If you have ever sat in a compliance meeting, a contract kickoff, or a CMMC scoping call and heard someone ask "what DoD instruction implements CUI," here is the direct answer: DoD Instruction 5200.48, Controlled Unclassified Information (CUI). Issued on March 6, 2020, DoDI 5200.48 established the Department of Defense CUI program and is the DoD-level policy that implements the government-wide CUI framework inside the Department and, by extension, across the Defense Industrial Base.
That one-sentence answer will get you through a quiz. It will not get you through a contract. DoDI 5200.48 sits at the center of a web of authorities: Executive Order 13556, 32 CFR Part 2002, DFARS 252.204-7012, NIST SP 800-171, and now the CMMC Program rule at 32 CFR Part 170. If your company touches DoD contracts, you need to understand not just which instruction implements CUI, but what that instruction actually demands of you, how CUI must be marked, and what level of system security is required before CUI ever lands on your network.
This guide walks through all of it, written for defense contractors and DIB suppliers who need working answers, not policy trivia.
What DoD Instruction Implements CUI? The Short Answer: DoDI 5200.48
DoD Instruction 5200.48, titled "Controlled Unclassified Information (CUI)," is the instruction that establishes and implements the CUI program within the Department of Defense. It was issued by the Under Secretary of Defense for Intelligence and Security on March 6, 2020.
DoDI 5200.48 did several important things at once:
- It established DoD's CUI program in accordance with Executive Order 13556 and the government-wide implementing regulation at 32 CFR Part 2002.
- It replaced the legacy For Official Use Only (FOUO) framework. DoDI 5200.48 cancelled the FOUO guidance previously carried in DoD Manual 5200.01, Volume 4. New DoD documents are no longer marked FOUO; unclassified information requiring safeguarding is marked as CUI.
- It set DoD-specific marking, safeguarding, dissemination, and decontrol rules for CUI, including the requirements that flow into defense contracts.
- It pointed contractors at NIST SP 800-171. DoDI 5200.48 states that CUI on non-DoD (contractor) information systems must be protected in accordance with DFARS 252.204-7012, which requires the security requirements of NIST SP 800-171.
So when a prime contractor, a contracting officer, or an assessor references "the DoD CUI instruction," they mean DoDI 5200.48. It is the document that turns the federal CUI program into enforceable DoD policy.
How DoDI 5200.48 Fits Into the Federal CUI Framework
DoDI 5200.48 did not invent CUI. It implements a framework that started a decade earlier, and understanding the chain of authority matters when you are arguing scope with a prime or preparing for a CMMC assessment.
Executive Order 13556 (2010): the origin
Executive Order 13556, "Controlled Unclassified Information," signed November 4, 2010, created the government-wide CUI program. Before that order, agencies used more than 100 different ad hoc markings (FOUO, SBU, LES, and others) with inconsistent rules. EO 13556 standardized all of it under a single program and designated the National Archives and Records Administration (NARA) as the CUI Executive Agent.
32 CFR Part 2002 (2016): the government-wide rule
NARA issued the implementing regulation, 32 CFR Part 2002, "Controlled Unclassified Information," in 2016. This rule defines what CUI is, distinguishes CUI Basic from CUI Specified, sets marking and safeguarding standards for all executive branch agencies, and establishes the CUI Registry as the authoritative catalog of CUI categories. Every agency-level CUI policy, including DoD's, must conform to 32 CFR Part 2002.
DoDI 5200.48 (2020): the DoD implementation
DoDI 5200.48 is DoD's implementation of that framework. It adopts the government-wide rules, adds DoD-specific requirements, and directs the use of the DoD CUI Registry, which aligns to the NARA registry but reflects DoD-specific categories such as Controlled Technical Information (CTI).
The contract clauses: where it reaches you
Policy instructions bind DoD components. What binds contractors is the contract. DoDI 5200.48 requirements reach the Defense Industrial Base primarily through DFARS 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting," which requires contractors to provide "adequate security" for covered defense information by implementing NIST SP 800-171, and to report cyber incidents to DoD within 72 hours of discovery. The assessment and scoring clauses at DFARS 252.204-7019 and 252.204-7020, and the CMMC clause framework tied to 32 CFR Part 170, complete the enforcement picture. If you want the full chain-of-custody story for subcontractors, our guide on CUI handling for DoD subcontractors covers how these obligations flow down.
