What Is CUI? Controlled Unclassified Information, Explained
What is CUI? Controlled Unclassified Information is unclassified information that a law, regulation, or government-wide policy requires the Federal Government to safeguard or to control before it is disseminated. It is defined by Executive Order 13556, implemented government-wide by 32 CFR Part 2002, and implemented inside the Department of Defense by DoD Instruction 5200.48. If your contract puts CUI on your systems, DFARS 252.204-7012 and NIST SP 800-171 decide how those systems have to be built. This hub also covers CUI distribution statements, the separate DoD marking under DoD Instruction 5230.24 that controls who a technical document may be released to, and it answers who is responsible for protecting CUI once it reaches your company.
The short version
- Definition and legal basis. Executive Order 13556 created the CUI Program in 2010. The National Archives and Records Administration is the Executive Agent, and its rule at 32 CFR Part 2002 sets the government-wide standard.
- The DoD instruction that implements CUI is DoDI 5200.48. It establishes Department of Defense policy for identifying, marking, safeguarding, disseminating, decontrolling, and destroying CUI.
- Two flavors. CUI Basic follows the uniform controls in 32 CFR Part 2002. CUI Specified follows the specific handling controls written into the underlying law, regulation, or government-wide policy.
- Types of CUI come from the CUI Registry published by the National Archives, which organizes every approved category into index groupings such as Defense, Export Control, Privacy, Procurement and Acquisition, and Critical Infrastructure.
- Who can control CUI. Designation authority is a Federal Government function. Contractors are authorized holders: they receive, mark, safeguard, disseminate, and destroy CUI according to the contract and the governing policy.
- System level required for CUI. A nonfederal system that processes, stores, or transmits CUI under DFARS 252.204-7012 has to implement NIST SP 800-171, which maps to CMMC Level 2 under 32 CFR Part 170.
What Is CUI? The Legal Definition
Controlled Unclassified Information is information the Federal Government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. That definition comes directly from 32 CFR 2002, the rule the National Archives and Records Administration issued to implement the CUI Program.
Three parts of that definition do the real work, and contractors get into trouble when they skip any of them.
First, CUI is unclassified. It is not Confidential, Secret, or Top Secret. Classified national security information is governed by a separate executive order and a separate marking and clearance regime. CUI sits below that line and above ordinary public information.
Second, CUI requires an authority. Information is not CUI because it feels sensitive, because a program manager calls it proprietary, or because an email footer says it is confidential. It is CUI only when a law, a regulation, or a government-wide policy authorizes the control. The National Archives calls those the authorizing laws, regulations, and government-wide policies, and every approved CUI category traces back to at least one of them.
Third, CUI is about handling, not secrecy in the abstract. The control attaches to safeguarding the information and to limiting how it is disseminated. That is why the practical consequences of CUI show up as system requirements, marking requirements, transmission requirements, and destruction requirements rather than as clearances.
Where the CUI Program came from
Before 2010, agencies invented their own control markings. Estimates of the number of distinct legacy markings ran into the dozens, and none of them had a shared definition, a shared safeguarding baseline, or a shared decontrol rule. "For Official Use Only" meant one thing at one agency and something else at another, and a contractor holding information from two agencies had no consistent standard to apply.
Executive Order 13556, signed on November 4, 2010, ended that. It established a single, government-wide CUI Program, designated the National Archives and Records Administration as the Executive Agent, and directed the Executive Agent to publish implementing standards. Those standards became 32 CFR Part 2002, which is the regulation that binds executive branch agencies today.
What DoD Instruction Implements CUI
The DoD instruction that implements CUI is DoD Instruction 5200.48, "Controlled Unclassified Information (CUI)." It was issued on March 6, 2020 and it is the answer defense contractors are usually looking for when they ask which DoD instruction implements the CUI program.
DoDI 5200.48 does several things that matter to a contractor:
- It establishes Department of Defense policy consistent with Executive Order 13556 and 32 CFR Part 2002, so DoD components stop applying component-specific control markings.
- It assigns responsibilities for designating, marking, safeguarding, disseminating, decontrolling, and destroying CUI inside the Department.
- It discontinues the legacy "For Official Use Only" marking for newly created information. Legacy FOUO material still in circulation does not automatically become uncontrolled, but new material is marked as CUI.
- It ties CUI handling in the contract environment to the DFARS and to the safeguarding requirements that come with it, rather than leaving handling to informal instruction.
Two related instruments come up constantly alongside DoDI 5200.48. DoD Instruction 5230.24 governs distribution statements on technical documents, which is why so much CUI in the defense industrial base is technical data carrying a Distribution B through F statement. And the DoD CUI Program office publishes marking guidance that translates the regulation into the banner and portion markings assessors actually look for.
What Is CUI Versus FCI, CDI, and Classified Information
These four terms are not interchangeable, and mixing them up is the most common scoping mistake we see.
| Term | Source | What it means for your systems |
|---|---|---|
| FCI Federal Contract Information | FAR 52.204-21 | Information not intended for public release, provided by or generated for the government under a contract. Triggers the 15 basic safeguarding requirements in FAR 52.204-21, which is CMMC Level 1. |
| CUI Controlled Unclassified Information | EO 13556, 32 CFR Part 2002, DoDI 5200.48 | Unclassified information requiring safeguarding or dissemination control under law, regulation, or government-wide policy. Triggers NIST SP 800-171 through DFARS 252.204-7012 and CMMC Level 2. |
| CDI Covered Defense Information | DFARS 252.204-7012 | The contract-clause term for the unclassified controlled technical information and other information that the clause requires you to protect. In practice CDI is the subset of CUI that arrives under a DFARS 7012 contract. |
| Classified | Separate executive order | Confidential, Secret, or Top Secret. Requires facility clearance, personnel clearances, and accredited systems. Out of scope for CMMC. |
A useful rule of thumb: every DoD contractor handling FCI has to meet the FAR 52.204-21 baseline. Only the contractors who actually receive or generate CUI take on the full NIST SP 800-171 obligation. Getting that boundary right is the single highest-leverage decision in a compliance program, which is why it is the first thing we work through in a CMMC gap assessment. For a side-by-side walkthrough with contract examples, see our field guide on CUI versus FCI for defense contractors.
CUI Basic and CUI Specified
32 CFR Part 2002 divides CUI into two subsets, and the distinction changes what you are allowed to do with the information.
CUI Basic
So what is CUI Basic? CUI Basic is the default subset of Controlled Unclassified Information: the authorizing law, regulation, or government-wide policy requires protection but does not spell out how. In that case the uniform controls in 32 CFR Part 2002 apply: the moderate confidentiality baseline, the standard marking, and the standard dissemination rules. Most CUI a mid-sized supplier sees is CUI Basic.
