Is OPSEC a Dissemination Control Category in CUI?

No. OPSEC is not a dissemination control category in the Controlled Unclassified Information program. The CUI program has a short, fixed list of approved limited dissemination controls, and OPSEC is not on it. OPSEC does appear inside the CUI framework, but as a category of information and, separately, as a risk-management methodology agencies use to decide what to protect. Those are different functions from restricting who may receive a document.

The distinction matters because the two roles get collapsed in everyday conversation. A category tells you what kind of sensitive information a document contains. A dissemination control tells you who is allowed to receive it. OPSEC fills the first role in some cases. It never fills the second.

The Approved CUI Dissemination Controls

Dissemination controls are markings placed on CUI that limit who can receive the information and under what conditions. Only the designating agency may apply them, and the CUI Registry lists the only markings agencies are allowed to use. Agencies cannot invent their own.1National Archives. CUI Registry – Limited Dissemination Controls

The approved limited dissemination controls are:

  • NOFORN: No sharing with foreign governments, foreign nationals, international organizations, or non-U.S. citizens.
  • FED ONLY: Sharing restricted to federal executive branch employees and U.S. armed forces personnel, including Active Guard and Reserve. Contractors excluded.
  • FEDCON: Sharing authorized for federal employees, armed forces personnel, and contractors working under a U.S. government contract, so long as sharing supports that contract’s purpose.
  • NOCON: No sharing with contractors, even those otherwise supporting the agency.
  • DL ONLY: Sharing limited to the people, organizations, or entities named on an accompanying dissemination list. This control overrides other dissemination markings when applied.
  • REL TO: Approved for release to specific foreign countries or international organizations, identified by name in the marking, through established disclosure channels.
  • DISPLAY ONLY: A foreign recipient may view the information but may not retain a physical or digital copy.

These seven markings are the entire authorized set.2National Archives. Limited Dissemination Control Markings Designating agencies can combine them when a situation calls for more than one restriction, but they cannot substitute other labels, and they are instructed not to use these markings unnecessarily. The CUI program was built to facilitate sharing across the executive branch, not to block it.3eCFR. 32 CFR 2002.16 – Dissemination Controls OPSEC is absent from the list because it does not perform the function these markings perform.

What OPSEC Actually Is

Operations Security is a five-step analytical process for identifying and protecting unclassified information that an adversary could piece together to learn about U.S. government capabilities and intentions. National Security Decision Directive 298, signed in 1988, established the National Operations Security Program and described OPSEC as “a systematic and proved process by which the U.S. Government and its supporting contractors can deny to potential adversaries information about capabilities and intentions by identifying, controlling, and protecting generally unclassified evidence of the planning and execution of sensitive Government activities.”4Reagan Presidential Library. National Security Decision Directive Number 298

The five steps are:

  • Identify critical information: Determine what facts about intentions, capabilities, or activities would be valuable to an adversary.
  • Identify threats: Figure out who might try to collect that information and what collection methods they use.
  • Analyze vulnerabilities: Find the gaps in current practices that could expose critical information.
  • Assess risk: Weigh the likelihood and impact of each vulnerability being exploited.
  • Apply countermeasures: Put protections in place to close the vulnerabilities that pose the greatest risk.

OPSEC is a thinking process. It produces decisions about how to protect information. It is not itself a marking, a legal authority, or a dissemination restriction, and it cannot be entered in a CUI banner the way NOFORN or FED ONLY can.

Where OPSEC Does Appear in CUI: As a Category

OPSEC does exist inside the CUI system, which is a large part of why the question gets asked in the first place. It appears as a CUI category, not as a dissemination control. Information tied to an organization’s OPSEC analysis, such as a critical information list or a vulnerability assessment, can be designated as CUI under the OPSEC category. That designation only happens when the information appears on the organization’s critical information list.5DoD CUI Program. Basics of CUI

The National Archives maintains the CUI Registry, which organizes CUI into index groupings such as Privacy, Export Control, and Procurement and Acquisition, each tied to a specific legal authority that mandates its protection.6National Archives. CUI Registry – CUI Categories OPSEC sits in that structure as one category among many. The category identifies the type of information and the authority requiring its protection. It does not, by itself, tell anyone who is allowed to receive the document.

How Category and Dissemination Control Work Together

A vulnerability assessment produced through the OPSEC process might be designated as CUI under the OPSEC category and then marked with NOFORN as its dissemination control. The OPSEC category tells you what kind of information it is. The NOFORN marking tells you who can see it. Two different pieces of the CUI framework, doing two different jobs on the same document.

The banner marking on a CUI document reflects this separation. Every CUI document carries a banner on each page containing CUI, and the banner includes up to three elements: the CUI control marking (either “CONTROLLED” or the acronym “CUI”), any applicable CUI Specified category markings, and any limited dissemination control markings from the approved list. A banner might read “CUI//SP-EXPT//NOFORN” to signal CUI Specified export-controlled information that cannot be shared with foreign nationals.7eCFR. 32 CFR 2002.20 – Marking The dissemination control slot in that banner draws from the seven approved markings only. OPSEC never appears there.

Why the Confusion Is Common

The mix-up usually comes from three overlapping realities. OPSEC and CUI both concern unclassified sensitive information. OPSEC appears by name in the CUI Registry as a category. And OPSEC produces protective decisions that often look, in practice, like access restrictions. So it is natural to assume OPSEC must be one of the labels used to control who gets a document.

It is not. CUI is defined as information the government creates or possesses, or that a contractor creates on the government’s behalf, that a law, regulation, or government-wide policy requires agencies to protect through safeguarding or dissemination controls.8eCFR. 32 CFR 2002.4 – Definitions The dissemination controls that satisfy that definition are the seven listed above, and only those seven. OPSEC informs what to protect and how. It is not the label you use to restrict who receives it.

Practical Takeaway for Marking Documents

If you are marking a CUI document and reaching for OPSEC as a dissemination restriction, stop and pick from the approved list instead. If the information should not go to foreign nationals, use NOFORN. If contractors should be excluded, use NOCON or FED ONLY, depending on the scope. If only named recipients should receive it, use DL ONLY. If the underlying information happens to be OPSEC-related and appears on your organization’s critical information list, add the OPSEC category to the banner in the category slot, then choose the dissemination control separately.

The two decisions are made independently, and they belong in different parts of the marking. Treating OPSEC as a dissemination control produces a banner that is not valid under 32 CFR Part 2002 and leaves recipients without the actual sharing restrictions the document needs.