Executive Order 13556: CUI Marking, Safeguarding, and Contractor Duties

Executive Order 13556, signed by President Obama on November 4, 2010, established a single government-wide system for handling sensitive unclassified information across the executive branch.1The White House. Executive Order 13556 – Controlled Unclassified Information Before the order, each agency invented its own labels for information that wasn’t classified but still needed protection, producing a tangle of markings like “For Official Use Only,” “Sensitive But Unclassified,” and “Law Enforcement Sensitive” that nobody could apply consistently across agency lines. The order replaced all of them with one framework, Controlled Unclassified Information (CUI), backed by binding regulations at 32 CFR Part 2002.2eCFR. 32 CFR Part 2002 – Controlled Unclassified Information The National Archives and Records Administration was designated Executive Agent for the program.

What CUI Is, and What It Isn’t

CUI is information the government creates or holds, or that an outside entity creates on the government’s behalf, when a law, regulation, or government-wide policy calls for safeguarding or dissemination limits.3eCFR. 32 CFR 2002.4 – Definitions It sits between fully public information and material classified under national security authorities. Information classified under Executive Order 13526 or the Atomic Energy Act is not CUI.1The White House. Executive Order 13556 – Controlled Unclassified Information

The regulation splits CUI into two tiers. CUI Basic is the default: the underlying law requires protection but doesn’t spell out how, so agencies follow the uniform handling rules in 32 CFR Part 2002 and the CUI Registry. CUI Specified applies when the authorizing statute or regulation dictates its own handling controls that differ from the Basic baseline. Specified controls aren’t necessarily stricter, just different, because a specific authority spells them out. Protected health information under HIPAA is a common example.3eCFR. 32 CFR 2002.4 – Definitions

Legacy Markings Are No Longer Authorized

One of the order’s core purposes was killing off the dozens of ad hoc agency labels. Markings like FOUO, SBU, and LES no longer carry legal weight under the CUI framework, and agencies must remark legacy documents when they are used, shared, or otherwise put back into active circulation.4DoD CUI Program. DoD CUI Program The volume of older records means the remarking effort is ongoing, but the rule itself is clear: old labels are dead letters.

The National CUI Registry

The National CUI Registry, maintained by the National Archives, is the single authoritative list of every approved CUI category and subcategory. Each entry identifies whether the category is Basic or Specified, points to the governing statute or regulation, and shows the correct markings.5National Archives. CUI Categories List If a type of information isn’t in the Registry, agencies cannot treat it as CUI or invent their own restrictive labels for it. That rule was a significant shift from the pre-2010 practice of letting individual offices apply “sensitive” labels at will.

The Registry covers a broad range of information, from immigration records and tax return data to critical infrastructure security details and nuclear safety information. Privacy Information, for instance, traces back to the Privacy Act.6National Archives. CUI Category: Privacy Information Anyone handling government data can check the Registry to verify whether their information actually qualifies for CUI treatment and what authority backs the protection.

How CUI Must Be Marked

Every document containing CUI carries a banner marking on each page that includes CUI. The banner has up to three elements: the CUI control marking itself (either “CONTROLLED” or “CUI”), any category or subcategory markings if the information is CUI Specified, and any limited dissemination controls that apply.7GovInfo. 32 CFR Part 2002 Section 2002.20 The same banner appears on every CUI-bearing page and reflects all CUI in the document.

Every CUI document also needs a designation indicator identifying the agency that designated the information. That can be agency letterhead or a simple “Controlled by” line on the first page or cover; it doesn’t need to repeat on every page.7GovInfo. 32 CFR Part 2002 Section 2002.20 For electronic files, the Department of Defense requires CUI markings in both the banner and footer of unclassified documents, and agencies are expected to integrate metadata tagging so CUI can be discovered and tracked.8Executive Services Directorate. DoD Instruction 5200.48, Controlled Unclassified Information When physical CUI leaves the office or an approved telework location, it goes in an opaque envelope with Standard Form 901, the official CUI cover sheet, on top.9DoD CUI Program. CUI Cover Sheets