In marking terms, CUI Basic carries the plain banner "CUI" (or "CONTROLLED"), optionally followed by the category marking. On your systems, CUI Basic is what the NIST SP 800-171 baseline was written for: the moderate confidentiality impact value applies by default, and no additional handling rules beyond 32 CFR Part 2002 attach.
CUI Specified
CUI Specified is the exception. The authorizing instrument prescribes specific controls that differ from the CUI Basic baseline. Export-controlled information is the canonical example: the International Traffic in Arms Regulations and the Export Administration Regulations impose their own access restrictions on foreign persons, and those restrictions govern even when the general CUI rules would be looser. When a category is Specified, you follow the underlying authority, not the default.
The practical consequence is that you cannot design a single handling procedure and apply it blindly. A Specified category can add nationality restrictions, physical storage requirements, or reporting duties that the Basic baseline never mentions. The CUI Registry entry for each category tells you which subset applies.
| CUI Basic | CUI Specified | |
|---|---|---|
| Handling rules come from | The uniform controls in 32 CFR Part 2002 | The underlying law, regulation, or government-wide policy for that category |
| Banner marking | "CUI" plus optional category marking | "CUI//SP-" plus the category, e.g. CUI//SP-CTI or CUI//SP-EXPT |
| Confidentiality baseline | Moderate, satisfied by NIST SP 800-171 | Moderate at minimum; the authority may add access, storage, or reporting rules on top |
| Common examples | General procurement and acquisition records, most privacy records | Controlled technical information under DoDI 5230.24, export-controlled information (ITAR/EAR), naval nuclear propulsion information |
| What to check | Contract, DD Form 254 or CDRL markings, and the CUI Registry entry | The Registry entry plus the authority it cites; the authority governs where it is stricter |
Types of CUI and the CUI Registry
People ask which of the following are types of CUI as though there were a short fixed list. There is a list, it is authoritative, and it lives in one place: the CUI Registry, maintained by the National Archives. The Registry is the only approved source of CUI categories. If a category is not in the Registry, it is not CUI.
The Registry organizes categories into index groupings. The groupings include, among others:
- Defense, which covers controlled technical information, naval nuclear propulsion information, and unclassified controlled nuclear information related to defense.
- Export Control, covering information subject to export control laws and regulations. This grouping is CUI Specified.
- Procurement and Acquisition, covering source selection information, contractor bid or proposal information, and small business research and technology information.
- Privacy, covering personally identifiable information, health information, and related categories.
- Critical Infrastructure, covering protected critical infrastructure information and related security information.
- Proprietary Business Information, covering trade secrets and other proprietary material the government holds.
- Law Enforcement, Legal, Intelligence, Nuclear, Tax, Statistical, Transportation, Immigration, Financial, International Agreements, NATO, Patent, and Natural and Cultural Resources.
For a defense supplier, the categories that appear on real contracts are overwhelmingly Controlled Technical Information under the Defense grouping, export-controlled data, and procurement-sensitive material. Drawings, specifications, process sheets, test data, and engineering change documents carrying a distribution statement are the day-to-day reality of CUI in a machine shop or a contract manufacturer.
Who Can Control CUI and Who Can Designate It
Designation is a government function. An authorized holder acting on behalf of a Federal agency determines that information falls within a CUI category and applies the control. A contractor does not get to invent CUI, and a contractor cannot unilaterally decide that its own commercial data is CUI simply because it wants the protection.
That said, contractors do create CUI in the ordinary course of performance. When you generate a drawing, a test report, or an analysis for the government under a contract that involves CUI, the resulting material is marked and handled as CUI according to the contract's requirements and the government's guidance. The authority still traces back to the government; you are executing it, not originating it.
What a CUI authorized holder is responsible for
32 CFR Part 2002 defines an authorized holder as an individual, agency, organization, or group of users that is permitted to designate or handle CUI in accordance with the CUI Program. Every employee at a defense supplier who touches CUI is an authorized holder, and the obligations attach to the individual, not only to the company.
A CUI authorized holder is responsible for:
- Determining, before dissemination, whether the recipient has a lawful government purpose. The CUI Program replaced "need to know" with the lawful government purpose standard. You share CUI when the sharing furthers a lawful government purpose and no limited dissemination control forbids it.
- Applying and maintaining the correct markings so that the next holder knows what they have received and what restrictions travel with it.
- Safeguarding the information at rest, in transit, and in physical form, which in a contract environment means the controls in NIST SP 800-171 plus physical protections.
- Not removing or downgrading markings on someone else's information. Only the designating agency may decontrol.
- Challenging designations believed to be improper. The CUI Program expects holders who think information was over-designated or under-designated to raise it through the process the regulation establishes rather than acting unilaterally.
- Reporting suspected or confirmed unauthorized disclosure through the required channels, which under DFARS 252.204-7012 means reporting a cyber incident to the Department of Defense.
- Destroying CUI when it is no longer required in a manner that makes it unreadable, indecipherable, and unrecoverable.
Those responsibilities are also why CUI training is not optional overhead. NIST SP 800-171 has an entire Awareness and Training family, and the personnel security requirements extend the obligation across hiring, transfer, and termination. We cover the personnel side in detail on protecting CUI during personnel actions.
CUI Marking and Handling Requirements
Marking is what makes the rest of the program work. If CUI is not marked, downstream holders do not know it is controlled, and it leaks by default.
Banner markings
CUI carries a banner marking at the top of the document. The banner uses the control marking CUI or the word CONTROLLED. For CUI Specified, the banner adds the category marking after a double forward slash, for example CUI//SP-EXPT for export-controlled information. Limited dissemination controls follow in the same banner, for example CUI//SP-EXPT//FED ONLY.
Designation indicator
Documents also carry a designation indicator identifying the office that designated the information, commonly rendered as a "Controlled by" block with the controlling office, the applicable category, the limited dissemination control if any, and a point of contact. That block is what lets a recipient trace the authority and ask questions.
Limited dissemination controls
Limited dissemination controls are the approved way to narrow distribution beyond the lawful government purpose standard. The approved set is published in the CUI Registry and includes controls such as NOFORN, FED ONLY, FEDCON, NOCON, DL ONLY, REL TO, and DISPLAY ONLY. Only agencies may apply them, and once applied they travel with the information.
Media, portable storage, and mobile devices
Physical media holding CUI has to be marked and controlled as well. That obligation is where NIST SP 800-171's Media Protection family becomes concrete. Rather than restate those requirements here, this hub links down to the implementation pages for each one, below.
