Who Is Responsible for Applying CUI Markings: Designators and Handlers

Under 32 CFR Part 2002, the person responsible for applying CUI markings is the authorized holder who first designates the information as Controlled Unclassified Information. That designator applies the full set of required markings before the information is shared. Anyone who later pulls that CUI into a new document inherits the same marking duty for the new document, and every downstream handler is responsible for respecting the markings already in place and flagging errors when they see them.

Who Counts as the Authorized Holder

The regulation doesn’t use the word “originator.” It defines an “authorized holder” as any individual, agency, organization, or group permitted to designate or handle CUI. Within that broad group, the people who actually designate CUI — meaning they determine that a specific piece of information falls into a CUI category — carry the heaviest marking burden.

Designating starts with a check against the CUI Registry, the government-wide online repository maintained by the National Archives and Records Administration that lists every authorized CUI category and subcategory along with the laws or policies that require protection. If the information matches a listed category, the holder designates it as CUI and applies the full set of required markings before sharing it with anyone else.

In practice, this means the responsibility usually falls on the federal employee or contractor who creates the document, drafts the email, or first identifies that an existing piece of information qualifies as CUI. There is no separate “marking clerk” role in the regulation. The person who identifies the information as controlled is the person who has to mark it.

What the Designator Has to Apply

CUI markings are not a single stamp. They consist of several distinct elements that together tell any recipient exactly what kind of controlled information they are looking at and how to handle it.

Banner Marking

Every document containing CUI must display a banner marking in bold, capitalized text, centered at both the top and bottom of every page. The banner can contain up to three elements separated by double forward slashes:

  • The CUI control marking itself, either the word “CONTROLLED” or the acronym “CUI.” This element is mandatory. The designator picks which form to use, though some agencies mandate one or the other.
  • Category or subcategory markings. These are mandatory for CUI Specified (information governed by a law or policy that prescribes specific handling requirements) and optional for CUI Basic, though individual agencies can require them.
  • Limited dissemination control markings, added when the information carries restrictions on who can receive it beyond the standard CUI protections.

A fully loaded banner might read CUI//SP-TAXINFO//NOFORN. A simple CUI Basic document might just read CUI or CONTROLLED. The banner content must be the same on every page and must reflect every CUI category contained anywhere in the document.

Designation Indicator

Every CUI document must also carry a designation indicator block, typically placed in the lower right corner or footer of the first page. It tells the recipient who designated the information and how to get more details: the controlling agency and office name, the CUI category, any limited dissemination controls, and a point of contact. A group email or central phone number is preferred over an individual’s contact information.

Portion Marking

Portion marking labels individual paragraphs, sections, or other portions of a document. It is encouraged for all CUI but only mandatory in two situations: when the authorized holder is the one designating the CUI, and when CUI appears in a document that also contains classified national security information. In that second scenario, portion markings let readers tell which parts are classified, which are CUI, and which are uncontrolled.

When a Handler Becomes a Marker

Once CUI is designated and marked, anyone who receives, stores, transmits, or processes it becomes a handler. Handlers do not get to ignore markings just because someone else applied them. The core handler duty is to respect the markings and follow the safeguarding and dissemination controls they indicate.

That handler role shifts back into a designator role in one common situation: incorporating existing CUI into a new document. When you pull CUI into something you are writing, you take on a designator’s marking responsibilities for the new document. It needs the full set of CUI markings — banner, designation indicator, and any required portion markings — reflecting all the CUI it contains. This is where a lot of unmarked CUI is created in practice, because people forget that a new document does not inherit the old document’s markings automatically.

Contractors and Non-Federal Recipients

CUI marking responsibilities extend beyond federal employees. When agencies share CUI with contractors and other non-executive-branch entities, the agreement governing that relationship must include provisions requiring the outside party to handle CUI in accordance with the CUI program rules, and handling includes proper marking.

Before disseminating CUI, any authorized holder — contractor or federal employee — must label it according to the marking guidance issued by the Information Security Oversight Office, including any specific markings required by the governing law or regulation. When a contractor creates new documents containing CUI during contract performance, the contractor is responsible for applying the appropriate markings to those documents.

Sometimes agencies share CUI with outside entities without a formal agreement. Even then, the agency must communicate that the government strongly encourages the recipient to protect the information under CUI program standards and that those protections should follow the information if it gets shared further. The practical effect is that even non-contractual recipients are put on notice about their marking and handling obligations.

If Markings Are Missing or Wrong

Handlers are expected to verify that markings are present and appear correct. If you receive information you believe should be marked as CUI but isn’t, or if the markings look wrong, flag the issue to the designating agency. Each agency’s CUI Senior Agency Official must maintain a mechanism for exactly this situation — a designated representative handlers can contact for instructions on unmarked or improperly marked information.

Authorized holders also have a formal right to challenge a designation they believe is incorrect, whether the challenge is that something should not be CUI or that something unmarked should be. To bring a challenge, notify the agency that disseminated the information; if that agency didn’t originally designate the CUI, they must pass the challenge to the designating agency. The agency must acknowledge the challenge, give a timeline for its response, let the challenger explain their reasoning, and provide contact information for the decision-maker. Challenges can be brought anonymously, and the regulation explicitly prohibits retaliation against challengers.

While a challenge is pending, keep treating the information at the control level its current markings indicate. Do not downgrade protections based on your own belief about what the markings should be. If you disagree with the agency’s decision, you can escalate through the formal dispute resolution process under 32 CFR 2002.52.

Consequences of Getting It Wrong

Misuse covers a broad range of conduct, not just failing to mark information that should be marked, but also marking information as CUI when it doesn’t qualify. Both errors count as misuse under the regulation.

The CUI Senior Agency Official at each agency must establish processes for reporting and investigating misuse. When ISOO identifies a misuse incident, it reports findings to the offending agency’s Senior Agency Official or program manager for action.

The regulation itself doesn’t prescribe a specific penalty schedule. It says that agency heads who are otherwise authorized to take administrative action against personnel should reflect that authority in their CUI policies. Administrative consequences vary by agency and can include reprimands, suspension, or removal. Where a specific law or regulation governing a particular CUI category establishes its own sanctions, agencies must follow those category-specific penalties. Tax return information under 26 U.S.C. § 7213, for example, carries up to five years imprisonment and a $5,000 fine for willful unauthorized disclosure.

One boundary worth keeping in mind: decontrolling CUI, whether by a date certain, a triggering event, or an affirmative decision, does not authorize public release. The information is no longer subject to CUI program requirements, but it may still be restricted under other authorities. Removing markings and releasing information are separate decisions.