Controlled Unclassified Information, or CUI, is sensitive federal information that isn’t classified but still requires specific protections under 32 CFR Part 2002. If you handle CUI documents, you are responsible for marking them correctly, storing them in a controlled environment, sharing them only for a lawful government purpose, and destroying them so the contents cannot be recovered. Executive Order 13556 replaced the old patchwork of agency labels like “For Official Use Only” and “Sensitive But Unclassified” with this single framework administered by the National Archives and Records Administration.1The White House Archives. Executive Order 13556 – Controlled Unclassified Information2eCFR. 32 CFR Part 2002 – Controlled Unclassified Information (CUI)
What Qualifies as a CUI Document
Not every sensitive paper on your desk is CUI. The information has to fall within a category listed on the NARA CUI Registry, and each category traces back to a specific statute, regulation, or government-wide policy. The Registry organizes CUI into 20 groupings, covering areas such as Defense, Law Enforcement, Tax, Privacy, Intelligence, Financial, Immigration, and Nuclear.3National Archives. CUI Registry – Category List Before you label anything CUI, check the Registry and confirm a legal authority exists. Inventing categories or applying the marking to information without legal backing is not permitted.
CUI Basic vs. CUI Specified
Every piece of CUI is either Basic or Specified, and the label tells you which rules apply. CUI Basic is the default: when the underlying law doesn’t spell out particular handling requirements, you follow the standard uniform rules in 32 CFR Part 2002. CUI Specified means the underlying authority builds in its own handling requirements that go beyond or differ from the baseline. Tax return information under the Internal Revenue Code and health information under HIPAA are common examples. With Specified information you follow both the standard CUI rules and the additional requirements the underlying statute imposes.4eCFR. 32 CFR 2002.4 – Definitions
How to Mark CUI Documents
Markings tell anyone who picks up the document what it is and how to treat it. Three elements matter most.
The Banner
Every CUI document carries a banner at the top of each page. At a minimum the banner shows the control marking, which is either the word “CONTROLLED” or the acronym “CUI.” Agencies can require one form or the other. For CUI Specified, the banner also includes the category or subcategory marking from the Registry, so a controlled tax document might read “CUI//SP-TAX.” Any limited dissemination controls appear in the banner too.5eCFR. 32 CFR 2002.20 – Marking
The Designation Indicator
Every document must identify who designated it as CUI. That means, at a minimum, naming the designating agency. It can appear as a “Controlled by” line on the first page, on agency letterhead, or in any format that makes the source office obvious. This lets recipients contact the right office with questions about handling or decontrol.5eCFR. 32 CFR 2002.20 – Marking
Portion Marks and Cover Sheets
Agencies may require a “(CUI)” indicator at the start of each paragraph that contains controlled content, so readers can tell which portions are sensitive. When a printed CUI document is being reviewed, moved, or left in a work area, place Standard Form 901, the CUI cover sheet, on top of it to prevent casual observation.6DoD CUI Program. Telework
How to Store CUI Documents
The regulation requires you to keep CUI in a controlled environment where unauthorized people cannot access or observe it. When the material is not actively in use, it needs at least one physical barrier between it and anyone who shouldn’t see it.7eCFR. 32 CFR 2002.14 – Safeguarding
Paper
Locked desks, locked file cabinets, and GSA-approved storage cabinets all satisfy the physical storage requirement.8U.S. Department of Defense CUI. Storage Requirements Vaults and safes are not required for CUI the way they are for classified material, but leaving documents on an open desk overnight in an unlocked office is not acceptable.
Digital
Federal information systems that store CUI must be handled at no less than a moderate confidentiality impact level under FIPS Publication 199, with security controls drawn from FIPS Publication 200 and NIST SP 800-53.7eCFR. 32 CFR 2002.14 – Safeguarding Encryption at rest is expected, and many agencies require FIPS-validated cryptographic modules. If you currently rely on FIPS 140-2 validation, note that all FIPS 140-2 certificates move to the historical list on September 22, 2026, after which FIPS 140-3 becomes the sole active standard. Modules on the historical list can remain in deployed systems, but new procurements should target FIPS 140-3.9National Institute of Standards and Technology. FIPS 140-3 Transition Effort Access should follow the principle of least privilege, with auditing to track who opens CUI files and whether anyone tried to.
Telework
You are allowed to take CUI to an approved home office, but the safeguarding rules travel with the paper. When hand-carrying documents out of the office, place SF 901 on top and put everything inside an opaque envelope with no CUI markings visible on the outside. At home, secure CUI in a desk, file cabinet, bookcase, or similar location whenever it’s not in use. Disconnect smart home devices and voice assistants when discussing CUI at a remote location.6DoD CUI Program. Telework
How to Share and Transmit CUI
Access is governed by the Lawful Government Purpose standard. That covers any activity, mission, or function the U.S. Government authorizes or recognizes within its legal authorities, and it can include recipients outside the executive branch, such as state and local law enforcement.10National Archives. Lawful Government Purpose
Mail and Hand Carry
You may mail CUI through the United States Postal Service or a commercial delivery service. The regulation recommends using automated tracking and accountability tools but does not make tracking absolutely mandatory for every mailing. Packages must be marked according to CUI requirements. Hand-carrying is permitted as long as you maintain direct control the whole way.7eCFR. 32 CFR 2002.14 – Safeguarding
Email and File Transfer
Electronic transmission requires encryption that meets the federal standards described above. Sending CUI in the clear across public networks violates the safeguarding rules. Check your agency or contract language for the specific FIPS-validated module and NIST SP 800-53 controls required.
