theme our guide to choosing a CMMC consultant explores in depth.

Badge reader controlling entry to a secure area where CUI is stored and processed
NIST SP 800-171 flows to contractors through DFARS 7012: access-controlled locations, encryption in transit and at rest, and a CUI footprint kept deliberately small.

How Do You Decontrol and Destroy CUI?

Decontrol is the designator's call, not the holder's. Only the designating agency can decontrol CUI, whether by a date or event stated in the indicator, by an authorized disclosure decision, or on request. Contractors never simply strip the labels because material seems old or harmless; if you believe something no longer warrants control, the path runs through the designating office listed in that first-page block.

Destruction has a standard, and a recycling bin doesn't meet it. When CUI reaches end of life, CUI must be destroyed so the information is unreadable, indecipherable, and irrecoverable. For paper, that means cross-cut shredding to accepted specifications rather than tearing or general recycling; for electronic media, sanitization per NIST SP 800-88 practices — wiping, degaussing, or physical destruction, matched to the media type and documented.

Build both into ordinary operations. A destruction log, marked collection bins, and a records-retention schedule that knows which files contain CUI turn end-of-life handling from an annual panic into routine hygiene. Auditors and assessors ask about this exact lifecycle, and "we shred quarterly and log it" is a satisfying answer that takes little effort to make true.

Destruction has a standard: cross-cut shredding for paper, NIST SP 800-88 sanitization for media, and a log that proves both happened.
Destruction has a standard: cross-cut shredding for paper, NIST SP 800-88 sanitization for media, and a log that proves both happened.

What CUI Training Do Your People Need?

Everyone who touches the material, trained at hire and refreshed annually — that's the DoD's own cadence, and it's the right one for contractors too. Effective CUI training covers the short list that prevents most incidents: what the categories in your world look like, how to read a banner, how to mark what you create, who to ask when unsure, and what mishandling CUI costs the company. The free awareness materials on the DoD's CUI site make a solid foundation to build your program on.

Make it concrete rather than ceremonial. Use your company's real documents as examples, walk through the type of information your contracts actually generate, and rehearse the awkward scenarios: the unmarked email from a prime, the vendor asking for a drawing, the engineer's home laptop. Ten minutes on "here's how we handle CUI in this company" outperforms an hour of regulation recitation.

And close the loop with accountability. Training plus spot checks plus a no-blame reporting path for mistakes creates the culture where a mismarked file gets caught in days instead of discovered in an audit. Sensitive information is protected by habits, and habits are built, not announced.

Get the CMMC Readiness Checklist

Understanding CUI is step one; proving you protect it is the game. VisioneerIT Security helps defense contractors protect Controlled Unclassified Information by turning these rules into working programs — scoping where CUI lives, aligning systems to NIST SP 800-171, and building the marking, handling, and training routines assessors expect. Our GovCon security team works with DIB firms across the mid-market, and our guide to how expert CMMC consultants protect contracts explains what outside help should deliver.

Request the CMMC readiness checklist — a practical, level-keyed worksheet covering CUI identification, marking, safeguarding, and the evidence that proves it. One afternoon with it will tell you exactly where you stand.

Key Things to Remember

  • CUI is unclassified information the government requires you to protect — established by Executive Order 13556, governed by 32 CFR Part 2002, cataloged in the ISOO CUI Registry, and implemented in defense through DoD Instruction 5200.48.
  • CUI Basic follows the uniform baseline; CUI Specified carries extra controls written into the underlying law and wears an "SP-" prefix in the banner.
  • The marks have three parts: the banner at the top of every page, optional-but-consistent portion marking, and the first-page designation indicator naming the controlling office.
  • Whoever creates material containing CUI marks it at creation; contractors inherit that duty for everything they derive or generate.
  • Dissemination controls like NOFORN and FEDCON bind everyone downstream — check the banner before any file leaves your team.
  • Handling runs through NIST SP 800-171 via DFARS 7012, and the CMMC Phase 2 pause changed assessment timing, not these obligations.
  • Only the designator decontrols; destruction means cross-cut shredding for paper and NIST SP 800-88 sanitization for media, logged.
  • Train everyone annually on your real documents and categories, keep CUI's footprint small, and give marking authority a named owner.

Send Us a Message

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Get in Touch for Expert Cybersecurity Solutions

At VisioneerIT  Security, we're committed to safeguarding your business. Reach out to us with your questions or security concerns, and our team will provide tailored solutions to protect your digital assets and reputation.