FOUO vs. CUI: Tiers, Marking, and Handling Rules

For Official Use Only (FOUO) is a legacy Department of Defense marking that has been replaced government-wide by Controlled Unclassified Information (CUI), and any comparison of FOUO vs. CUI comes down to this: agencies can no longer apply FOUO to new documents, CUI is the only authorized framework going forward, and existing FOUO markings stay valid only until a document is edited or reprocessed. At that point, the CUI format takes over.

Why FOUO Was Replaced

FOUO began as a DoD control marking for unclassified information that could be withheld under one or more Freedom of Information Act exemptions. Under DoD Manual 5200.01, if releasing a record would cause foreseeable harm to a FOIA-protected interest, the document got an FOUO stamp.1Department of Defense. DoDM 5200.01, Volume 2 – DoD Information Security Program

The problem was that FOUO sat alongside dozens of similar labels used by other agencies: Sensitive But Unclassified, Law Enforcement Sensitive, For Official Use Only – Law Enforcement, and more. Each had its own handling rules, and once a document crossed agency lines, nobody could be sure which rules applied. Executive Order 13556, signed in 2010, called the arrangement “inconsistent, inefficient, and confusing” and established CUI as a single uniform standard.2The White House Archives. Executive Order 13556 – Controlled Unclassified Information The implementing regulation, 32 CFR Part 2002, spells out marking, handling, and sharing rules, and the Information Security Oversight Office at the National Archives runs the program across the executive branch.3National Archives. Controlled Unclassified Information

How FOUO and CUI Actually Differ

The switch was not just a name change. Several things about how the information gets protected changed with it.

  • Scope. FOUO applied mainly within DoD and a few other agencies. CUI reaches the entire executive branch and extends to contractors and other non-federal organizations that handle government information.
  • Legal basis. FOUO was tied to FOIA exemptions. Every CUI category, by contrast, points to a specific law, regulation, or government-wide policy that requires or permits protection, whether or not a FOIA exemption also covers it.
  • Marking standards. FOUO markings varied between agencies. CUI marking rules are rigid and centralized, covering banner lines, designation indicators, and portion markings.
  • Registry. FOUO had nothing like the CUI Registry, the public database at the National Archives that lists every approved CUI category and cites the legal authority behind it.4National Archives. Controlled Unclassified Information (CUI) – Category List
  • Dissemination controls. CUI introduced standardized distribution limits, such as NOFORN and FED ONLY, that FOUO never carried.

The Two Tiers of CUI

CUI splits into two tiers based on how much control the underlying law demands. Anyone used to FOUO’s flat approach needs to know which tier applies before handling a document.

CUI Basic covers categories where the authorizing law requires protection but doesn’t spell out specific handling procedures. The uniform controls in 32 CFR Part 2002 and the CUI Registry apply. Standard safeguarding, standard access, standard markings.5National Archives. CUI Registry – CUI Glossary

CUI Specified covers categories where the authorizing law itself prescribes particular handling requirements that differ from, and are often stricter than, the baseline. Certain tax return information and intelligence source data are examples: their handling rules come straight from the statute. The CUI Registry flags Specified categories and points to the controlling authority. Where a Specified category’s law is silent on a specific handling question, CUI Basic controls fill the gap.5National Archives. CUI Registry – CUI Glossary

How CUI Documents Are Marked

If you’re used to an FOUO stamp in the corner of a page, CUI marking is more structured. Every CUI document carries a banner line at the top and bottom of each page reading “CUI” or “CONTROLLED” in capital letters. When the document contains CUI Specified information, the banner adds the relevant category abbreviations separated by double forward slashes, such as “CUI//SP-CTI” for specified counter-terrorism information. The CUI Registry lists the exact abbreviation for each category.

The first page also has to include a Designation Indicator block naming the originating agency, the originating office, and a point of contact. That’s who a reader calls to ask whether the information can go further.

Portion markings tag individual paragraphs. “(CUI)” goes at the start of each controlled paragraph so a reader scanning a mixed document knows which parts carry restrictions. For CUI Specified paragraphs, the portion marking uses the category abbreviation instead.

Who Can Receive CUI

Access to CUI turns on what the regulation calls a “lawful government purpose”: the recipient needs the information to do their job and is not blocked by a dissemination control or underlying law.6eCFR. 32 CFR 2002.16 – Accessing and Disseminating Unlike classified information, CUI does not require a security clearance. That’s one of the bigger practical shifts from classified handling, and it carried over from FOUO.

What did not exist under FOUO is the layer of standardized dissemination controls a designating agency can attach to a document. Only the originating agency can apply them, and they must come from the approved list in the CUI Registry.7National Archives. CUI Registry – Limited Dissemination Controls The common ones:

  • NOFORN. No sharing with foreign governments, foreign nationals, or international organizations.
  • FED ONLY. Federal executive branch employees and active military personnel only.
  • FEDCON. Federal employees and contractors working under a relevant government contract.
  • NOCON. Blocks federal contractors but allows state, local, or tribal government employees.
  • REL TO. Pre-approved for release to specified foreign countries or international organizations.
  • DL ONLY. Restricted to those on an accompanying dissemination list.