Who Is Responsible for Applying CUI Markings and Dissemination Instructions
The short answer, and the one the Department of Defense writes down: the authorized holder of the document or material, at the time of creation. DoD Instruction 5200.48 states that the authorized holder of a document or material is responsible for determining, at the time of creation, whether information in that document or material falls into a CUI category, and that if it does, the authorized holder is responsible for applying CUI markings and dissemination instructions accordingly.
That sentence assigns the duty to a person, not to a system, an administrator, or a network. No email gateway, file server, or data loss prevention tool discharges it. The individual who creates the drawing, the test report, the quote, or the email decides whether it is CUI and marks it before it moves. The previous section covered what the markings look like. This section covers who owes them.
Designating authority and marking responsibility are two different jobs
Confusion on this question almost always comes from collapsing two distinct roles into one. They are separate under 32 CFR Part 2002.
- The designating agency decides that information is CUI. 32 CFR 2002.20 places the determination that information qualifies as CUI, and the application of the appropriate markings, with the designating agency. That same paragraph forbids marking information as CUI to conceal illegality, negligence, ineptitude, or other disreputable circumstances, which is the guardrail against over-designation.
- The authorized holder carries the marking out, every time new material is created. Designation authority is exercised once, at the level of the information. Marking responsibility recurs at every act of creation downstream. A contractor engineer who builds a new assembly drawing from a government-furnished specification is an authorized holder creating a new document, and the marking obligation attaches to that engineer at that moment.
The bridge between the two is the designation indicator. 32 CFR 2002.20 requires every document containing CUI to carry an indicator of who designated the CUI within it, identifying the designator's agency at a minimum. When a contractor marks a derivative document, that indicator is what preserves the trail back to the agency that actually holds the authority. Strip it and the next holder has a marked document with no way to ask the right office a question.
What this means for a defense contractor
DoDI 5200.48 extends compliance with its requirements to every individual at every level, including DoD civilian and military personnel and contractors providing support to the Department under contractual requirements. There is no threshold below which an employee is exempt. Practically, that produces four obligations inside a supplier:
- Mark at creation, not at transmission. The obligation attaches when the document comes into existence. Marking a file only at the moment it is emailed out leaves an unmarked copy sitting on a share, where the next person who opens it has no notice that it is controlled.
- Do not push the duty downstream. A recipient cannot be expected to reconstruct whether unmarked material was CUI. Sending unmarked CUI to a subcontractor and expecting them to sort it out is how flow-down obligations break.
- Cover every artifact type. Email bodies, spreadsheets, CAD files, scanned travelers, meeting notes, and screenshots are documents. Marking programs that only address formal engineering releases leave the majority of daily CUI unmarked.
- Train to the duty and keep the evidence. Because the responsibility sits with individuals, an assessor tests it by asking individuals. NIST SP 800-171's Awareness and Training family is where that expectation becomes an assessable requirement.
Who applies dissemination instructions and limited dissemination controls
Dissemination instructions travel with markings, but the authority behind them is narrower. 32 CFR 2002.16 is explicit that only the designating agency may apply limited dissemination controls to CUI, and that other entities that receive CUI and seek to apply additional controls must request permission from the designating agency to do so. 32 CFR 2002.20 adds that agency policy establishes which authorized holders may apply limited dissemination control markings in the banner.
For a contractor, the working rule that falls out of those two provisions is straightforward. You are responsible for carrying forward and honoring the dissemination instructions that arrived with the information, and for applying them correctly to derivative material. You are not free to invent a new limited dissemination control because a program manager wants tighter distribution, and you are not free to drop one because it is inconvenient. The approved control set and its meanings are published in the CUI Registry; the specific controls that show up on defense work are listed in the marking section above.
Where marking responsibility fails an assessment
Three patterns recur. First, derivative documents created during performance go out unmarked because the marking program was written for received material only. Second, the banner marking appears on a cover page but not on every page that contains CUI, which 32 CFR 2002.20 requires. Third, the designation indicator is missing, so no one downstream can identify the controlling office. Each of these is a documentation failure rather than a technology failure, and each is cheap to fix before an assessment and expensive to explain during one. If you are not sure which of your documents are marked correctly today, that inventory is part of the same exercise that maps where your CUI lives.
CUI Distribution Statements
A distribution statement is a short block of text placed on a technical document that states who is allowed to receive it and who controls further release. On defense work it is the marking that answers a different question from the CUI banner. The banner tells you the information is controlled. The distribution statement tells you how far the document may travel and which office decides that.
The governing issuance is DoD Instruction 5230.24, Distribution Statements on Technical Documents. It requires DoD technical documents to carry a distribution statement, requires the statement to identify the controlling DoD office, and requires the determination to be made before the document is released. DoD Instruction 5200.48 is the issuance that governs DoD Controlled Unclassified Information marking and handling. The two operate in parallel. DoDI 5200.48 does not eliminate the distribution statement requirement in DoDI 5230.24, and a distribution statement does not satisfy the CUI marking requirements described earlier on this page.
A distribution statement is not a CUI marking
This is the distinction that costs contractors the most rework. Three separate marking systems can appear on the same page, and each has a different legal source:
- The CUI banner marking comes from 32 CFR 2002.20 and the CUI Registry. It identifies the information as CUI and, where applicable, names the category and any limited dissemination control.
- The distribution statement comes from DoDI 5230.24. It is a document-level release control, and it names a controlling DoD office that requests must be referred to.
- The export control warning notice applies where the technical data is subject to export control law, including the International Traffic in Arms Regulations at 22 CFR Parts 120 through 130 and the Export Administration Regulations at 15 CFR Parts 730 through 774.
Because the systems are separate, one can be present while another is missing. A drawing can carry Distribution Statement C and no CUI banner. A test report can carry a CUI banner and no distribution statement. Neither omission gives you permission to treat the document as uncontrolled. Where the content is Controlled Technical Information, the CUI Registry category for technical information with military or space application, it is CUI regardless of whether the distribution statement block was filled in correctly by the originator.
Limited dissemination controls are also distinct from distribution statements. Under 32 CFR 2002.16 only the designating agency may apply a limited dissemination control, and the approved control set is published in the CUI Registry. A distribution statement is not one of those controls, and applying a distribution statement to a document does not create or remove a limited dissemination control.