What DoDI 5200.48 Actually Requires
Inside DoD, the instruction governs how components designate, mark, handle, store, transmit, and decontrol CUI. For contractors, the practical requirements cluster into four areas.
1. Designation and identification
CUI is information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or government-wide policy requires or permits an agency to safeguard. Under DoDI 5200.48, DoD components must identify CUI in contracts and other agreements so contractors know what they are receiving or generating. In practice this shows up in the contract, the DD Form 254 for classified efforts with CUI elements, statements of work, and government-furnished information markings.
2. Marking
DoDI 5200.48 carries DoD's CUI marking requirements, covered in detail in the next section. Marking is the single most visible obligation and the one most often botched in the DIB.
3. Safeguarding
Within DoD systems, CUI must be protected at a level consistent with the risk of unauthorized disclosure. On contractor systems, DoDI 5200.48 defers to the DFARS: covered defense information must be protected per DFARS 252.204-7012, which means implementing the security requirements in NIST SP 800-171.
4. Decontrol and destruction
CUI does not stay controlled forever. DoDI 5200.48 addresses decontrol, and 32 CFR Part 2002 requires that CUI be destroyed by methods that make it unreadable, indecipherable, and irrecoverable. For contractors, that means shredding to appropriate standards and sanitizing media in accordance with your security requirements, not tossing drawings in the recycling bin.
Day-to-day handling questions (email, printing, travel, home offices, incident response) deserve their own treatment. We wrote the CUI handler field manual for exactly that: the operational rules your employees actually need at their desks.
CUI Marking Requirements Under DoDI 5200.48
CUI marking requirements trip up more contractors than any other part of the program, in both directions: failing to mark CUI they generate, and over-marking everything in sight, which bloats their compliance scope. Here is what DoDI 5200.48 and 32 CFR Part 2002 require.
- Banner marking. Documents containing CUI must carry the acronym "CUI" in the banner at the top of each page. DoDI 5200.48 directs marking at a minimum at the top of the page; marking top and bottom is common DoD practice.
- The designation indicator block. The first page must carry a CUI designation indicator identifying the designating DoD office ("Controlled by"), the CUI category or categories, applicable limited dissemination controls or distribution statement, and a point of contact.
- Category markings. CUI categories come from the CUI Registry. For DoD work, common categories include Controlled Technical Information (CTI), export-controlled information, and procurement-sensitive information. CUI Specified categories carry handling requirements set by the underlying law or regulation, not just the baseline.
- Limited dissemination controls. Markings such as NOFORN or FEDCON restrict who may receive the information. You cannot invent your own dissemination controls; only those authorized by the CUI Registry and DoD policy apply.
- Legacy material. Documents marked FOUO under the old framework did not need re-marking on the shelf, but legacy information incorporated into new documents must be reviewed and marked as CUI where it qualifies. New documents must not be marked FOUO.
- Emails and electronic files. The marking obligation follows the information, not the medium. Emails containing CUI carry the CUI marking, and file-level marking applies to electronic documents just as it does to paper.
One hard-earned lesson from the field: as a contractor, you mark CUI that you generate under the contract consistent with what the government identified, but you do not get to unilaterally designate or decontrol government CUI. When the contract is ambiguous about what is CUI, ask the contracting officer in writing. Guessing in either direction creates risk: under-marking risks a spill, and over-marking drags systems into your assessment scope that never needed to be there.
Not sure what in your environment actually counts as CUI, or how far your scope really extends? Book a CMMC and CUI scoping consultation. Petronella Technology Group, Inc. maps your data flows, identifies what is and is not CUI, and draws an assessment boundary you can actually defend.
What Level of System Is Required for CUI?
This is the question behind the question. Once you know DoDI 5200.48 implements the DoD CUI program, the operational issue becomes: what level of system is required for CUI? What does a network have to look like before CUI can live on it?
The baseline: moderate confidentiality impact
32 CFR Part 2002 sets the floor. It requires that CUI Basic be protected at no less than the moderate confidentiality impact level under FIPS Publication 199, the federal standard for categorizing information systems. In plain terms: federal systems handling CUI must implement the moderate-baseline confidentiality controls, and any system holding CUI must be treated as carrying real sensitivity, not as ordinary business data.
