Home / Compliance / CUI / Who can decontrol CUI
CUI decontrol authorityWho Can Decontrol CUI? The Authority, the Rules, and What Contractors Can Do
The agency that designated the information decontrols CUI, through the personnel it authorizes (32 CFR 2002.18). In the Department of Defense, DoDI 5200.48 paragraph 3.3.a.(2) names the originator of the information, the original classification authority (OCA) if identified in a security classification guide, or designated offices for decontrolling CUI. A contractor cannot decontrol CUI itself. It can ask.
The short version
- Decontrol belongs to the designating agency. 32 CFR 2002.18 lets agencies decontrol CUI automatically when a listed condition occurs, or through an affirmative decision by the designating agency, and lets each agency name the personnel it authorizes.
- The Department of Defense names three. DoD Instruction 5200.48, paragraph 3.3.a.(2): the originator of the information, the original classification authority (OCA) if identified in a security classification guide, or designated offices for decontrolling CUI.
- A contractor is an authorized holder, not a decontrol authority. The regulation gives a holder one channel of its own: a request to the designating agency, under 32 CFR 2002.18(h).
- Decontrol is not public release. 32 CFR 2002.18(e) says decontrolling relieves holders of CUI handling requirements but does not constitute authorization for public release.
- A leak decontrols nothing. Under 32 CFR 2002.18(j), unauthorized disclosure of CUI does not constitute decontrol.
Who Can Decontrol CUI: The Authority Table
The question "who can decontrol CUI" has a government-wide answer and a Department of Defense answer, and they fit together. The government-wide rule is 32 CFR Part 2002, the regulation the National Archives and Records Administration issued as Executive Agent for the CUI Program. The DoD answer is DoD Instruction 5200.48, which applies that rule inside the Department. The table below lists every party either source names, the paragraph that names it, and the limit on what that party can decontrol. It is the expanded version of the summary on our CUI hub.
| Who | Under what authority | What they can decontrol |
|---|---|---|
| The designating agency | 32 CFR 2002.18(a), (b), and (c) | CUI that the agency itself designated and that no longer requires safeguarding or dissemination controls, unless decontrol would conflict with the governing law, regulation, or government-wide policy. |
| Agency personnel named in the agency's CUI policy | 32 CFR 2002.18(d) | Whatever the agency's CUI policy authorizes them to decontrol, consistent with law, regulation, and government-wide policy. |
| The originator of the information (DoD) | DoDI 5200.48, paragraphs 3.3.a.(2) and 4.4.b | DoD CUI records the originator created, once a formal review under DoDI 5230.09 is complete and the information no longer requires protection from public disclosure. |
| The original classification authority (OCA) (DoD) | DoDI 5200.48, paragraph 3.3.a.(2) | DoD CUI records, and only where the OCA is identified in a security classification guide. |
| Designated offices for decontrolling CUI (DoD) | DoDI 5200.48, paragraph 3.3.a.(2) | CUI records handled under the procedures for review and release of information under the Freedom of Information Act. Paragraph 4.4.b gives initial FOIA denial and appellate authorities as examples of other competent authority. |
| The Archivist of the United States | 32 CFR 2002.18(m) and 2002.34 | Records transferred to the National Archives, absent a specific agreement otherwise with the designating agency. |
| An authorized holder, including a contractor | 32 CFR 2002.18(h) and 2002.20(e)(2) | Nothing on its own decision. A holder may request decontrol from the designating agency, and may treat an item as decontrolled when the decontrol date or event the designator marked on it arrives. |
Read the last row twice. It is the row most people searching this question work under, and it is the one that produces incidents when someone guesses.