One more distinction is worth stating plainly, because it drives the wrong architecture decision more often than any other. A distribution statement restricts release. A CUI marking triggers protection. A document can be released widely inside an authorized audience and still require FIPS-validated encryption at rest, access control, and audit logging on every system that touches it. Conversely, a tightly restricted distribution statement on a document that contains no CUI does not by itself pull a file server into your assessment scope. Suppliers that conflate the two either overscope, and pay to protect drawings that carry no CUI at all, or underscope, and leave Controlled Technical Information on a general-purpose share because the distribution statement looked like the only control in play.
The distribution statements and what each one restricts
DoDI 5230.24 defines a lettered series of statements. Described only as far as the instruction itself states them:
- Distribution Statement A. Approved for public release. Distribution is unlimited. A document cleared to Statement A has been through public release review and is no longer restricted by the distribution statement system.
- Distribution Statement B. Distribution authorized to U.S. Government agencies only. Other requests are referred to the controlling DoD office. Contractors are not inside the authorized audience unless the controlling office says otherwise.
- Distribution Statement C. Distribution authorized to U.S. Government agencies and their contractors. This is the statement most often seen on material sent to the defense industrial base.
- Distribution Statement D. Distribution authorized to the Department of Defense and U.S. DoD contractors only. Narrower than C, because it excludes government agencies outside the Department and their contractors.
- Distribution Statement E. Distribution authorized to DoD Components only. Contractors are outside the audience. Receiving a Statement E document as a supplier is a signal to stop and contact the controlling office rather than to circulate it internally.
- Distribution Statement F. Further dissemination only as directed by the controlling DoD office or higher DoD authority. Nothing moves without an affirmative instruction, including inside your own company.
Each restricted statement is paired with a stated reason for the restriction. DoDI 5230.24 provides the permitted reason set, which includes categories such as foreign government information, proprietary information, critical technology, test and evaluation, premature dissemination, administrative or operational use, software documentation, and specific authority. The reason matters operationally, because it tells you which office and which body of law is actually driving the restriction. Older editions of the instruction used a slightly different lettering set, so a legacy document in your archive may carry a statement that the current instruction no longer lists. Treat legacy statements as restrictive until the controlling office says otherwise rather than assuming they lapsed.
Where the statement goes on the document
DoDI 5230.24 requires the statement to be displayed conspicuously enough to be recognized readily. In practice that means the front cover or title page of a technical report, the title block of a drawing, and the report documentation page where one is used. The block identifies the statement letter, the reason for the restriction, the date the determination was made, and the controlling DoD office. The controlling office entry is the operationally important part, because it is the address to which you refer any request you are not authorized to fill.
When a document contains both CUI and a distribution statement, the CUI banner marking goes at the top and bottom of the page as 32 CFR 2002.20 requires, and the distribution statement occupies its own block. They do not merge, and abbreviating the distribution statement into the CUI banner is a marking error.
What a contractor must do with a document that carries one
The obligations are narrow and specific:
- Read the letter and the audience before you forward anything. Statement C permits contractor distribution. Statements B, E, and F do not, or do so only on direction. Forwarding a Statement F drawing to a second-tier supplier because the program needs a quote is an unauthorized release even when everyone involved holds a contract.
- Refer requests to the controlling DoD office. That is what the block is for. You do not get to make a release determination on someone else's technical data, and neither does your customer's program manager unless that office is the controlling office named on the document.
- Never publish to Statement A on your own authority. Public release requires the originating component's clearance process. Posting a marked drawing on a public website or a supplier portal is the fact pattern behind NIST SP 800-171 requirement 3.1.22.
- Carry the statement forward onto derivative material. If you build a new drawing or report from a Statement D source, the derivative inherits the restriction. This is the same rule as derivative CUI marking, and it fails assessments for the same reason: marking programs written only for received documents.
- Protect the underlying information to the applicable standard. A distribution statement is a release control, not a security control. If the content is CUI under a DFARS 252.204-7012 contract, the system storing it still has to implement NIST SP 800-171. See NIST SP 800-171 compliance.
- Mark the media too. Physical and removable media holding the document inherit the marking obligation under requirement 3.8.4, which addresses distribution limitations explicitly.
One practical note from assessment work. Distribution statements are frequently the first hard evidence a supplier has that it holds CUI at all. Companies that believe they have no CUI often have a folder of Statement C and Statement D documents sitting on a general-purpose file share. If that describes your environment, the inventory exercise is the same one described in the enclave section below, and it should happen before any architecture decision.
What Level of System Is Required for CUI
This is the question with the most expensive wrong answers. The short version: a nonfederal information system that processes, stores, or transmits CUI under a DFARS 252.204-7012 contract has to implement NIST SP 800-171, and under 32 CFR Part 170 that maps to CMMC Level 2.
The clause chain
DFARS 252.204-7012 requires adequate security on covered contractor information systems, defines adequate security as implementing NIST SP 800-171, requires rapid reporting of cyber incidents to the Department of Defense within 72 hours of discovery, requires preservation of affected media and images for 90 days, requires submission of malicious software when isolated, and requires flow-down of the clause to subcontractors whose performance involves covered defense information.
DFARS 252.204-7019 and 252.204-7020 add the assessment layer: a current NIST SP 800-171 self-assessment score posted in the Supplier Performance Risk System, and the government's right to conduct higher-level assessments. If you have not scored yourself, our SPRS score calculator walks the arithmetic.
DFARS 252.204-7021 is the CMMC clause. Where it applies, self-attestation is replaced or supplemented by the certification requirement defined in the CMMC Program rule at 32 CFR Part 170. CMMC Level 2 is the 110 security requirements of NIST SP 800-171, assessed either by a certified third-party assessment organization or, for a limited set of contracts, by self-assessment. Level 3 layers a selected set of enhanced requirements drawn from NIST SP 800-172 on top of Level 2 for the highest-risk programs. Our CMMC levels explained page walks the level boundaries, and CMMC Level 3 covers the enhanced tier.
Cloud, encryption, and the details that fail assessments
Three technical constraints catch contractors repeatedly:
- Cloud service providers. DFARS 252.204-7012 requires a cloud service provider handling covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline. Commercial productivity tenants that were never assessed against that baseline do not satisfy the clause.
- FIPS-validated cryptography. NIST SP 800-171 requires FIPS-validated cryptography to protect the confidentiality of CUI. Encryption that is strong but not validated does not meet the requirement as written.
- External connections and flow. Information flow between the CUI environment and everything else has to be controlled and documented. See controlling CUI flow.
For a broader treatment of the 110 requirements and the 14 families, see our NIST SP 800-171 compliance page. For the assessment mechanics, see C3PAO assessment and CMMC Level 2 certification.