Foreign Dissemination
Some CUI carries restrictions on sharing with foreign nationals or governments. The marking NOFORN (Not Releasable to Foreign Nationals) can be applied to certain CUI categories, but only after a Foreign Disclosure Officer confirms that international agreements or other arrangements prohibit release. Categories that commonly carry NOFORN restrictions include unclassified intelligence information, naval nuclear propulsion information, export-controlled data, and nuclear information designated as CUI. The companion marking REL TO works in the opposite direction and lists countries or international organizations that can receive the information, using ISO 3166 country codes with “USA” first.11Defense Counterintelligence and Security Agency. Proper Use of NOFORN and REL TO Dissemination Control Markings
Contractor Obligations
If you handle CUI under a federal contract, the base rule is only the starting point. Agencies must apply NIST SP 800-171 when setting security requirements for CUI on non-federal information systems.7eCFR. 32 CFR 2002.14 – Safeguarding Revision 3, published in May 2024, organizes the requirements into 17 families covering areas such as access control, incident response, and system integrity.12National Institute of Standards and Technology. Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
Defense Department contractors face an additional assessment layer through the Cybersecurity Maturity Model Certification (CMMC), which has three levels:
- Level 1 covers basic safeguarding of Federal Contract Information (not full CUI) and requires an annual self-assessment against the 15 security requirements in FAR clause 52.204-21.
- Level 2 covers broad CUI protection through the 110 security requirements in NIST SP 800-171 Revision 2, verified either by self-assessment or by an independent third-party assessment organization (C3PAO) every three years.
- Level 3 addresses advanced persistent threats to CUI. It requires a Level 2 certification first, then a government-led assessment by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) covering 24 additional requirements from NIST SP 800-172.
Contractors submit their compliance affirmations through the Supplier Performance Risk System (SPRS).13Department of Defense Chief Information Officer. About CMMC Federal contracts that involve CUI also incorporate FAR 52.204-21 for basic safeguarding, and defense contracts add DFARS 252.204-7012.14Acquisition.GOV. FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems DFARS 252.204-7012 carries a 72-hour incident reporting obligation when covered defense information is compromised. Initial reports go through the DoD’s designated reporting channels and must describe the information affected, the systems involved, and the operational impact. Contractors must preserve images of affected systems and relevant monitoring data for at least 90 days and submit any detected malware to the DoD Cyber Crime Center for analysis. Outside the defense context, each agency has its own reporting procedure, typically built around NIST SP 800-53 incident response controls.
Training
Federal employees must be trained on CUI handling when they first arrive at the agency and at least once every two years after that. Training covers designation, categories and subcategories, use of the Registry, marking, safeguarding, dissemination, and decontrol. Contractors with CUI access face equivalent obligations through their contract terms, and skipping or falling behind can cost you access to the affected work.15eCFR. 32 CFR 2002.30 – Education and Training
When CUI Protections End
CUI is not protected forever. Agencies should remove the designation as soon as the information no longer requires safeguarding, unless doing so conflicts with the underlying authority. Decontrol can happen automatically, when the governing law no longer requires protection, when the agency proactively releases the information, when it is disclosed through a public access statute such as FOIA, or when a pre-set date or event arrives. Any authorized holder can also request decontrol from the designating agency. When you reuse decontrolled information in a new document, remove every CUI marking.16eCFR. 32 CFR 2002.18 – Decontrolling
One point on the boundary of the program: a CUI marking does not shield a document from FOIA. It may inform the reviewer about the type of information involved, but every FOIA request still requires an independent determination about whether a specific exemption applies. No marking automatically exempts a record from FOIA review.17National Archives. FOIA and the CUI Program
How to Destroy CUI Documents
Once you no longer need the CUI and records disposition schedules allow disposal, destroy it so the information is unreadable, indecipherable, and irrecoverable. If the underlying authority specifies a method, use it. Otherwise the regulation points to two options: follow NIST SP 800-53 and NIST SP 800-88, or use a method approved for classified national security information under 32 CFR 2001.47.2eCFR. 32 CFR Part 2002 – Controlled Unclassified Information (CUI)
Paper
Cross-cut shredding is the standard. NSA/CSS requirements call for shredders that reduce paper to particles no larger than 1 millimeter by 5 millimeters.18National Security Agency. NSA/CSS Requirements for Paper Shredders Standard strip-cut shredders don’t meet that specification. Organizations with high volume often use mobile shredding services.
Electronic Media
NIST SP 800-88 describes three approaches of increasing intensity. Clearing overwrites the data using software tools. Purging uses stronger techniques such as degaussing, which destroys the magnetic field on a hard drive and makes the data unrecoverable even with laboratory methods. Physical destruction through crushing or incineration is the final option when the media cannot be reliably wiped. Document every disposal action to create an audit trail.
Consequences of Mishandling
The CUI regulation itself creates no new criminal penalties. It preserves whatever sanctions already apply under the statute, regulation, or policy behind the specific information. Mishandling tax records, for example, carries the penalties tax law already imposes. Agency heads can also use their existing administrative authority to discipline employees who misuse CUI.19U.S. Nuclear Regulatory Commission. CUI Frequently Asked Questions For contractors the consequences are contractual: failure to meet FAR 52.204-21, DFARS 252.204-7012, or the applicable CMMC level can lead to contract termination and loss of future awards, on top of the 72-hour incident reporting obligation for defense work.