What 32 CFR 2002.18 and DoDI 5200.48 Actually Say
The government-wide rule: 32 CFR 2002.18
Section 2002.18 is titled "Decontrolling." Paragraph (a) sets the duty: agencies should decontrol as soon as practicable any CUI designated by their agency that no longer requires safeguarding or dissemination controls, unless doing so conflicts with the governing law, regulation, or government-wide policy. Paragraph (b) says agencies may decontrol CUI automatically upon the occurrence of one of four listed conditions, or through an affirmative decision by the designating agency. Paragraph (d) is the sentence that answers the "who" question directly:
"An agency may designate in its CUI policies which agency personnel it authorizes to decontrol CUI, consistent with law, regulation, and Government-wide policy."32 CFR 2002.18(d)
The definitions in 32 CFR 2002.4 frame it the same way. A designating agency is the executive branch agency that designates or approves the designation of a specific item of information as CUI. Decontrolling occurs when an authorized holder, consistent with Part 2002 and the CUI Registry, removes safeguarding or dissemination controls from CUI that no longer requires such controls, and it may occur automatically or through agency action. So the holder is the one who physically stops applying the controls, but only after the regulation's conditions or the agency's decision say the controls are no longer required.
The DoD rule: DoDI 5200.48, paragraph 3.3.a.(2)
DoD Instruction 5200.48, "Controlled Unclassified Information (CUI)," took effect March 6, 2020. Its glossary defines decontrol by pointing straight back to 32 CFR 2002.18, and paragraph 3.3.a.(2) names who executes it inside the Department:
"Decontrolling and releasing CUI records will be executed by the originator of the information, the original classification authority (OCA) if identified in a security classification guide, or designated offices for decontrolling CUI pursuant to the procedures for the review and release of information under the FOIA in accordance with the November 19, 2018 ISOO Notice."DoDI 5200.48, paragraph 3.3.a.(2)
Paragraph 4.4 adds the procedure. Under 4.4.a, CUI documents and materials will be formally reviewed in accordance with DoDI 5230.09 before being decontrolled or released to the public. Under 4.4.b, the originator or other competent authority, for example initial FOIA denial and appellate authorities, terminates the CUI status of specific information when it no longer requires protection from public disclosure. All known holders are then notified by email or other means, and upon notification holders remove the CUI markings.
If you are answering the DoD CUI training question
Many people arrive here from the mandatory DoD CUI awareness course, where the question is phrased "Who can decontrol CUI? Select the best answer." We do not publish or verify the course's answer key, and the wording of the choices changes between versions. What we can tell you is what the governing instruction says, because that is what the course is built on: DoDI 5200.48 paragraph 3.3.a.(2) lists the originator of the information, the OCA if identified in a security classification guide, and designated offices for decontrolling CUI. An answer that matches that list matches the instruction. An answer that says any authorized holder, any cleared employee, or the contractor's security officer does not.
When CUI Is Decontrolled: Automatic Conditions and Agency Decisions
Authority and timing are two halves of the same rule. 32 CFR 2002.18(b) lists four conditions under which an agency may decontrol automatically, and 2002.18(c) adds two more routes the designating agency may use.
- The law stops requiring control. When laws, regulations, or government-wide policies no longer require control of the information as CUI and the authorized holder has the appropriate authority under the authorizing law, regulation, or government-wide policy (2002.18(b)(1)).
- Proactive public disclosure. When the designating agency decides to release the information to the public by making an affirmative, proactive disclosure (2002.18(b)(2)).
- Disclosure under an access statute. When the agency discloses it under an applicable information access statute, such as the Freedom of Information Act, or the Privacy Act when legally permissible, if the agency incorporates such disclosures into its public release processes (2002.18(b)(3)).
- A marked date or event arrives. When a predetermined event or date occurs, unless law, regulation, or government-wide policy requires coordination first (2002.18(b)(4)). The marking rules for these decontrolling indicators sit in 32 CFR 2002.20(e).
- A holder asks and the agency agrees. The designating agency may decontrol in response to a request by an authorized holder (2002.18(c)(1)).
- Alongside declassification. The designating agency may decontrol concurrently with a declassification action under Executive Order 13526, as long as the information also appropriately qualifies for decontrol as CUI (2002.18(c)(2)).
There is no default expiration clock
CUI does not age out. DoDI 5200.48 paragraph 3.3.a.(2) states that there are no specific timelines to decontrol CUI unless specifically required in a law, regulation, or government-wide policy, and that decontrol will occur when the CUI no longer requires safeguarding and will follow DoD records management procedures. A ten-year-old drawing with a CUI banner is still CUI unless one of the conditions above has occurred.
