FOUO stands for “For Official Use Only,” a label federal agencies place on unclassified documents to keep them from being released to the public. It is not a security classification like Confidential, Secret, or Top Secret; it sits below that threshold, but it still carries real handling rules for anyone who touches the material.1Defense Logistics Agency. For Official Use Only (FOUO) The federal government is phasing FOUO out in favor of a program called Controlled Unclassified Information (CUI), but legacy FOUO markings still appear on millions of documents, and the protection duties that come with them are still enforceable.
What FOUO Is and Isn’t
FOUO is a handling instruction. Classified information moves through a formal process with designated classification authorities, damage assessments, and declassification schedules. FOUO skips all of that. It simply signals that an agency has decided a particular unclassified document should not be released publicly, usually because the content falls under one of the exemptions to the Freedom of Information Act.2Department of the Army Information Security. For Official Use Only (FOUO)
The practical effect: the information stays inside government channels. You do not need a security clearance to see it, but you do need an authorized reason to have it, and you are responsible for protecting it while it is in your hands.
What Kinds of Information Get an FOUO Marking
The common thread is that release could harm agency operations, compromise an investigation, or invade someone’s privacy. FOIA lists nine exemptions that let agencies withhold information, and FOUO material typically falls under one or more of them.3FOIA.gov. Frequently Asked Questions The categories that most often show up as FOUO include:
- Internal agency rules and practices, such as operational procedures, staffing plans, and internal policy drafts.
- Trade secrets and commercial information submitted by companies during procurement or regulatory processes.
- Privileged communications, including deliberative drafts, attorney-client material, and pre-decisional memos.
- Personal information whose release would be an unwarranted invasion of privacy.
- Law enforcement records, including investigative files, informant identities, and surveillance techniques.
Other FOIA exemptions cover national defense information (which usually goes through classification instead), financial institution supervision data, and geological well data, but those are less common bases for an FOUO marking.4Department of Justice. What Are the 9 FOIA Exemptions
How to Recognize an FOUO Document
The markings follow set rules so anyone handling a document can see its status at a glance. On paper, “FOR OFFICIAL USE ONLY” appears at the bottom of the front cover, title page, first page, and outside back cover. Every interior page containing FOUO information carries the marking at the bottom as well.1Defense Logistics Agency. For Official Use Only (FOUO) Army rules require the marking in bold letters at least 3/16 of an inch high.5GovInfo. 32 CFR Part 518 Subpart D – For Official Use Only
Inside a document, individual paragraphs holding FOUO content are flagged with “(FOUO)” at the start. That matters in mixed documents, where some sections are protected and others can be shared freely. The paragraph marker tells you exactly which portions need to stay controlled.
Electronic media, slides, films, and databases also require FOUO markings. For a database, a common approach is to note in the opening screen or footer which columns, rows, or fields contain FOUO data.1Defense Logistics Agency. For Official Use Only (FOUO) When a classified document contains a page with only FOUO content and no classified information, that page is marked “For Official Use Only” at the bottom instead of the higher classification banner.5GovInfo. 32 CFR Part 518 Subpart D – For Official Use Only
How You’re Expected to Handle It
Storage is straightforward. Keep FOUO material out of view of unauthorized people. During the workday, that means minimizing the risk of someone reading your screen or picking a document off your desk. After hours, if your building does not have continuous monitoring or controlled entry, FOUO documents go into a locked desk, file cabinet, or similar container.6Department of Defense CUI. Storage Requirements Facilities with 24-hour security or badge-controlled access meet the requirement on their own, since the building itself is the barrier.
Before sending FOUO material outside your organization, confirm both who the recipient is and that they have a work reason to see it. Email containing FOUO should be encrypted or travel through a secure system. Where encryption is impractical, agencies allow FOUO on regular email channels, and a common workaround is to place the sensitive content in a password-protected attachment and send the password separately.7Department of Homeland Security. Safeguarding Sensitive But Unclassified (For Official Use Only) Information Sending FOUO to a personal email account is prohibited.
FOUO information must not be posted on any publicly accessible website. A site restricted to .mil or .gov visitors is not automatically acceptable either, because that kind of filter is easy to bypass. Posting FOUO to any website requires at a minimum certificate-based authentication (such as a Common Access Card) or a password-and-ID combination, plus encrypted transmission over HTTPS.8Department of Defense Inspector General. DoD Manual 5200.01 Volume 3
When an FOUO document is no longer needed, destroy it in a way that prevents reconstruction. Shredding is the standard method. Burning and pulverizing also qualify. FOUO destruction does not require the witnessed, documented procedures that apply to classified material, but the outcome has to be the same: no one can piece the information back together.