Safeguarding Standards

The regulation obligates authorized holders to take “reasonable precautions” against unauthorized disclosure. In practice, that means establishing controlled environments where unauthorized people cannot access or observe CUI, and keeping CUI under direct control or behind at least one physical barrier when outside those environments.2eCFR. 32 CFR Part 2002 – Controlled Unclassified Information

For digital systems, federal agencies must protect CUI in accordance with FIPS Publication 199, FIPS Publication 200, and NIST Special Publication 800-53, which together set security categorization and minimum controls for federal information systems.2eCFR. 32 CFR Part 2002 – Controlled Unclassified Information That translates into encrypted storage, individual-account access controls, and audit logging.

Before sharing CUI, an authorized holder must reasonably expect that every intended recipient has a lawful government purpose to receive it. That purpose covers any activity, mission, or function the U.S. government authorizes or recognizes as within its legal authorities, and can include non-executive-branch entities like state and local law enforcement.3eCFR. 32 CFR 2002.4 – Definitions Electronic transmission runs through approved secure systems using protections like Public Key Infrastructure or transport layer security.8Executive Services Directorate. DoD Instruction 5200.48, Controlled Unclassified Information

Limited Dissemination Controls

Only the agency that designated the information as CUI can apply limited dissemination controls, and only from an approved list. The most commonly encountered are:

  • NOFORN (NF): cannot be shared with foreign governments, foreign nationals, or international organizations.
  • FED ONLY: restricted to federal executive branch employees and armed forces personnel.
  • FEDCON: limited to federal employees, armed forces personnel, and contractors working under a government contract.
  • NOCON: no dissemination to contractors, though state, local, and tribal employees may still receive it.
  • DL ONLY: restricted to individuals or entities named on an accompanying dissemination list.

Additional controls exist for specialized contexts, including REL TO for pre-approved foreign release and DISPLAY ONLY where foreign recipients may view but not retain physical copies.10National Archives. Limited Dissemination Controls Any control not on the approved list is a violation of the regulation.

Decontrol and Destruction

CUI status does not last forever. Decontrol removes the safeguarding and dissemination controls and can happen automatically when the designating agency publicly releases the information, when a statute triggers release, when the need for control ends under the governing authority, or when a pre-set date or event in a decontrol indicator arrives.11National Archives. CUI Decontrol and Disposal The designating agency can also decontrol CUI on request or on its own initiative.

One nuance matters. Public release always results in decontrol, but decontrolled information may still be restricted under other authorities, so decontrol is not the same as public release. All CUI markings must be removed or struck through before reuse or donation. And one hard limit: information cannot be decontrolled to cover up an unauthorized disclosure.11National Archives. CUI Decontrol and Disposal

When CUI is destroyed rather than decontrolled, NIST Special Publication 800-88 Revision 1 sets the standards, defining three sanitization tiers (Clear, Purge, and Destroy) and specific requirements for paper, optical media, and flash storage.12National Institute of Standards and Technology. Guidelines for Media Sanitization (NIST Special Publication 800-88 Revision 1) Organizations are expected to document sanitization actions and periodically test their equipment.

Agency Responsibilities and Training

NARA, as Executive Agent, issues guidance and oversees agency compliance.1The White House. Executive Order 13556 – Controlled Unclassified Information Each agency head must designate a CUI Senior Agency Official (SAO) in writing. The SAO implements the program within the agency, serves as primary contact with NARA, handles accountability reporting, and establishes internal processes for reporting and investigating misuse of CUI.2eCFR. 32 CFR Part 2002 – Controlled Unclassified Information

The regulation does not set a single government-wide deadline for reporting CUI incidents. Each agency defines its own reporting timelines and procedures, and the CUI Executive Agent reports misuse findings to the offending agency’s SAO or program manager for action. Reporting timelines therefore vary across departments.