What changed in September 2026: ISOO Notice 2026-07
On September 2, 2026, the Information Security Oversight Office issued ISOO Notice 2026-07, "Executive Agent Guidance for Implementation of the Controlled Unclassified Information Program." Two passages matter for decontrol. First, under "Decontrol and Disposition," the notice says agencies must establish procedures for the timely decontrol of CUI when it no longer requires protection, and must include the identification of a specific decontrolling date or event with all CUI. Second, under "Contracts and Information-Sharing Agreements," it says that for all contracts requiring access to CUI, agencies must at a minimum give the prime contractor specific guidance on a list of topics that includes decontrol and disposition requirements and the process for CUI challenges.
The notice is addressed to agencies. Its closing paragraph says it does not apply to and is not meant to bind the public, except as authorized by law or regulation or as incorporated into a contract. For a contractor, its practical value is that it tells you what to expect in the contract: if your contract gives you CUI and says nothing about decontrol or disposition, that is a gap to raise with the contracting officer in writing, citing the notice.
What a Contractor Can and Cannot Do
Neither 32 CFR Part 2002 nor DoDI 5200.48 contains a sentence that reads "contractors cannot decontrol CUI." The conclusion comes from the structure of the rule: every route in 2002.18 runs through the designating agency, the governing law, a date or event the designator marked, or the Archivist. None of them runs through the judgment of the company holding the file. Here is what the sources do give an authorized holder.
What a contractor can do
- Request decontrol. "Authorized holders may request that the designating agency decontrol certain CUI" (32 CFR 2002.18(h)). The agency may decontrol in response (2002.18(c)(1)). It is not required to agree.
- Rely on a marked decontrol date or event. Under 32 CFR 2002.20(e)(2), authorized holders may consider specific items of CUI as decontrolled as of the date indicated, requiring no further review by, or communication with, the designator. If the indicator is an event, 2002.20(e)(3) requires that the event be foreseeable and verifiable by any authorized holder. The authority here still comes from the designator, who wrote the date or event onto the document.
- Act on a termination notice. When a DoD originator or other competent authority terminates CUI status and notifies known holders, DoDI 5200.48 paragraph 4.4.b says holders will remove the CUI markings.
- Release through the agency's own procedures. If an authorized holder publicly releases CUI in accordance with the designating agency's authorized procedures, the release constitutes decontrol of the information (32 CFR 2002.18(i)). For DoD work that means the prepublication and security policy review described in DoDI 5200.48 paragraphs 3.3.a.(1) and 5.3.d, not a decision made inside the company.
- Challenge a designation you believe is wrong. This is a different process from decontrol. Under 32 CFR 2002.50(a), authorized holders who in good faith believe a designation is improper or incorrect should notify the disseminating agency. Under 2002.50(d), until the challenge is resolved, holders should continue to safeguard and disseminate the challenged CUI at the control level indicated in the markings.
What a contractor cannot do
- Decide that information is no longer sensitive and remove the controls. No paragraph of 32 CFR 2002.18 gives an authorized holder that decision.
- Treat the end of a contract or a program as decontrol. Contract completion is not among the conditions listed in 2002.18(b) or (c).
- Treat age as decontrol. There are no specific timelines unless a law, regulation, or government-wide policy sets one (DoDI 5200.48, paragraph 3.3.a.(2)).
- Treat a leak as decontrol. "Unauthorized disclosure of CUI does not constitute decontrol" (32 CFR 2002.18(j)). If the disclosure involved your information system, the 72-hour cyber incident reporting duty in DFARS 252.204-7012 is the clock to watch, not a decontrol theory.
- Strip markings to make sharing easier. Under 32 CFR 2002.20(a)(7), the lack of a CUI marking on information that qualifies as CUI does not exempt the authorized holder from the applicable handling requirements. Removing the banner removes nothing else.
How to ask for decontrol in practice
The regulation gives you the right to ask and does not prescribe a form. What follows is our working practice with defense suppliers, not a regulatory requirement. Identify the designating agency from the CUI designation indicator on the first page or cover. For DoD documents that indicator is the "Controlled by" block described in DoDI 5200.48 paragraph 3.4.f, and its last line is a point of contact. Send the request through your contracting officer, or through your prime if you are a subcontractor, and copy the point of contact named on the document. List the specific documents, say why you believe they no longer require safeguarding, and ask for a written answer. Keep handling the material as CUI until that answer arrives. File the answer with the documents, because it is the evidence an assessor will ask for later. If the question turns on contract interpretation or an export control statute, ask your contracting officer and your own counsel. This page is compliance education, not legal advice.
