CUI Must Be Reviewed Before Destruction: Retention and Holds

Reviewing CUI before destruction means confirming, in order, that the originating agency no longer needs the information, that a NARA-approved records disposition schedule authorizes disposal, that no litigation or audit hold covers the material, and that the destruction method you plan to use meets the standard for that media type. Federal regulation doesn’t use the word “review,” but 32 CFR 2002.14(f) sets preconditions that can’t be met without one, and skipping the check has cost contractors millions in False Claims Act settlements.1eCFR. 32 CFR 2002.14 – Safeguarding

The Two Conditions That Must Both Be True

Under 32 CFR 2002.14(f), an authorized holder may destroy CUI only when the agency that controls the information no longer needs it and a records disposition schedule published or approved by the National Archives and Records Administration permits destruction at that point. Both conditions have to be satisfied at the same time. Missing either one makes the destruction unlawful, regardless of how carefully the shredding itself is done.1eCFR. 32 CFR 2002.14 – Safeguarding

“Authorized holder” is broad. The regulation defines it as any individual, agency, organization, or group permitted to designate or handle CUI, which pulls contractors, grantees, and other non-executive-branch entities into the same rulebook when their contracts require CUI handling.2eCFR. 32 CFR 2002.4 – Definitions If you touch CUI under a federal agreement, you’re on the hook for the review.

Reading the Document Itself

Start with the markings. A properly marked CUI document tells you the category (Defense, Legal, Privacy, and so on), any limited dissemination controls, and any date-based or event-based triggers that indicate when the information becomes eligible for decontrol or destruction. The CUI Registry maintained by the National Archives is the government-wide reference for category-specific handling requirements, but NARA itself advises checking your own agency’s implementing policies first, because agencies can layer additional requirements on top of the baseline.3National Archives. Controlled Unclassified Information

Category matters because some CUI carries destruction methods prescribed by a specific law, regulation, or government-wide policy. When that’s the case, you follow the prescribed method rather than the general standards.1eCFR. 32 CFR 2002.14 – Safeguarding

Confirming the Retention Schedule Allows Disposal

The NARA schedule check is where most of the review work actually happens. Federal records may not be destroyed except under procedures established in Chapter 33 of Title 44, and every federal record has to be covered by a NARA-approved schedule before it can legally be purged.4Office of the Law Revision Counsel. 44 USC 33145National Archives. Scheduling Records

NARA’s General Records Schedules cover common categories of federal records, and their use is mandatory unless an agency can justify an agency-specific schedule.6National Archives. What Are the General Records Schedules The GRS mostly covers administrative and support records, so agencies with mission-specific CUI often maintain their own schedules. The person authorizing destruction needs to identify which schedule applies, confirm the retention period has elapsed, and verify no other constraint blocks disposal. Skipping this isn’t just a CUI issue; it’s a Federal Records Act violation.

Checking for Litigation and Audit Holds

A litigation hold freezes destruction of records that may be relevant to pending or reasonably anticipated litigation, an investigation, or an audit. Destroying material subject to a hold can trigger spoliation sanctions, and courts presume the destroyed evidence would have been unfavorable to the party who destroyed it. The hold check applies to federal agencies and contractors alike, and it has to happen before the shredder starts, not after.

Decontrol Is a Separate Decision

Decontrol and destruction get confused often enough that it’s worth stating the distinction: decontrolling CUI is an official determination that the information no longer requires safeguarding or dissemination controls; destruction is the physical or electronic elimination of the information. You can decontrol without destroying, and you can destroy without first decontrolling.

Under 32 CFR 2002.18, decontrol happens automatically when the authorizing law no longer requires CUI status, when the agency proactively releases the information publicly, when a pre-determined date or event occurs, or by affirmative decision of the designating agency. Only the designating agency or officials it specifically authorizes can make that call. A contractor holding CUI it believes is outdated can request decontrol but cannot decide unilaterally.7eCFR. 32 CFR 2002.18 – Decontrolling

One trap worth flagging: decontrolling CUI does not authorize public release, and it doesn’t automatically permit ordinary recycling. If the content includes personally identifiable information or triggers another protection, secure disposal is still required.

