Controlled Unclassified Information: Marking, Safeguarding, and Sharing

The rules for controlled unclassified information sit in 32 CFR Part 2002, the regulation the National Archives issues as executive agent for the CUI program. In practical terms, they tell you six things: how to identify CUI, how to mark it, how to safeguard it, how to share it, how to destroy or decontrol it, and what happens if you get it wrong. If you handle sensitive unclassified information for a federal agency or under a federal contract, these are the requirements you have to meet.1eCFR. 32 CFR Part 2002 – Controlled Unclassified Information

Who the Rules Cover

Every executive branch agency has to implement a CUI policy, name a Senior Agency Official to run it, and train employees who touch CUI. The reach extends past government offices. Any non-federal organization that receives, stores, or processes CUI on the government’s behalf is bound by the same rules, usually through a contract clause.1eCFR. 32 CFR Part 2002 – Controlled Unclassified Information

For defense contractors, the operative clause is DFARS 252.204-7012, which requires protecting covered defense information on non-federal systems using NIST SP 800-171.2eCFR. 48 CFR 252.204-7012 – Safeguarding Covered Defense Information A proposed FAR rule published in January 2025 would push similar requirements to all federal contractors. As of early 2026, that rule is still a proposal, but it is worth watching if you contract outside the Department of Defense.3Federal Register. Federal Acquisition Regulation: Controlled Unclassified Information

Basic vs. Specified

Every piece of CUI is either Basic or Specified, and the difference matters because it changes how much control the underlying law dictates.

CUI Basic is the default. The law behind it says “protect this” without spelling out how, so the uniform standards in 32 CFR Part 2002 govern. Most CUI is Basic.1eCFR. 32 CFR Part 2002 – Controlled Unclassified Information

CUI Specified exists where the governing statute or regulation lays out specific handling procedures beyond the baseline. Tax return information carries handling rules from the Internal Revenue Code. Certain health records are covered by separate federal statutes. With Specified CUI, the general rules still apply as a floor, and you layer the extra controls on top. The CUI Registry, maintained by NARA, lists every approved category and subcategory, flags which ones are Specified, and cites the legal authority for each. It is where any designation question starts.1eCFR. 32 CFR Part 2002 – Controlled Unclassified Information

How to Mark CUI

Marking is where most compliance problems start. Every page of a CUI document carries a banner marking at the top and bottom, centered, in bold capitals. The banner reads either “CONTROLLED” or “CUI.”4eCFR. 32 CFR 2002.20 – Marking5Center for Development of Security Excellence. CUI Quick Marking Tips

For CUI Specified, the banner must also include the applicable category or subcategory marking. Tax-related Specified information might be banner-marked “CUI//SP-TAX.” Every Specified category that applies to the document has to appear.4eCFR. 32 CFR 2002.20 – Marking For CUI Basic, category markings in the banner are optional unless agency policy requires them.

The first page also needs a designation indicator block, usually in the lower-right corner. That block names the originating agency, the responsible office, the CUI category, and any limited dissemination controls attached to the document. It tells the reader where the document came from and how to handle it.5Center for Development of Security Excellence. CUI Quick Marking Tips

Portion markings, which label individual paragraphs or tables, are a common source of confusion. For unclassified documents they are optional. The regulation says agencies are “permitted and encouraged” to use them, and if you use them you must apply them throughout the document, including to uncontrolled portions.4eCFR. 32 CFR 2002.20 – Marking They earn their keep in long documents that mix CUI with releasable content.

Safeguarding CUI

Physical Storage

Printed CUI has to be stored in a locked container or a secured room when it is not actively in use. Vault-level security is not required. What is required is that no one without a legitimate need can view the information, whether that is an office visitor, cleaning staff, or a colleague on a different project. CUI does not sit on an open desk overnight, and it does not live in an unlocked filing cabinet.