On contractor systems: NIST SP 800-171
You are not a federal agency, so FIPS 199 categorization does not apply to you directly. For nonfederal systems, the government translated the moderate confidentiality baseline into NIST Special Publication 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations." DFARS 252.204-7012 makes NIST SP 800-171 the contractual security standard for covered defense information on contractor networks. NIST SP 800-171 Revision 2 contains 110 security requirements across 14 families, covering access control, incident response, media protection, system and communications protection, and more. The CMMC Program rule at 32 CFR Part 170 assesses against the Revision 2 requirements.
For cloud services: FedRAMP Moderate or equivalent
If you put CUI in a cloud service, DFARS 252.204-7012 requires that the cloud service provider meet security requirements equivalent to the FedRAMP Moderate baseline, and that it support the clause's incident reporting, media preservation, and access obligations. This is why standard commercial email and file-sharing tiers are generally unsuitable for CUI, while government-oriented offerings (for example, GCC High for the Microsoft stack, or purpose-built encrypted platforms) exist for the DIB.
What this means in practice
- CUI on an unmanaged, flat corporate network fails the standard. A system that has not implemented the NIST SP 800-171 requirements is not an acceptable home for CUI under DFARS 252.204-7012.
- An enclave is usually the efficient answer. Most small and mid-size contractors are better served by a segmented CUI enclave that implements all 110 requirements for a small footprint than by dragging the entire company network into scope.
- Verification is now mandatory, not self-declared. Under the CMMC Program rule, contracts involving CUI will require CMMC Level 2, assessed against the 110 NIST SP 800-171 requirements, with most assessments conducted by a C3PAO rather than by self-attestation.
- Your SPRS score already matters. DFARS 252.204-7019 and 252.204-7020 require a current NIST SP 800-171 self-assessment score, on a scale from -203 to 110, posted in the Supplier Performance Risk System before award.
So the compact answer to "what level of system is required for CUI" is: a system protected at the moderate confidentiality baseline, which for defense contractors means a system that fully implements NIST SP 800-171 Revision 2, with FedRAMP Moderate or equivalent cloud services underneath it, verified through CMMC as contracts phase the requirement in.
CUI vs FCI: Why the Distinction Drives Your Compliance Bill
Every conversation about CUI eventually collides with its lower-tier sibling, Federal Contract Information. Getting the CUI vs FCI distinction right determines which rulebook, and which price tag, applies to you.
Federal Contract Information (FCI) is information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service. It is defined in FAR 52.204-21, which imposes 15 basic safeguarding requirements: fundamentals like limiting access to authorized users, sanitizing media, and patching systems. Under the CMMC Program rule, FCI maps to CMMC Level 1, a 15-requirement annual self-assessment.
Controlled Unclassified Information (CUI) is the higher tier: information that a law, regulation, or government-wide policy actually requires safeguarding for, cataloged in the CUI Registry, marked per DoDI 5200.48, and protected on contractor systems per NIST SP 800-171's 110 requirements. CUI maps to CMMC Level 2, and for most contractors that means a triennial third-party assessment.
Three practical consequences follow:
- Nearly every DoD contractor has FCI; not all have CUI. If you truly handle only FCI, do not let anyone talk you into scoping a Level 2 program you do not need.
- CUI status comes from the contract and the registry, not from a feeling. The presence of a DFARS 252.204-7012 clause, government-furnished technical data, or a requirement to generate controlled technical information are the signals to look for.
- Misclassifying in either direction costs money. Treating CUI as FCI exposes you to breach-of-contract and False Claims Act risk; treating FCI as CUI buys you a six-figure compliance program you did not owe anyone.
We break this down with contract-clause examples and decision trees in our full CUI vs FCI guide for defense contractors.
From DoDI 5200.48 to CMMC: How the Instruction Gets Enforced in 2026
For most of a decade, CUI protection in the DIB ran on the honor system: sign the contract, self-attest to NIST SP 800-171, hope nobody checks. That era is over.
The CMMC Program rule, 32 CFR Part 170, became effective December 16, 2024. It establishes the Cybersecurity Maturity Model Certification program: Level 1 (15 requirements, annual self-assessment) for FCI, Level 2 (the 110 NIST SP 800-171 Revision 2 requirements, mostly C3PAO-assessed) for CUI, and Level 3 (Level 2 plus selected NIST SP 800-172 enhanced requirements, government-assessed) for the highest-risk programs. The companion DFARS acquisition rule inserts CMMC requirements into solicitations, phased in over several years, so Level 2 certification requirements are appearing in live DoD solicitations now.