Agencies must train employees on CUI when they begin work and at least once every two years thereafter.2eCFR. 32 CFR Part 2002 – Controlled Unclassified Information Training covers designation, categories and subcategories, use of the CUI Registry, marking, and the applicable safeguarding, dissemination, and decontrolling procedures. Non-compliance can result in loss of access to sensitive data, formal reprimands, or suspension without pay.

What the Order Means for Contractors

The CUI program reaches well beyond federal employees. Any non-federal organization that processes, stores, or transmits CUI on behalf of the government must meet security requirements tailored to that environment, and this is where most real-world compliance work happens.

NIST SP 800-171

NIST Special Publication 800-171 sets the security requirements for protecting CUI on non-federal systems. Revision 3, published in May 2024, organizes requirements across 17 security families covering access control, incident response, supply chain risk management, and more.13National Institute of Standards and Technology. Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (SP 800-171 Rev. 3) As of 2026, however, the Department of Defense still requires contractors to comply with Revision 2 for DFARS and CMMC purposes. A transition to Revision 3 is expected, and contractors should prepare for both.

DFARS 252.204-7012

Defense contractors encounter CUI obligations primarily through DFARS clause 252.204-7012, which appears in nearly all DoD contracts except those exclusively for commercial off-the-shelf items. The clause requires contractors to implement NIST SP 800-171, report cyber incidents to the DoD within 72 hours of discovery, submit isolated malicious software to the DoD Cyber Crime Center, and cooperate with damage assessments.14eCFR. 48 CFR 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting Contractors document compliance through a System Security Plan, and any control they cannot meet must be addressed through a written explanation proposing an alternative measure of equivalent protection.15Department of Defense. Safeguarding Covered Defense Information – The Basics These requirements flow down to subcontractors whose work involves covered defense information.

CMMC Certification

The Cybersecurity Maturity Model Certification program adds a verification layer on top of DFARS. Instead of taking contractors at their word, CMMC requires demonstrated compliance as a condition of contract award.16DoD CIO. CMMC About The tiers:

  • Level 1: foundational protection for Federal Contract Information, based on basic safeguarding practices.
  • Level 2: broad protection for CUI, requiring compliance with the 110 security requirements in NIST SP 800-171 Revision 2. Assessment is either a self-assessment or an independent evaluation by an accredited third-party assessment organization (C3PAO), conducted every three years with annual affirmation.
  • Level 3: higher-level protection against advanced persistent threats, requiring all Level 2 controls plus 24 additional requirements from NIST SP 800-172, assessed by the Defense Contract Management Agency every three years.

CMMC Phase 1 implementation began on November 10, 2025, and runs through November 9, 2026, focused on Level 1 and Level 2 self-assessments.17DoD CIO. Cybersecurity Maturity Model Certification Phase 2, starting November 10, 2026, is expected to require Level 2 certification assessments by a C3PAO for contracts involving CUI.

The Proposed FAR CUI Rule

DFARS requirements have applied to defense contractors for years. A proposed Federal Acquisition Regulation rule published in early 2025 would extend CUI safeguarding requirements across all civilian federal agencies’ contracts as well.18Federal Register. Federal Acquisition Regulation: Controlled Unclassified Information If finalized, contractors working with any federal agency will face standardized CUI protection obligations in their contracts, significantly expanding the population of contractors under formal compliance requirements.

False Claims Act Exposure

Failing to protect CUI can cost more than access privileges or a reprimand. The Department of Justice’s Civil Cyber-Fraud Initiative, launched in October 2021, uses the False Claims Act against contractors who knowingly misrepresent their cybersecurity compliance. It targets three categories of conduct: failing to comply with contractual cybersecurity standards, misrepresenting security controls during the contracting process, and failing to promptly report suspected cyber incidents.

False Claims Act penalties include treble damages plus per-claim penalties that currently range from $14,308 to $28,619. Settlements in the millions have already resulted from allegations that contractors misrepresented their cybersecurity posture or failed to disclose that they were not securely storing protected records as required by contract. If a System Security Plan claims a control that isn’t actually deployed, that gap can form the basis of an enforcement action.