Who Is Responsible for Protecting CUI
Responsibility for protecting CUI is not assigned to one office. It runs down a chain, and every link in that chain has an obligation that exists independently of the others. Understanding where you sit on the chain is what turns a policy document into something an assessor can test.
The authorized holder is the base unit of responsibility
The CUI Program rule at 32 CFR Part 2002 builds the entire safeguarding regime on the authorized holder. An authorized holder is an individual, agency, organization, or group of users permitted to designate or handle CUI in accordance with the rule. Under 32 CFR 2002.14 authorized holders must take reasonable precautions to guard against unauthorized disclosure, and must safeguard CUI at all times in a manner that prevents access by unauthorized persons. Under 32 CFR 2002.16 an authorized holder may disseminate CUI only when doing so furthers a lawful government purpose and is consistent with any limited dissemination controls that were applied by the designating agency.
Two consequences follow. First, responsibility attaches to a person, not to a network. Second, it attaches on receipt, not on signature of a policy. The engineer who opens the file, the buyer who forwards the quote package, and the shop lead who prints the traveler are each authorized holders in that moment and each owe the safeguarding duty directly.
The contract is what puts a company on the chain
A private company is not bound by the CUI Program rule the way a federal agency is. The mechanism that binds a contractor is the contract itself, and specifically the clauses in it.
- DFARS 252.204-7012 obligates the contractor to provide adequate security on covered contractor information systems that process, store, or transmit covered defense information, and defines adequate security as implementing NIST SP 800-171.
- DFARS 252.204-7019 and 252.204-7020 obligate the contractor to have a current NIST SP 800-171 assessment score posted in the Supplier Performance Risk System and to give the government access to conduct higher-level assessments. Our SPRS score calculator covers the scoring method.
- DFARS 252.204-7021 is the CMMC clause, implemented by the program rule at 32 CFR Part 170. Where it applies, the required certification level has to be achieved and maintained for the duration of the contract.
The clause is the reason a subcontractor two tiers away from the government has any obligation at all. Absent the clause, there is no privity and no duty. With the clause, the duty is contractual and enforceable.
Flow-down to subcontractors
DFARS 252.204-7012 requires the contractor to include the substance of the clause in subcontracts, including subcontracts for commercial products or commercial services, when performance will involve covered defense information. The prime does not delegate its own responsibility by doing so. It adds a second obligated party. The prime remains answerable to the government for performance of its contract while the subcontractor becomes directly obligated under its own subcontract.
Three flow-down failures show up repeatedly in supplier assessments. The clause is omitted from purchase orders issued by a procurement team that never saw the prime contract. The clause is included but no one verifies that the supplier can actually meet it, so CUI is sent to a company with no compliant environment. Or CUI is sent unmarked, so the supplier never learns that the material is controlled. The marking duty described earlier on this page is what prevents the third failure, which is why marking and flow-down are the same problem viewed from two ends.
Under DFARS 252.204-7012 a subcontractor that experiences a reportable incident is required to report it rapidly to the Department of Defense and to provide the incident report number to the prime or next higher tier contractor. Responsibility is parallel, not transferred.
The individual employee
DoD Instruction 5200.48 extends compliance with its requirements to every individual at every level, including contractor personnel providing support under contractual requirements. There is no seniority threshold. In practice the individual duty comes down to five behaviors: recognize CUI when you see it, mark what you create, store and send it only through the approved environment, report anything that looks like a spill immediately, and complete the required training. NIST SP 800-171 makes the last one assessable through its Awareness and Training family, and the personnel security family at requirement 3.9.2 extends the duty through transfers and terminations.
What responsible means when CUI spills
Accountability lands in more than one place at once, and it is worth being precise about which forum does what.
- The company answers to the contracting officer. DFARS 252.204-7012 obligates the contractor to report a cyber incident that affects a covered contractor information system or covered defense information rapidly, within 72 hours of discovery, through the DoD reporting portal at dibnet.dod.mil. Reporting requires a DoD-approved medium assurance certificate, which has to be obtained in advance. Waiting until an incident to start that process is how the 72 hour window gets missed.
- Evidence has to be preserved. The same clause requires preservation and protection of images of known affected information systems and relevant monitoring or packet capture data for at least 90 days from the incident report submission, and requires submission of isolated malicious software to the Department of Defense Cyber Crime Center.
- Internal reporting is a separate requirement. NIST SP 800-171's Incident Response family requires an operational incident handling capability and the tracking, documenting, and reporting of incidents to designated internal and external officials. A company that reports to the government but has no internal process fails the requirement even when the external report was timely.
- Individuals face administrative consequences. 32 CFR 2002.56 addresses misuse of CUI and the sanctions available for it. Within a contractor, the parallel consequence is whatever the employee handbook and the security policy provide, which is why the policy has to state it.
- Misrepresenting compliance is its own exposure. Scores submitted to the Supplier Performance Risk System and affirmations of continuing compliance made under the CMMC rule at 32 CFR 170.22 are representations to the government. The Department of Justice has pursued cybersecurity misrepresentation cases under the False Claims Act, 31 U.S.C. 3729. The compliance risk and the security risk are not the same risk, and the first one is created by the affirmation rather than by the breach.
The short answer to the question, then, is that everyone who touches the information is responsible, the company is the party that answers for it contractually, and the individual who signs the affirmation is the one whose name is on the representation. The way to make that survivable is to know exactly which systems and which people are in scope before an incident forces the question. Petronella Technology Group, Inc. treats that scoping exercise as the first deliverable on every engagement, because every other decision, including whether to build a CUI enclave, depends on it.
CUI Handling, Control by Control
This hub explains the program. The pages below explain the individual NIST SP 800-171 and CMMC requirements that govern how CUI is stored, moved, marked, and destroyed. Each one covers scope, implementation, evidence, and the assessment objectives.
Control CUI Flow
Enforcing approved authorizations for controlling the flow of CUI within and between systems.
3.1.19Encrypt CUI on Mobile Devices
Encryption on mobile devices and mobile computing platforms that carry CUI.
3.1.22CUI on Public Systems
Controlling CUI posted or processed on publicly accessible systems, including websites.
3.8.1Protect CUI on System Media
Protecting system media containing CUI, both paper and digital.
3.8.2Limit Access to CUI on Media
Limiting access to CUI on system media to authorized users.
3.8.3Sanitize or Destroy CUI Media
Sanitizing or destroying media containing CUI before disposal or release for reuse.
3.8.4Mark CUI Media
Marking media with necessary CUI markings and distribution limitations.
3.8.5Control and Account for CUI Media
Controlling access to media containing CUI and maintaining accountability during transport.