Here is the connection that matters: CMMC does not create new security requirements for CUI. It verifies the ones DoDI 5200.48 and DFARS 252.204-7012 already imposed. If a contract identifies CUI, the instruction says it must be marked and safeguarded; the DFARS clause says your systems must implement NIST SP 800-171 and you must report incidents within 72 hours; CMMC says you now have to prove it to an assessor before you can win the work.
The enforcement stack in 2026 looks like this:
- SPRS scores (DFARS 252.204-7019/7020) are checked before award and are subject to government review.
- CMMC Level 2 certification is being phased into solicitations involving CUI under 32 CFR Part 170.
- False Claims Act exposure is real: the Department of Justice's Civil Cyber-Fraud Initiative has produced settlements with contractors that misrepresented their cybersecurity compliance.
If DoDI 5200.48 tells you what CUI is and how to mark it, CMMC is the mechanism that decides whether you get paid to touch it. A practical, phased path from where you are to a defensible Level 2 posture is exactly what our CMMC compliance services are built for.
FAQ
What DoD instruction implements the CUI program?
DoD Instruction 5200.48, "Controlled Unclassified Information (CUI)," issued March 6, 2020, establishes and implements the CUI program within the Department of Defense. It implements Executive Order 13556 and the government-wide CUI regulation at 32 CFR Part 2002, and it replaced the legacy For Official Use Only (FOUO) framework previously found in DoD Manual 5200.01, Volume 4.
Did DoDI 5200.48 replace FOUO?
Yes. DoDI 5200.48 cancelled the FOUO guidance in DoD Manual 5200.01, Volume 4. New DoD documents are no longer marked FOUO; unclassified information requiring safeguarding or dissemination control is designated and marked as CUI. Legacy FOUO documents did not require wholesale re-marking, but legacy content reused in new documents must be reviewed and marked as CUI where it qualifies.
What level of system is required for CUI?
CUI must be protected at no less than the moderate confidentiality impact level under 32 CFR Part 2002. On contractor systems, that translates to full implementation of NIST SP 800-171 Revision 2's 110 security requirements, as required by DFARS 252.204-7012. Cloud services holding CUI must meet the FedRAMP Moderate baseline or equivalent. CMMC Level 2 is the verification mechanism being phased into DoD contracts under 32 CFR Part 170.
Who designates information as CUI, the government or the contractor?
Designation authority rests with the government. DoD components identify CUI in contracts and agreements, and contractors mark the CUI they generate under those contracts consistent with the government's identification. Contractors do not unilaterally designate government information as CUI or decontrol it. When a contract is ambiguous, request clarification from the contracting officer in writing.
What are the basic CUI marking requirements?
Under DoDI 5200.48 and 32 CFR Part 2002: the "CUI" banner marking at the top of each page, a designation indicator block on the first page (controlled-by office, CUI category, dissemination controls or distribution statement, and point of contact), and any applicable limited dissemination control markings drawn from the CUI Registry. The obligation follows the information into email and electronic files, not just paper.
Is CUI the same as classified information?
No. CUI is unclassified by definition. It is information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy, but it does not meet the standards for classification under Executive Order 13526. That said, mishandling CUI still carries contractual, civil, and in some cases criminal consequences, and losing CUI-handling eligibility can end your ability to perform DoD work.
Does handling CUI mean I need CMMC Level 2?
Under the CMMC Program rule at 32 CFR Part 170, contracts involving CUI will generally require CMMC Level 2, assessed against the 110 NIST SP 800-171 Revision 2 requirements. Most Level 2 assessments must be performed by a certified third-party assessment organization (C3PAO); a limited subset of programs allows Level 2 self-assessment. The requirement is phasing into solicitations now, so the practical answer for most CUI-handling contractors is yes.
Get Your CUI Scope Right Before an Assessor Does It for You
DoDI 5200.48 answers the policy question. The business question is whether your company can identify its CUI, mark it correctly, contain it in a system that genuinely meets NIST SP 800-171, and prove all of that to a C3PAO when the contract demands it. That work is faster and dramatically cheaper when the scope is drawn correctly on day one. Craig Petronella, CMMC Registered Practitioner, and the team at Petronella Technology Group, Inc. have guided defense contractors through exactly this: data-flow mapping, enclave design, SPRS scoring, and full CMMC Level 2 preparation. Schedule a CMMC and CUI scoping consultation and get a defensible boundary, a realistic gap picture, and a plan that fits the size of your actual CUI footprint.
Free, practical, and specific to regulated environments. We will email it to you.
No spam. Unsubscribe anytime.