Digital Systems and NIST SP 800-171

Any non-federal information system that stores, processes, or transmits CUI has to meet the security requirements in NIST Special Publication 800-171. The publication covers 17 security requirement families, including access control, audit and accountability, incident response, and system and communications protection. Concretely, that means multi-factor authentication, encrypted communications, session timeouts, and audit logs that show who accessed what and when.6Computer Security Resource Center. NIST Special Publication 800-171 Rev. 3 – Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

NIST published Revision 3 in May 2024. It streamlined the requirements, dropped the old “basic” and “derived” distinction, and introduced organization-defined parameters. Defense contractors should note, though, that CMMC and DFARS 252.204-7012 currently reference Revision 2 and its 110 security requirements for assessment purposes.2eCFR. 48 CFR 252.204-7012 – Safeguarding Covered Defense Information

CMMC for Defense Contractors

The Cybersecurity Maturity Model Certification program adds a verification layer to NIST SP 800-171. Instead of trusting contractors to self-report, CMMC requires assessments at defined levels. Level 2, which maps to the 110 requirements in NIST SP 800-171 Revision 2, is the benchmark for organizations that handle CUI.

The rollout is phased:

  • Phase 1 began November 2025. Solicitations may require Level 1 or Level 2 self-assessments.
  • Phase 2 begins November 2026. Solicitations may require Level 2 certification through an independent third-party assessment organization.
  • Phase 3 begins November 2027. Solicitations may require Level 3 certification for the most sensitive CUI.
7Department of War. About CMMC – DoD CIO

Self-assessment results go into the Supplier Performance Risk System. A final score of 110 (full compliance) is valid for three years with annual affirmations. A conditional score between 88 and 109 gives you 180 days to close remaining gaps through a Plan of Action and Milestones before the conditional status expires.8Supplier Performance Risk System (SPRS). CMMC Level 2 Self-Assessment Quick Entry Guide Contractors have to maintain a current CMMC status at the required level for the life of the contract.9eCFR. 48 CFR Part 204 Subpart 204.75 – Cybersecurity Maturity Model Certification

Sharing CUI

You can share CUI with someone who has a lawful government purpose for it. That generally means the person needs the information to carry out official duties or to perform work under a government contract. Verify authorization and legitimate need before you send anything. A recipient’s clearance level or job title alone is not enough.10National Archives and Records Administration. CUI Notice 2017-01 – Lawful Government Purpose11eCFR. 32 CFR 2002.16 – Accessing and Disseminating

How you transmit CUI matters. Electronic transmissions should use FIPS-validated encryption, such as encrypted email or an approved secure portal. Physical mail should go in an opaque inner envelope so markings are not visible through the packaging, and double-wrapping in an unmarked outer envelope adds protection during transit.

Limited Dissemination Controls

The designating agency can attach limited dissemination controls that narrow who may receive the information beyond the baseline. Only the agency that originally designated the CUI may apply them, and only using approved markings from the CUI Registry. The regulation cautions against overusing these controls, because restricting access more than necessary defeats the program’s information-sharing purpose.11eCFR. 32 CFR 2002.16 – Accessing and Disseminating

The most common controls:

  • NOFORN. No foreign dissemination. The information cannot go to foreign governments, foreign nationals, or international organizations.
  • FED ONLY. Restricted to federal employees and active military personnel.
  • FEDCON. Open to federal employees, active military, and contractors working under a government contract.
  • NOCON. Available to federal and state, local, or tribal employees but not to contractors.
  • DL ONLY. Dissemination limited to individuals or entities on a specific accompanying list.
12National Archives. CUI Registry: Limited Dissemination Controls

These controls appear in the banner marking and the designation indicator block. A NOFORN document might carry a banner reading “CUI//NOFORN.” You cannot add a limited dissemination control to CUI you received from another agency without that agency’s permission.

Destroying CUI

When CUI is no longer needed, it has to be destroyed so the information cannot be recovered. For paper, that means cross-cut shredding. Strip-cut shredders do not meet the standard, because strips can sometimes be reassembled.

Digital media requires sanitization techniques aligned with NIST Special Publication 800-88. Depending on whether you plan to reuse the media, options include software wiping that overwrites data multiple times, degaussing for magnetic drives, cryptographic erasure, or physical destruction. What matters is that the CUI cannot be retrieved after the fact.13National Institute of Standards and Technology. NIST SP 800-88 Rev. 2 – Guidelines for Media Sanitization

Document every destruction action. An audit trail of what was destroyed, when, how, and by whom protects the organization if questions come up later.