Matching the Method to the Media

Once the review clears the record for destruction, the method has to render the information unreadable, indecipherable, and irrecoverable. Absent a category-specific method prescribed by law, authorized holders use guidance from NIST SP 800-88 (media sanitization) and NIST SP 800-53 (security controls), or any method approved for classified national security information under 32 CFR 2001.47.1eCFR. 32 CFR 2002.14 – Safeguarding

Paper

Approved single-step methods for paper are cross-cut shredding to particles no larger than 1 mm by 5 mm, or disintegration using a 3/32-inch (2.4 mm) security screen. Organizations without equipment that meets the single-step standard can use a multi-step process or contract with a shared-service destruction group.8Defense Counterintelligence and Security Agency. Guidance for Destroying Controlled Unclassified Information

Electronic Media

NIST SP 800-88 Rev. 1 defines three sanitization levels. Clear overwrites data in user-addressable storage locations using standard read/write commands and protects against non-invasive recovery tools. Purge uses physical or logical techniques that make recovery infeasible even with laboratory methods, including degaussing for magnetic drives and cryptographic erase or block erase for SSDs. Destroy physically renders the media unable to store data through shredding, disintegration, pulverization, or incineration.9National Institute of Standards and Technology. NIST SP 800-88 Rev. 1 – Guidelines for Media Sanitization

Optical media cannot be cleared or purged and must be physically destroyed. Flash-based storage can be cleared or purged, but if neither is feasible, physical destruction is required.

Cloud and Virtual Storage

CUI in a cloud environment creates a sanitization problem because you don’t control the hardware. NIST introduced the concept of logical sanitization in SP 800-88 Rev. 2, published in September 2025, to address this.10Computer Security Resource Center. NIST SP 800-88 Rev. 2 For defense contractors, DFARS 252.204-7012 requires any external cloud service provider storing CUI to meet security requirements equivalent to the FedRAMP Moderate baseline, which means the provider’s sanitization procedures must be part of the contract and available for audit.11Acquisition.gov. DFARS 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting

Documenting the Destruction

The review is only defensible if it’s recorded. Organizations typically maintain destruction logs or certificates capturing the date, method, and CUI category of the material destroyed, and DCSA guidance specifically calls out the requirement to document all processes used.8Defense Counterintelligence and Security Agency. Guidance for Destroying Controlled Unclassified Information Best practice is the signature of the person who performed the destruction plus a witness who observed it. Contractors must make these records available for inspection by the disseminating agency.

Under NARA’s General Records Schedule 4.2, destruction-related records covering classified and CUI materials must be retained for two years after the last form entry, reply, or submission, or until the associated documents are declassified, decontrolled, or destroyed, or until an individual’s authorization expires, whichever applies. Longer retention is permitted for business needs.12National Archives and Records Administration. General Records Schedule 4.2 – Information Access and Protection Records

Extra Layers for Contractors

When agencies share CUI with non-executive-branch entities, they enter formal agreements requiring compliance with 32 CFR Part 2002 and the CUI Registry. Systems operated on behalf of an agency are treated as the agency’s own.13GovInfo. 32 CFR 2002.14 – Safeguarding

Defense contractors carry additional obligations. DFARS 252.204-7012 mandates implementation of NIST SP 800-171 for covered contractor information systems not operated on behalf of the government.11Acquisition.gov. DFARS 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting CMMC 2.0 adds practice MP.L2-3.8.3, which requires contractors to sanitize or destroy system media containing CUI before disposal or release for reuse.14Department of Defense CIO. CMMC Assessment Guide Level 2

What Skipping the Review Costs

False Claims Act enforcement has become the government’s primary tool against contractors who certify compliance with cybersecurity and information-handling rules but fall short. The statute’s definition of “knowingly” reaches deliberate ignorance and reckless disregard, so unfamiliarity with the rules isn’t a defense.

A defense contractor paid $4.6 million to settle allegations that it failed to implement required NIST SP 800-171 controls and submitted false compliance scores. A subcontractor paid over $421,000 for knowingly failing to provide adequate cybersecurity for technical drawings supplied to prime contractors. Another contractor settled for $1.75 million after allegedly providing improper access to Air Force CUI.15Mayer Brown. False Claims Act Enforcement – Record-Breaking Year Signals Continued Attention to Cybersecurity

CMMC 2.0 raises the stakes further by requiring contractual certifications and repeated affirmations of compliance, which give the government a stronger factual basis for FCA claims. Contractors who receive a conditional certification have up to 180 days to close identified gaps through a Plan of Action and Milestones. Destruction procedures that don’t meet the applicable standard are exactly the kind of gap auditors flag, and an incomplete review is what turns a compliance question into a liability one.