These appear in the banner line after the CUI marking and category indicators. If you receive CUI and want to tighten restrictions further, you have to ask the designating agency. You cannot unilaterally add controls to someone else’s information.

Storing, Sending, and Destroying CUI

Physical CUI stays in locked drawers or locked offices when not in active use. In transit, it goes in opaque envelopes so markings don’t show. Electronic transmissions require encryption validated under federal standards. The longstanding reference has been FIPS 140-2, but FIPS 140-3 superseded it in 2019, and all remaining FIPS 140-2 certificates move to the historical list on September 22, 2026, so organizations should be moving to FIPS 140-3 validated modules now.8NIST. FIPS 140-3 Transition Effort Sending CUI over unencrypted personal email is prohibited.

CUI is not meant to stay controlled forever. Agencies should remove the designation as soon as the information no longer needs protection.9eCFR. 32 CFR 2002.18 – Decontrolling Automatic triggers include the underlying law no longer applying, a proactive public release, a FOIA or Privacy Act disclosure incorporated into the agency’s public release process, or a pre-set date or event written into the original designation. When you incorporate decontrolled CUI into a new document, every CUI marking has to come off.

Destroying CUI means destroying it beyond recovery. Single-step destruction of paper requires cross-cut shredding to particles no larger than 1 mm by 5 mm, or pulverizing with a disintegrator using a 3/32-inch security screen.10National Archives and Records Administration. CUI Notice 2017-02 – Controlled Unclassified Information and Multi-Step Destruction Process Standard office shredders with larger strip cuts don’t meet that threshold. Electronic media follows NIST SP 800-88 sanitization guidance, ranging from clearing to purging to physical destruction depending on the media and whether it will be reused.

What Contractors Need to Do Differently

FOUO barely touched most contractors. CUI reaches them directly. Any contractor whose systems process, store, or transmit CUI must meet specific cybersecurity requirements, and defense contractors carry the heaviest load.

DFARS clause 252.204-7012 requires defense contractors to implement the security controls in NIST Special Publication 800-171 on any covered contractor information system handling CUI.11eCFR. 48 CFR 252.204-7012 – Safeguarding Covered Defense Information The current version is NIST SP 800-171 Revision 3.12NIST. SP 800-171 Rev. 3 – Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

The Cybersecurity Maturity Model Certification program adds enforcement on top. Under CMMC 2.0, contractors handling CUI need Level 2 certification, which maps to the 110 security requirements in NIST SP 800-171 Revision 2. Depending on the sensitivity involved, a contract may require a self-assessment or an independent assessment by a CMMC Third-Party Assessment Organization. Either way the assessment is valid for three years, with an annual affirmation of continued compliance. Miss that annual affirmation and the certification lapses.13Department of Defense. About CMMC

What Happens If CUI Is Mishandled

CUI mishandling does not automatically trigger criminal prosecution the way classified information leaks can. The regulation puts enforcement in the hands of individual agencies: each agency’s CUI Senior Agency Official has to establish processes for reporting and investigating misuse, and sanctions come from whatever disciplinary authority the agency head already holds.14Federal Register. Controlled Unclassified Information In practice, that means administrative consequences ranging from a written reprimand for a first-time accidental exposure up to suspension or removal for intentional or repeated violations.

Many CUI categories sit on top of laws that carry their own penalties. Improper disclosure of tax return information is punished under the tax code. Leaking law enforcement sensitive data falls under the applicable criminal statute. CUI is the administrative overlay, and the underlying law supplies the teeth where they exist.

For contractors, mishandling CUI can mean removal from the contract, loss of CMMC certification, debarment from future government work, and civil liability. Agreements between agencies and non-federal entities must state that misuse is subject to penalties established in applicable laws and regulations.6eCFR. 32 CFR 2002.16 – Accessing and Disseminating

Training Before You Handle CUI

Anyone with access to CUI has to complete training before touching it. Within DoD, the mandatory course is IF141, offered through the Center for Development of Security Excellence. It covers accessing, marking, safeguarding, decontrolling, and destroying CUI, plus identifying and reporting security incidents. The same course satisfies training requirements for contractors when a government contracting activity specifies CUI obligations in the contract.15CDSE. DoD Mandatory Controlled Unclassified Information (CUI) Training

Other executive branch agencies run their own CUI training under the ISOO framework, but the core content tracks the same regulation. If you were trained under the old FOUO rules, CUI training is not optional. The marking conventions, dissemination controls, and incident reporting procedures have changed enough that prior FOUO familiarity does not substitute for CUI-specific instruction.