Who Can Access FOUO Material
Access runs on need to know, not clearance level. If your job requires the information and you are authorized to receive it, you can see FOUO material whether or not you hold a clearance. A Top Secret clearance does not give you a right to browse FOUO files outside your job function. The originating office keeps authority over who gets access and can add restrictions on top of the baseline rules.
Designation authority is broader than most people assume. At the Department of Homeland Security, any employee, detailee, or contractor can mark information as FOUO if it fits a recognized category, and supervisors can designate information from their jurisdiction even when it does not fit neatly into a predefined slot.7Department of Homeland Security. Safeguarding Sensitive But Unclassified (For Official Use Only) Information Other agencies set narrower rules, so the specifics depend on where you work.
What Happens If FOUO Information Is Disclosed
FOUO does not carry the criminal penalties that come with mishandling classified information, but the consequences are still meaningful, and they vary by whether the person is military, civilian federal, or a contractor.
For service members, unauthorized release of FOUO can be charged under the Uniform Code of Military Justice as failure to obey a regulation. For civilian federal employees, the standards of conduct prohibit using nonpublic information for unauthorized purposes, and consequences run from a written reprimand to removal from federal service. An intentional release, or one that causes actual compromise, pushes the penalty range higher, and removal is possible on a first offense in that scenario.9Air Force Judge Advocate General. Disciplinary Action for Release of Non-Public Information Contractors risk removal from the contract and possible civil action under their nondisclosure agreements.
One carve-out matters. Before initiating discipline, agencies must determine whether the disclosure was protected under the Whistleblower Protection Act. Reporting fraud, waste, abuse, or a threat to public safety through appropriate channels remains protected even when the underlying information carried FOUO controls.
What to Do If FOUO Is Lost or Exposed
Report it to your agency’s security office as soon as you find out. If the incident involves a federal information system, meaning a compromised server, unauthorized database access, or a breach of an email system holding FOUO content, the agency must notify the Cybersecurity and Infrastructure Security Agency within one hour of its security team identifying the incident.10Cybersecurity and Infrastructure Security Agency. Federal Incident Notification Guidelines The initial report includes the type of information involved, the systems and users affected, and an estimated recovery timeline. Agencies report with what they have and update later as the picture sharpens.
Why FOUO Is Being Replaced by CUI
Executive Order 13556, signed in 2010, created the Controlled Unclassified Information program to replace the patchwork of agency-specific labels, including FOUO, Sensitive But Unclassified, Law Enforcement Sensitive, and dozens of others, with one standardized system across the executive branch. The order called the existing approach inefficient and confusing, and said it caused inconsistent protection and needless barriers to information sharing between agencies.11The White House. Executive Order 13556 – Controlled Unclassified Information
The implementing rule, 32 CFR Part 2002, is blunt about legacy markings: if an old FOUO marking is still on a document that has not been re-marked under the CUI program, that marking is void and does not, by itself, indicate the information is protected or qualifies as CUI.12eCFR. 32 CFR Part 2002 – Controlled Unclassified Information
That does not mean old FOUO documents can be ignored. Agencies are required to review pre-2016 material and re-mark anything that qualifies as CUI. Where re-marking every document would be excessively burdensome, the agency’s CUI Senior Agency Official can grant a waiver and permit an alternate marking method.12eCFR. 32 CFR Part 2002 – Controlled Unclassified Information
The rule that matters most in daily work: when you pull information out of a legacy FOUO document and drop it into something new, you have to evaluate whether the content qualifies as CUI and mark the new document that way. Within the Department of Defense, legacy FOUO material does not need to be re-marked while it stays inside DoD or is downloaded from DoD systems for internal DoD use. Once that information moves into a new product or goes to an external recipient, the CUI marking rules apply.13Center for Development of Security Excellence. Controlled Unclassified Information Toolkit
A Note for Contractors
If you receive CUI (including information that used to be marked FOUO) on your company’s own systems, a separate framework applies. The baseline is NIST Special Publication 800-171, which sets out 14 families of security requirements covering access control, encryption, incident response, and personnel screening, among others.14National Institute of Standards and Technology. NIST Special Publication 800-171 Revision 2 Those requirements apply when the data is designated as CUI and the contract explicitly references both the CUI content and the obligation to follow NIST 800-171.