3.8.6Cryptography on Portable Storage
Cryptographic mechanisms protecting CUI on digital media during transport.
3.8.9Protect Backup CUI
Protecting the confidentiality of backup CUI at storage locations.
3.9.2CUI During Personnel Actions
Protecting CUI during and after personnel transfers and terminations.
3.13.8Cryptography for CUI in Transit
Preventing unauthorized disclosure of CUI during transmission.
3.13.16Protect CUI at Rest
Protecting the confidentiality of CUI at rest across storage tiers.
Destruction, Decontrol, and Incident Reporting
Destruction
CUI is destroyed when it is no longer needed, and the standard is outcome-based: the information must be rendered unreadable, indecipherable, and unrecoverable. For digital media that means sanitization consistent with NIST SP 800-88, "Guidelines for Media Sanitization," which distinguishes clearing, purging, and physical destruction and matches the method to the media type. For paper it means cross-cut shredding or equivalent. Keeping a destruction record is not glamorous, but it is the evidence an assessor asks for. The requirement-level detail lives on sanitize or destroy CUI media before disposal.
Decontrol
Decontrol is the formal removal of CUI status, and it is a separate act from destruction: destruction disposes of the information, decontrol lifts the controls while the information continues to exist. The key rule for contractors is that you do not decontrol government information on your own authority. Because decontrol authority is the question defense suppliers get wrong most often, the section below treats it in full.
Incident reporting
Under DFARS 252.204-7012, a contractor that discovers a cyber incident affecting covered defense information or affecting its ability to perform operationally critical support must rapidly report to the Department of Defense within 72 hours of discovery. Reporting goes through the DoD reporting portal and requires a medium assurance certificate, which takes time to obtain. Getting that certificate before you need it is a five-minute task that becomes a crisis if it is deferred.
The clause also requires preserving images of affected systems and relevant monitoring data for at least 90 days from the report so the government can request them, and submitting malicious software to the government if it is isolated in connection with the incident. Subcontractor incidents flow through the same structure, and the prime has to be notified.
If your CUI moves down a supply chain, the flow-down obligations are worth reading closely. We walk them in CUI handling for DoD subcontractors.
Who Can Decontrol CUI
The designating agency can decontrol CUI. 32 CFR 2002.18 assigns decontrol either to an automatic trigger that the agency built into the designation, or to an affirmative decision by the designating agency. The same section lets an agency name, in its own CUI policies, which of its personnel are authorized to decontrol, consistent with law, regulation, and government-wide policy. So the precise answer is narrower than "the government": it is the agency that designated the information, acting through the personnel that agency has authorized.
Note that this is a different question from who can designate or control CUI, which the earlier section on control and designation covers. Designation creates the control. Decontrol removes it. The two authorities are held by the same agency but exercised under different rules, and the decontrol rules are written more tightly because the failure mode is disclosure rather than over-protection.
The conditions under which CUI is decontrolled
32 CFR 2002.18 sets out when decontrol occurs. Agencies should decontrol as soon as practicable any CUI they designated that no longer requires safeguarding or dissemination controls, unless doing so would conflict with the governing law, regulation, or government-wide policy. Beyond that general duty, decontrol happens in these situations:
- The underlying authority no longer requires control. When the laws, regulations, or government-wide policies that made the information CUI no longer require it, and the authorized holder has the appropriate authority under that instrument, the control lapses.
- The designating agency proactively releases the information. An affirmative, proactive public disclosure by the designating agency decontrols the material.
- The agency discloses it under an access statute. Disclosure under the Freedom of Information Act, or under the Privacy Act where legally permissible, decontrols the information when the agency has incorporated those disclosures into its public release processes.
- A predetermined date or event arrives. Agencies may build a decontrol date or a foreseeable, verifiable decontrol event into the marking itself. When it occurs, decontrol follows, unless law, regulation, or government-wide policy requires coordination first.
- An authorized holder asks and the agency agrees. The designating agency may decontrol in response to a request from an authorized holder. This is the channel available to a contractor.
- Declassification action. The designating agency may decontrol concurrently with a declassification action under Executive Order 13526, provided the information also independently qualifies for decontrol as CUI.
- Authorized public release by a holder. If an authorized holder publicly releases CUI in accordance with the designating agency's authorized procedures, that release itself constitutes decontrol.
- Transfer to the National Archives. The Archivist of the United States may decontrol records transferred to the National Archives under 32 CFR 2002.34, absent a specific agreement otherwise with the designating agency.
Who cannot decontrol CUI
This is the half of the question that protects contractors from a self-inflicted incident.
- A contractor cannot decontrol government information unilaterally. Your available action is a request: 32 CFR 2002.18 expressly permits authorized holders to ask the designating agency to decontrol certain CUI. Route it through the contracting channel and get the answer in writing.
- An agency cannot decontrol to cover a spill. Agencies must not decontrol CUI in an attempt to conceal, or to otherwise circumvent accountability for, an identified unauthorized disclosure.
- A leak is not a decontrol. Unauthorized disclosure of CUI does not constitute decontrol. Material that appeared on a public site because someone misconfigured a share is still CUI, still marked, and still subject to incident reporting under DFARS 252.204-7012.
- Decontrol is not permission to publish. Decontrolling relieves authorized holders of the obligation to handle the information under the CUI Program, but it does not constitute authorization for public release. Any subsequent release still has to satisfy applicable law and the agency's public release policies, which for defense technical information means the distribution statement and prepublication review regime rather than the CUI rules.
Decontrol procedures and markings
When decontrol does happen, 32 CFR 2002.18 sets out what an authorized holder has to do with the paperwork, and the obligations are lighter than most people expect.
Authorized holders must clearly indicate that the information is no longer controlled when they restate it, paraphrase it, re-use it, release it to the public, or donate it to a private institution. Outside those situations, holders do not have to mark, review, or take other action to show that the CUI is no longer controlled. Agency policy may allow a holder to remove or strike through only the CUI markings on the first or cover page of the decontrolled material and on the first page of any attachments that contain CUI, rather than every page. If a holder uses decontrolled information in a newly created document, all CUI markings for that information must be removed from the new document.
Two qualifiers matter for defense work. First, where a law, regulation, or government-wide policy prescribes specific decontrol procedures, authorized holders must follow those procedures instead of the general rule. That is the CUI Specified problem again: export-controlled material carries its own release regime, and nothing in the CUI decontrol rules displaces it. Second, decontrol markings are an evidence artifact. If you decontrolled a document because the government told you to, keep the instruction. An assessor looking at an unmarked file that used to be CUI will want to see why.
