CUI Documents Must Be Reviewed According to Which Procedures?

The procedures for reviewing CUI documents run through three layers: 32 CFR Part 2002 and the NARA-maintained CUI Registry govern whether a document is properly designated and marked; NIST security publications govern whether the system holding it is adequately protected; and, for defense work, the Cybersecurity Maturity Model Certification program and DFARS 252.204-7012 add a verification layer on top. A complete review walks each layer in order, because a document can be correctly marked yet sitting on a non-compliant system, or perfectly protected yet carrying a designation it never qualified for.

Confirm the Designation Is Valid

Start by checking that the information actually qualifies as CUI. The CUI Registry, maintained by NARA, is the authoritative list of every approved category and subcategory, and each entry cites the law, regulation, or government-wide policy that authorizes control.1National Archives. CUI Registry: Category List If the content does not fall within a listed category, it should not carry a CUI designation at all. Executive Order 13556 is explicit: where there is significant doubt about whether information should be designated as CUI, it should not be.2The White House. Executive Order 13556 — Controlled Unclassified Information

Next, identify whether the document is CUI Basic or CUI Specified. CUI Basic applies when the authorizing law does not spell out specific handling controls, and those documents follow the uniform defaults in 32 CFR Part 2002. CUI Specified applies when the underlying authority prescribes particular handling requirements that differ from or go beyond the defaults.3eCFR. 32 CFR 2002.4 – Definitions The distinction changes the review: a Specified document must be handled according to whatever the governing law requires, with Basic controls filling any gaps the law leaves open.

Check the Markings

Under 32 CFR 2002.20, a properly marked CUI document has three elements. Verify each.

Banner Marking

Every page containing CUI must carry a banner at the top reading either “CONTROLLED” or “CUI.” Both are acceptable, and agencies may direct their people to use one or the other.4eCFR. 32 CFR 2002.20 – Marking The banner may include category or subcategory markings and any limited dissemination controls. For CUI Specified documents, the category or subcategory in the banner is mandatory; for CUI Basic, it is optional unless agency policy requires it. The banner must be the same on every page and must reflect the full scope of CUI categories present.

Designation Indicator

The document must identify who designated the information. At a minimum this means the designating agency, shown through letterhead, a “Controlled by” line, or another clear format. It needs to appear only on the first page or cover.4eCFR. 32 CFR 2002.20 – Marking

Portion Marking

Portion markings tag individual paragraphs, bullets, or figures to show which parts contain CUI. Agencies are encouraged but not required to use them.4eCFR. 32 CFR 2002.20 – Marking If an organization uses portion markings, every portion must be marked. Partial application is not allowed. Portion markings use the acronym “CUI” rather than the full word, and may include category or dissemination control markings as applicable.

Check Safeguarding on the System That Holds It

Under 32 CFR 2002.14, authorized holders must take reasonable precautions against unauthorized disclosure: controlled environments, barriers to unauthorized viewing, and direct control or at least one physical barrier when CUI leaves a controlled space.5eCFR. 32 CFR 2002.14 – Safeguarding Where the review gets technical is on the electronic side, and the applicable standard depends on who runs the system.

For CUI on federal information systems, agencies apply FIPS Publication 199, FIPS Publication 200, and NIST SP 800-53.5eCFR. 32 CFR 2002.14 – Safeguarding For CUI on systems operated by contractors, universities, or other non-federal organizations, the governing publication is NIST SP 800-171, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.”6National Institute of Standards and Technology. NIST SP 800-171 Rev 2 – Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

A version distinction matters. NIST published Revision 3 in 2024, reorganizing the requirements into 17 control families.7National Institute of Standards and Technology. NIST SP 800-171 Rev 3 – Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations As of 2026, the Department of Defense and its CMMC program still require compliance with Revision 2, which contains 110 security requirements across 14 control families. DoD has not announced a transition date to Revision 3. Organizations being assessed under CMMC or DFARS 252.204-7012 should review against Revision 2 until DoD formally updates the requirement.

