DoDI 5200.48 is the Department of Defense instruction that governs how everyone in the defense enterprise identifies, marks, protects, shares, and destroys Controlled Unclassified Information. It implements Executive Order 13556 and 32 CFR Part 2002, and it replaced the patchwork of older labels like “For Official Use Only” with a single framework.1Department of Defense. DoDI 5200.48 – Controlled Unclassified Information (CUI) If you wear a uniform, work as a DoD civilian, or hold a defense contract that touches DoD-originated information, this is the rulebook.
Who Has to Follow It
The scope reaches active-duty military, DoD civilian employees, and every contractor or subcontractor that handles DoD-originated information. External partners receiving CUI through contracts, grants, or other agreements meet the same handling standards as internal DoD personnel.1Department of Defense. DoDI 5200.48 – Controlled Unclassified Information (CUI)
For contractors, DFARS clause 252.204-7012 makes CUI protection contractually enforceable. It requires safeguarding “covered defense information” on contractor systems and reporting cyber incidents to DoD within 72 hours of discovery.2Acquisition.GOV. DFARS 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting The clock starts when the contractor discovers the incident, not when the investigation wraps up, which catches many organizations off guard.3eCFR. 48 CFR 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting
How CUI Is Categorized
Not every piece of CUI is handled identically. The program splits information into two categories based on what the underlying law demands.
CUI Basic covers information where the authorizing law requires protection but does not specify how. These documents follow the uniform controls in 32 CFR Part 2002, and most CUI you will see falls here. CUI Specified applies where the authorizing law or regulation dictates particular handling procedures beyond the baseline. You follow those specific instructions; where the law is silent on a control, CUI Basic rules fill the gap.4National Archives. Controlled Unclassified Information (CUI) – CUI Glossary
Every CUI designation traces back to a specific law, regulation, or government-wide policy listed in the CUI Registry maintained by the National Archives.5National Archives. CUI Registry You cannot label a document CUI just because the content feels sensitive.
Limited Dissemination Controls
On top of the Basic/Specified split, a document can carry a Limited Dissemination Control that narrows who may access it:
- FED ONLY restricts access to federal executive branch employees and armed forces personnel.
- FEDCON allows federal employees and contractors working in support of the contract.
- NOCON blocks contractors but allows state, local, or tribal employees.
- DL ONLY limits access to individuals or organizations on an attached dissemination list.
- NOFORN prohibits sharing with foreign governments, foreign nationals, or international organizations in any form.6DoD CUI Program. Limited Dissemination Controls
Where no LDC appears, any person with a lawful government purpose may access the CUI. That term is defined in regulation as any activity, mission, or function the U.S. Government authorizes or recognizes as within the scope of its legal authorities, including those of non-executive-branch entities like state or local law enforcement.7eCFR. 32 CFR 2002.4 – Definitions The absence of an LDC does not mean a document is cleared for public release.
How to Mark a CUI Document
Marking is where most mistakes happen. Every downstream handler relies on those markings to know what protections apply, so the instruction is exacting.
Banner and Footer
The acronym “CUI” must appear as a bold, capitalized, centered banner at the top and bottom of every page. Once a document starts being marked, every page carries the banner. Any LDCs or CUI Specified categories go on the banner line of the first page.8DoD CUI Program. Banner Line Categories and LDCs do not repeat on every page because that detail lives in the designation indicator block.
Designation Indicator Block
The first page also carries a designation indicator block in the lower right corner or footer, containing four items:
- Controlled by: the originating organization and specific office; contractors put their company name here.
- CUI Category: all categories present in the document, using approved abbreviations from the CUI Registry.
- Distribution/LDC: either the applicable distribution statement or the limited dissemination control, not both.
- POC: name and phone number of the document creator, or the originating office’s mailbox.9DoD CUI Program. CUI Designation Indicator Block
Portion Markings
Portion markings are optional under DoDI 5200.48. If an organization chooses to use them, every section, paragraph, or similar portion known to contain CUI gets “(CUI)” in front, and uncontrolled portions get “(U).” Portion markings become mandatory when CUI sits inside a classified document, where CUI paragraphs need to be distinguished from classified ones.1Department of Defense. DoDI 5200.48 – Controlled Unclassified Information (CUI)
How to Store and Protect It
The safeguarding standard under 32 CFR Part 2002 comes down to “reasonable precautions.” You establish a controlled environment that keeps unauthorized people from accessing or observing CUI, and outside that environment you keep the information under your direct control or behind at least one physical barrier.10eCFR. 32 CFR 2002.14 – Safeguarding
For paper, that usually means a locked desk, filing cabinet, or restricted room, with the space secured when you leave. An unlocked office with CUI folders on the desk is exactly the kind of scene that triggers an incident report.
For digital information, federal systems storing CUI comply with FIPS 199, FIPS 200, and NIST SP 800-53 controls.10eCFR. 32 CFR 2002.14 – Safeguarding Contractor systems follow NIST Special Publication 800-171, which applies at Revision 2 for CMMC assessment purposes and lays out 110 security requirements covering access control, encryption, audit logging, and incident response on nonfederal networks.11Computer Security Resource Center. NIST SP 800-171 Rev. 3 – Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations Removable media such as USB drives must use FIPS-validated hardware encryption with controlled access.
How to Share and Transmit CUI
You can share CUI when a lawful government purpose exists between you and the recipient, meaning the information is necessary for an official task, contractual obligation, or authorized government function.7eCFR. 32 CFR 2002.4 – Definitions Any LDC on the document tightens that further.