What decontrol does not do to your assessment scope
Contractors sometimes reach for decontrol as a scoping tool, hoping to shrink the assessment boundary by declaring aging project data no longer controlled. That does not work, for the reason above: the authority is not yours. The levers that actually reduce scope are retention and destruction on your side, and boundary design. Retire the data you no longer need under a defensible schedule and destroy it to the standard covered above, and architect the environment so that CUI has a small number of places to be. That is what a scoping exercise produces, and it is the first thing our CMMC gap assessment maps.
What Is a CUI Enclave and When It Makes Sense
A CUI enclave is a deliberately bounded environment that holds all of your CUI, so the security requirements apply to that environment rather than to your whole company. The term is architectural rather than regulatory. What makes it meaningful under CMMC is the asset categorization in the CMMC assessment scoping guidance, which sorts assets into CUI assets, security protection assets, contractor risk managed assets, specialized assets, and out-of-scope assets. An enclave is how you engineer the answer to that sort in advance instead of discovering it during an assessment. If you are weighing that approach for your own environment, our CMMC enclave design and build engagement covers how the boundary is drawn, evidenced, and defended.
Why teams build one
- Assessment scope shrinks. A shop with 200 endpoints that funnels CUI work through 25 devices inside an enclave is assessed on a much smaller footprint, with fewer systems to harden, document, monitor, and produce evidence for.
- Cost and disruption drop. FIPS-validated encryption, hardened baselines, session controls, and continuous logging are expensive to apply company-wide and reasonable to apply to a bounded environment.
- The boundary becomes explainable. An assessor can follow a diagram. A diffuse environment where CUI might be anywhere is very hard to attest to honestly.
- General business systems stay flexible. Sales, marketing, and general operations do not inherit CUI controls they do not need.
When an enclave is the wrong answer
An enclave adds a boundary, and boundaries have to be enforced. It is the wrong answer when CUI genuinely permeates the business, because you end up maintaining two environments and still assessing most of the company. It is also the wrong answer when the workflow forces constant movement of data across the boundary, since every crossing is a control point that can fail. And it fails outright when it exists only on paper: if engineers routinely email drawings to their personal workstations, the enclave boundary is fiction and the assessment will say so.
The honest decision comes out of a scoping exercise, not a product choice. Map where CUI enters, where it is processed, where it is stored, who touches it, and where it leaves. The right architecture usually becomes obvious once that map exists. That mapping is the first stage of our CMMC gap assessment, and the engineering patterns we deploy are documented on the CMMC technical stack page. If you want the buyer-facing overview of the whole program instead, start at CMMC compliance.
CUI Obligations During the July 2026 CMMC Pause
On July 13, 2026, the Department of War suspended Phase 2 of the CMMC rollout and stood up a CMMC Reform Task Force, which is running a 60-day review with a public request for information (memo 26-P-1023). Contractors sometimes read that headline as a pause on CUI obligations. It is not. The suspension reaches one thing: the point at which third-party (C3PAO) Level 2 certification assessments would start appearing as a condition of award in new solicitations. There is no scheduled date for that while the review runs, and the Department has been explicit that the objective is to reduce certification burden rather than to lower the underlying cybersecurity baseline.
Everything on this page remains fully in force. CUI marking, safeguarding, dissemination, destruction, and incident reporting duties come from 32 CFR Part 2002, DoDI 5200.48, and DFARS 252.204-7012, none of which were suspended. DFARS 252.204-7019 and 252.204-7020 still require a current NIST SP 800-171 self-assessment score in SPRS before award, and the annual affirmation of continued compliance still applies where Phase 1 CMMC requirements already sit in your contracts. Prime contractors continue to run their own supplier questionnaires and continue to weight SPRS posture in sourcing decisions, and False Claims Act exposure for a misstated SPRS score is unchanged. You can check your own number in minutes with our free SPRS score calculator.
The practical read is that the clock came off, not the requirement. Measuring where your CUI actually sits and closing the gaps while nothing is gating an award is the low-stress version of this work. Doing the same work later, against a solicitation you are already bidding, is the expensive version. Treat the review period as the preparation window it is.
The scoping concepts above are also exactly what a CMMC assessment evaluates. Where CUI lives determines your assessment boundary, your asset categories, and your level: FCI-only environments stop at Level 1, CUI environments require Level 2, and a small set of programs handling the most sensitive CUI on critical programs map to CMMC Level 3, which stacks 24 NIST SP 800-172 enhanced requirements on top of the 110. For the buyer-facing view of the whole program, including current fixed-price gap assessment bands, start at our CMMC compliance hub.
Frequently Asked Questions About CUI
What is CUI in simple terms?
CUI is unclassified information that the government requires you to protect or to limit sharing of, because a law, regulation, or government-wide policy says so. It is not classified, and it is not ordinary business data. Executive Order 13556 created the program and 32 CFR Part 2002 sets the rules.
What DoD instruction implements CUI?
DoD Instruction 5200.48, issued March 6, 2020, implements the CUI Program inside the Department of Defense. It establishes policy and assigns responsibilities for identifying, marking, safeguarding, disseminating, decontrolling, and destroying CUI, consistent with Executive Order 13556 and 32 CFR Part 2002.
Who can control CUI?
Designation is a Federal Government function performed by an authorized holder acting on behalf of an agency. Contractors are authorized holders who receive, mark, safeguard, disseminate, and destroy CUI according to the contract and the governing category rules. A contractor cannot designate its own commercial information as CUI, and cannot decontrol government information.
Who can decontrol CUI?
The designating agency. Under 32 CFR 2002.18, decontrol happens either automatically on a condition the agency built into the designation, or through an affirmative decision by the designating agency, and an agency may specify in its own CUI policies which of its personnel are authorized to decontrol. Authorized holders, including contractors, may request decontrol but cannot decontrol government information themselves. Decontrolling relieves holders of CUI Program handling obligations but is not authorization for public release, and unauthorized disclosure never constitutes decontrol.
Who is responsible for applying CUI markings and dissemination instructions?
The authorized holder of the document or material, at the time of creation. DoD Instruction 5200.48 makes the authorized holder responsible for determining at creation whether information falls into a CUI category and, if it does, for applying CUI markings and dissemination instructions accordingly. The designating agency decides that information is CUI and is the only party that may apply limited dissemination controls under 32 CFR 2002.16; the authorized holder carries those markings and instructions forward onto every derivative document.
What is a CUI authorized holder responsible for?