Decontrolling CUI

Decontrolling means removing CUI status so the information no longer needs special handling. Agencies are supposed to decontrol CUI as soon as the underlying law, regulation, or policy no longer requires protection. That can happen by a deliberate decision from the designating agency, an approved public release, a FOIA disclosure, or a pre-set date or event specified when the CUI was first designated.14eCFR. 32 CFR 2002.18 – Decontrolling

Only the designating agency, or personnel it authorizes, can decontrol CUI. If you hold CUI from another agency and think it should be decontrolled, you request that the originating agency review it. Once information is decontrolled, the CUI handling requirements fall away for that material, though decontrol does not automatically approve it for public release. If you reuse decontrolled CUI in a new document, remove all CUI markings from that information. Agency policy may also allow you to strike through markings on the original document’s first page and its attachments.14eCFR. 32 CFR 2002.18 – Decontrolling

One boundary worth stating clearly: an unauthorized disclosure is not decontrol. Agencies cannot decontrol information to cover up or avoid accountability for a breach.

Training

Every agency has to have a CUI training policy, and everyone with access to CUI has to be trained. Training is required when an employee starts and at least every two years after. It has to cover designation, categories and subcategories, use of the CUI Registry, marking, and the rules for safeguarding, sharing, and decontrolling CUI.1eCFR. 32 CFR Part 2002 – Controlled Unclassified Information

The proposed FAR CUI rule would extend training requirements to contractors. Under the proposal, no contractor employee could access or handle CUI without first completing training that meets the minimum elements specified in the contract’s CUI requirements form.3Federal Register. Federal Acquisition Regulation: Controlled Unclassified Information

Reporting Incidents

A CUI incident is any potential compromise of CUI through unauthorized access, disclosure, or loss of control. On a contractor system, the reporting clock depends on the governing clause.

Under DFARS 252.204-7012, defense contractors must report cyber incidents involving covered defense information within 72 hours of discovery.2eCFR. 48 CFR 252.204-7012 – Safeguarding Covered Defense Information The proposed government-wide FAR rule tightens the window to 8 hours from discovery, with subcontractors notifying the prime contractor in the same 8-hour window.3Federal Register. Federal Acquisition Regulation: Controlled Unclassified Information

Beyond reporting, organizations have to maintain an incident-handling capability that includes preparation, detection and analysis, containment, eradication, and recovery. If a CUI spill lands on a system that should not have held it, the affected media has to be sanitized. Document every incident and every remediation action.15National Institute of Standards and Technology. Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (NIST SP 800-171r3)

Enforcement and Penalties

32 CFR 2002.56 requires each agency to include sanctions for CUI misuse in its own policy. The regulation does not create a separate penalty structure. Instead, it directs agencies to use existing administrative authorities, which can range from a formal reprimand or loss of CUI access to suspension of a security clearance, depending on the severity and the agency’s disciplinary framework.16eCFR. 32 CFR 2002.56 – Sanctions for Misuse of CUI

For contractors, the exposure is more concrete. The Department of Justice has increasingly used the False Claims Act against companies that falsely certify compliance with CUI cybersecurity requirements. False Claims Act liability does not require an actual data breach. If a contractor claims to meet NIST SP 800-171 to win or keep a contract without actually implementing the controls, that misrepresentation alone can trigger enforcement. In a 2025 settlement, a defense contractor and its private equity owner paid $1.75 million to resolve allegations that they failed to implement required security controls and improperly gave a foreign software company access to Air Force CUI. Many of these actions originate as whistleblower complaints from employees with firsthand knowledge of the company’s actual cybersecurity practices.

Challenging a CUI Designation

If you think information has been improperly designated as CUI, or you have received CUI that is not marked correctly, you can challenge the designation. Challenges go to the designating agency’s Senior Agency Official. The SAO acknowledges receipt within seven days, and you get an opportunity to explain your reasoning verbally or in writing. The regulation protects challengers from retaliation and allows anonymous submissions.17General Services Administration. GSA Controlled Unclassified Information (CUI) Program Guide

While a challenge is pending, keep handling the information at the control level shown in its current markings. If the agency’s response does not resolve the dispute, the formal dispute resolution procedures in 32 CFR Part 2002 give you a way to escalate.1eCFR. 32 CFR Part 2002 – Controlled Unclassified Information