Digital transmission requires encrypted channels: encrypted email, secure file transfer portals, or approved collaboration platforms. Unencrypted email is never appropriate for CUI, even inside an internal network.
Physical mail can go through the U.S. Postal Service or a commercial delivery service, with in-transit tracking recommended. Packages are addressed to a specific recipient, and no CUI markings or indicators appear on the outside of the envelope.12eCFR. 32 CFR Part 2002 – Controlled Unclassified Information (CUI) If someone intercepts the package, nothing on the outside should signal sensitive contents.
Training and the Non-Disclosure Agreement
Before anyone gains CUI access, two things happen. They complete training on the categories they will encounter, and they sign a CUI Non-Disclosure Agreement. The NDA requires initialing each CUI category the person may access and attesting to the safeguarding requirements under 32 CFR Part 2002 and any applicable agency-specific guidance.13Defense Counterintelligence and Security Agency. DOD-CUI Non-Disclosure Agreement
Those obligations do not expire when a contract ends or an employee changes roles. They remain in effect for as long as the information stays controlled, unless the signer receives a written release from an authorized representative. Violating the NDA can result in CUI access revocation and administrative, disciplinary, civil, or criminal action depending on the governing law.13Defense Counterintelligence and Security Agency. DOD-CUI Non-Disclosure Agreement
DoD contractors take CUI awareness training annually. Personnel governed by the broader 32 CFR 2002 framework train at least every two years.14Defense Counterintelligence and Security Agency. CUI Training Reference Guide for Industry DCSA offers a mandatory DoD CUI training that satisfies the requirement for both government and industry personnel when their contracts call for it.15Defense Counterintelligence and Security Agency. DoD Mandatory Controlled Unclassified Information (CUI) Training
CMMC and Contractor Verification
The Cybersecurity Maturity Model Certification program verifies that contractors actually meet CUI protection requirements before winning contracts. It has three levels.
- Level 1 covers Federal Contract Information only, not CUI. It requires an annual self-assessment against 15 security requirements from FAR clause 52.204-21.
- Level 2 covers CUI. It requires compliance with all 110 security requirements in NIST SP 800-171 Revision 2. Assessment is either self-assessment or an independent evaluation by a CMMC Third-Party Assessment Organization, depending on the solicitation. Either way, assessment renews every three years with annual affirmation of continued compliance.
- Level 3 covers CUI against advanced persistent threats. It requires achieving Level 2 first, then meeting 24 additional requirements from NIST SP 800-172, assessed by the Defense Industrial Base Cybersecurity Assessment Center every three years.16Department of Defense Chief Information Officer. About CMMC
Rollout is phased. Phase 1, from November 2025 through November 2026, focuses on Level 1 and Level 2 self-assessments appearing in solicitations. Phase 2 begins in November 2026, when solicitations may start requiring Level 2 third-party certification, though DoD can delay that requirement to an option period.16Department of Defense Chief Information Officer. About CMMC Building documentation and technical infrastructure for 110 NIST controls takes most organizations six months to a year, and assessment scheduling adds more lead time.
One point of confusion worth flagging: NIST published SP 800-171 Revision 3 in 2024, but CMMC assessments still measure against Revision 2. DoD needs separate rulemaking to point CMMC at Revision 3, and that change is not expected during the current phase of implementation.
Destruction and Decontrol
When CUI is no longer needed and records disposition schedules allow, it is destroyed in a way that renders the information unreadable and irrecoverable.10eCFR. 32 CFR 2002.14 – Safeguarding
For paper, the standard is a cross-cut shredder producing particles no larger than 1 mm by 5 mm, or a disintegrator with a 3/32-inch security screen.17Defense Counterintelligence and Security Agency. Guidance for Destroying Controlled Unclassified Information Regular strip-cut shredders do not meet the standard. For electronic media, NIST SP 800-88 governs sanitization, including clearing, purging, or physical destruction depending on sensitivity and reuse plans.18National Archives and Records Administration. Controlled Unclassified Information Destruction
Decontrol is separate from destruction. When the reason for protecting a document no longer applies, the designating agency can remove its CUI status. Where feasible, agencies include a decontrol date or triggering event at the time of designation. If a specific decontrol date appears on the document, authorized holders can treat it as decontrolled automatically when that date arrives, without contacting the originator.19eCFR. 32 CFR 2002.20 If the trigger is an event rather than a date, the designator includes contact information so holders can verify the event occurred.
What Happens When CUI Is Mishandled
DoDI 5200.48 requires DoD components to establish procedures for responding to CUI misuse, including improper designation, incorrect markings, and unauthorized disclosure. In most cases, the emphasis falls on correcting the conditions that led to the incident.1Department of Defense. DoDI 5200.48 – Controlled Unclassified Information (CUI)
Unauthorized disclosure does not automatically trigger a formal investigation. An inquiry becomes necessary when the command intends to pursue disciplinary action against the responsible individual. Some categories carry steeper consequences on their own. Unauthorized disclosure of export-controlled technical data, for example, can result in civil and criminal sanctions under the governing export control statutes.1Department of Defense. DoDI 5200.48 – Controlled Unclassified Information (CUI)
Senior leaders, contracting officers, and supervisors are expected to take administrative, legal, or disciplinary action proportional to the severity of the mishandling and the requirements of the applicable law. For contractors, a serious CUI breach can jeopardize eligibility for future DoD contracts, especially as CMMC assessments become standard in solicitations.