Verifying a lawful government purpose before sharing, applying and preserving correct markings, safeguarding the information at rest and in transit, refraining from removing another agency's markings, challenging designations believed to be improper, reporting suspected unauthorized disclosure, and destroying CUI so that it is unreadable, indecipherable, and unrecoverable when it is no longer required.
What level of system is required for CUI?
A nonfederal system that processes, stores, or transmits CUI under DFARS 252.204-7012 must implement NIST SP 800-171. Under the CMMC Program rule at 32 CFR Part 170, that corresponds to CMMC Level 2, which is the 110 NIST SP 800-171 security requirements. Cloud services in that boundary must meet security requirements equivalent to the FedRAMP Moderate baseline, and cryptography protecting CUI must be FIPS-validated.
What is CUI Basic?
CUI Basic is the default subset of Controlled Unclassified Information. It applies when the authorizing law, regulation, or government-wide policy requires the information to be protected but does not prescribe specific handling controls, so the uniform rules in 32 CFR Part 2002 apply: the moderate confidentiality baseline, the standard "CUI" banner marking, and the standard dissemination rules. On contractor systems, CUI Basic is protected by implementing NIST SP 800-171, which is what your SPRS score measures. You can baseline yourself with the free SPRS score calculator.
What are examples of CUI?
Common examples in the defense industrial base include controlled technical information such as engineering drawings, specifications, and technical reports carrying a distribution statement; export-controlled information under ITAR or EAR; naval nuclear propulsion information; source selection and contractor bid or proposal information; personally identifiable information and health information the government holds; and protected critical infrastructure information. The authoritative list is the CUI Registry maintained by the National Archives; if a category is not in the Registry, it is not CUI.
What is the difference between CUI Basic and CUI Specified?
CUI Basic follows the uniform safeguarding and dissemination controls in 32 CFR Part 2002 because the authorizing law or policy does not prescribe specifics. CUI Specified follows the specific controls written into the underlying authority, which may be stricter. Export-controlled information is a common Specified example because export law imposes its own access restrictions.
Which of the following are types of CUI?
The authoritative list is the CUI Registry maintained by the National Archives. Its index groupings include Defense, Export Control, Procurement and Acquisition, Privacy, Critical Infrastructure, Proprietary Business Information, Law Enforcement, Legal, Intelligence, Nuclear, Tax, Statistical, Transportation, Immigration, Financial, International Agreements, NATO, Patent, and Natural and Cultural Resources. If a category is not in the Registry, it is not CUI.
Is FCI the same as CUI?
No. Federal Contract Information is defined in FAR 52.204-21 as information not intended for public release that is provided by or generated for the government under a contract. FCI triggers the 15 basic safeguarding requirements of FAR 52.204-21, which is CMMC Level 1. CUI is a higher bar defined by Executive Order 13556 and 32 CFR Part 2002 and triggers NIST SP 800-171 and CMMC Level 2.
What is a CUI enclave?
A CUI enclave is a bounded environment that contains all of an organization's CUI so that security requirements and assessment scope apply to that environment rather than to the entire company. It is an architectural pattern, not a regulatory term, and it works only when the boundary is genuinely enforced in daily workflow.
How fast do I have to report a CUI incident?
DFARS 252.204-7012 requires rapid reporting to the Department of Defense within 72 hours of discovering a cyber incident affecting covered defense information. Reporting requires a medium assurance certificate, and the clause also requires preserving affected images and monitoring data for at least 90 days and submitting isolated malicious software to the government.
Does "For Official Use Only" still exist?
DoD Instruction 5200.48 discontinued the use of the FOUO marking for newly created information in favor of CUI markings. Legacy documents marked FOUO may still be in circulation and do not become uncontrolled automatically, but new material generated under DoD policy is marked as CUI.
Does the July 2026 CMMC pause change CUI handling requirements?
No. The Department of War suspended Phase 2 of the CMMC rollout on July 13, 2026 under memo 26-P-1023, so no date is currently set for third-party C3PAO certification to gate new solicitations while the CMMC Reform Task Force review runs. CUI marking, safeguarding, and incident reporting under 32 CFR Part 2002, DoDI 5200.48, and DFARS 252.204-7012 remain fully in force, as do NIST SP 800-171 self-assessments, SPRS score submissions, annual affirmations, and prime contractor flow-down questionnaires. See the current program status on our CMMC compliance page.
Does CUI ever require more than CMMC Level 2?
Yes. A small set of contractors handling the most sensitive CUI on critical DoD programs falls in the band reserved for CMMC Level 3, which adds 24 NIST SP 800-172 enhanced security requirements on top of the 110 Level 2 requirements, is assessed by the government rather than a C3PAO, and has a Final Level 2 status as a prerequisite. Level 3 contract designations are among the requirements the Department suspended in July 2026. The CUI itself is not a different data class; the program criticality drives the higher level.
Who can help us scope and protect CUI?
Petronella Technology Group, Inc. is a CMMC Registered Provider Organization, RPO #1449, based in Raleigh, North Carolina and serving defense contractors nationwide. Start with a CMMC gap assessment to map where CUI lives, then work the boundary and control implementation from there. Call (919) 348-4912.
Sources and Authorities
Every claim on this page traces to one of the following instruments. Read them directly before making a compliance decision.
- Executive Order 13556, "Controlled Unclassified Information," November 4, 2010
- 32 CFR Part 2002, "Controlled Unclassified Information," the National Archives implementing rule, including 2002.16 (safeguarding and limited dissemination controls), 2002.18 (decontrolling), 2002.20 (marking), and 2002.34 (records transferred to the National Archives)
- Executive Order 13526, "Classified National Security Information," referenced by 32 CFR 2002.18 for concurrent declassification and decontrol
- The CUI Registry, maintained by the National Archives and Records Administration
- DoD Instruction 5200.48, "Controlled Unclassified Information (CUI)," March 6, 2020
- DoD Instruction 5230.24, "Distribution Statements on DoD Technical Information"
- FAR 52.204-21, "Basic Safeguarding of Covered Contractor Information Systems"
- DFARS 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021
- NIST SP 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations"
- NIST SP 800-172, enhanced security requirements referenced by CMMC Level 3
- NIST SP 800-88, "Guidelines for Media Sanitization"
- 32 CFR Part 170, the CMMC Program rule, and the CMMC assessment scoping guidance
Find out exactly where your CUI lives
Most contractors do not have a CUI problem. They have a CUI boundary problem. A gap assessment maps every place CUI enters, rests, moves, and leaves your business, scores you against NIST SP 800-171, and gives you a remediation sequence you can actually execute. Petronella Technology Group, Inc., RPO #1449.