Defense Contractors: CMMC and DFARS 7012

Contracts containing the DFARS 252.204-7012 clause require contractors to implement NIST SP 800-171 on any covered contractor information system that processes, stores, or transmits Covered Defense Information.8eCFR. 48 CFR 252.204-7012 – Safeguarding Covered Defense Information The clause also requires cloud service providers to meet FedRAMP Moderate baseline or equivalent, and its safeguarding obligations flow down to subcontractors. A prime cannot pass CUI to a subcontractor without confirming the subcontractor meets the same requirements.

CMMC layers assessment onto that baseline. Phase 1, running from November 10, 2025 through November 9, 2026, focuses on Level 1 and Level 2 self-assessments. Phase 2 begins November 10, 2026 and will start requiring Level 2 certification by third-party assessment organizations in applicable solicitations.9Department of Defense Chief Information Officer. About CMMC Level 2 maps directly to the 110 requirements in NIST SP 800-171 Revision 2. Level 3 adds 24 additional requirements drawn from NIST SP 800-172 for higher-level protection.

Verify Dissemination Controls

The baseline rule is that CUI can be shared with anyone who needs it for a lawful government purpose and is not otherwise prohibited from receiving it. Documents may narrow that through Limited Dissemination Controls, which appear in the banner. Only the designating agency can apply an LDC. Common ones include:

  • NOFORN (NF), which prohibits sharing with foreign governments, foreign nationals, international organizations, or non-U.S. citizens in any form.
  • FEDCON, which limits distribution to federal employees and contractors.
  • FED ONLY, which limits distribution to federal employees.

The full list is published in the CUI Registry.10National Archives. CUI Registry: Limited Dissemination Controls Confirm that any LDC on the document matches an approved control in the Registry and that the designating agency, not a downstream holder, applied it.

Check Decontrol and Destruction Status

CUI does not stay CUI forever. Under 32 CFR 2002.18, agencies should decontrol as soon as practicable once the underlying authority no longer requires protection.11eCFR. 32 CFR 2002.18 – Decontrolling Decontrol can happen automatically when the governing law no longer applies, when the agency proactively releases the information, when a preset date or event occurs, or through an affirmative decision by the designating agency. An authorized holder can also request that the designating agency decontrol specific information.

Two points trip people up during a review. Decontrolling CUI removes the CUI Program handling obligation but does not automatically authorize public release.11eCFR. 32 CFR 2002.18 – Decontrolling And unauthorized disclosure never counts as decontrol. Leaked CUI is still CUI.

When approved records disposition schedules allow destruction, the regulation requires methods that render the information unreadable, indecipherable, and irrecoverable. If the governing authority specifies a method, use it; otherwise, follow NIST SP 800-53 and NIST SP 800-88 (Guidelines for Media Sanitization).5eCFR. 32 CFR 2002.14 – Safeguarding For paper, that typically means cross-cut shredding. For electronic media, sanitization ranges from secure erase to physical destruction depending on the media.

Confirm Incident Reporting Is in Place

Reviewing CUI handling includes confirming that the organization can respond when something goes wrong. Defense contractors operating under DFARS 252.204-7012 must report cyber incidents involving Covered Defense Information to the DoD Cyber Crimes Center within 72 hours of discovery, preserve malicious software and affected system images for 90 days for damage assessment, and, if a subcontractor experiences the incident, pass the incident report number up to the prime as soon as possible.12Department of Defense Cyber Crime Center. Mandatory and Voluntary Cyber Incident Reporting Federal agencies handle CUI incidents through their internal processes, but the principle is the same: unauthorized disclosure must be reported, investigated, and addressed. A review should verify that the incident response plan actually covers these obligations.

Sanctions and Trained Holders

The regulation does not set a uniform penalty schedule. Under 32 CFR 2002.56, each agency develops its own sanctions policy consistent with the discipline authority the agency head already has, and where a specific CUI category’s authorizing law sets sanctions, agencies must follow those.13eCFR. 32 CFR 2002.56 – Sanctions for Misuse of CUI Consequences for mishandling can range from retraining and letters of reprimand to loss of access, contract termination for non-federal partners, and criminal prosecution when the underlying statute allows it.

Finally, a review that ends with the document should not ignore the person who designated it. The authorized holder is responsible for knowing the CUI categories, determining Basic versus Specified, applying the correct markings, and recognizing when decontrol is appropriate. If a document fails review at the marking or designation stage, that failure usually traces back to a holder who was not trained to the standard the program requires.