Decontrol vs Public Release: Two Different Decisions
Decontrol ends the CUI handling requirements. It does not clear the information for publication. The regulation says so in two separate paragraphs, which is a fair sign the drafters expected the confusion.
"Decontrolling CUI relieves authorized holders from requirements to handle the information under the CUI Program, but does not constitute authorization for public release."32 CFR 2002.18(e)
Paragraph (g) follows up: once decontrolled, any public release of information that was formerly CUI must be in accordance with applicable law and agency policies on the public release of information. The definition of public release in 32 CFR 2002.4 runs the same direction. Public release occurs when the agency that originally designated the information makes it available through the agency's official public release processes, and disseminating CUI to non-executive branch entities as authorized does not constitute public release. Receiving CUI under a contract therefore tells you nothing about whether the information is public.
DoD adds its own gate. DoDI 5200.48 paragraph 4.4.b ends with this sentence: "Information with a terminated CUI status will not be publicly released without review and approval in accordance with DoDIs 5230.09, 5230.29, and 5400.04." Paragraph 5.3.d requires DoD personnel and contractors, pursuant to mandatory DoD contract provisions, to submit unclassified DoD information for review and approval for release. So a conference paper, a marketing case study, or a website photo built from formerly controlled program information still goes through release review.
The Freedom of Information Act route works in the other direction. The November 19, 2018 joint memorandum from the Information Security Oversight Office and the Department of Justice Office of Information Policy tells agencies to base a FOIA disclosure decision on the content of the information and the FOIA exemptions, regardless of whether the information was marked CUI, and says that as a general matter information released in response to a FOIA request can no longer be protected as CUI and is essentially decontrolled by the agency. That is an agency action. A contractor that receives a records request does not get to apply it.
On your own systems, the matching control is NIST SP 800-171 Revision 2 requirement 3.1.22, control CUI posted or processed on publicly accessible systems. We cover implementation on the 3.1.22 publicly accessible systems page.
Marking After Decontrol
The marking duties after decontrol are lighter than most teams expect, and 32 CFR 2002.18(f) sets them out.
- You must show the change only in five situations. Authorized holders must clearly indicate that CUI is no longer controlled when restating, paraphrasing, re-using, releasing to the public, or donating it to a private institution. Otherwise, holders do not have to mark, review, or take other actions to indicate the CUI is no longer controlled.
- Agency policy may allow a first-page strike-through. Under 2002.18(f)(1), agency policy may allow holders to remove or strike through only the CUI markings on the first or cover page of the decontrolled CUI and on the first page of any attachments that contain CUI.
- New documents carry no CUI markings for the decontrolled information. Under 2002.18(f)(2), a holder who uses decontrolled CUI in a newly created document must remove all CUI markings for the decontrolled information.
- DoD holders do not have to pull old files. DoDI 5200.48 paragraph 4.4.b says that upon notification holders will remove the CUI markings, and that holders will not need to retrieve records on file solely for this purpose.
- Specific procedures override the general rule. When laws, regulations, or government-wide policies require specific decontrol procedures, authorized holders must follow them (32 CFR 2002.18(l)). For export-controlled technical information, DoDI 5200.48 paragraph 4.3.c keeps distribution statements and the export control warning in place, and those do not disappear with the CUI banner.
Mixed documents need care. When CUI is commingled with classified national security information, 32 CFR 2002.20(g) says the decontrolling provisions apply only to portions marked as CUI. The classified portions follow declassification rules, which are a separate authority.
The decontrol indicator you should look for first
Before writing to anyone, read the first page. 32 CFR 2002.20(e)(1) says that where feasible, designating agencies must include a specific decontrolling date or event with all CUI, in any manner that makes the decontrolling schedule readily apparent to an authorized holder. When the designator uses an event rather than a date, 2002.20(e)(3)(ii) says the designator should include a point of contact and preferred method of contact so holders can verify that the event has occurred. The five-line designation indicator in DoDI 5200.48 Figure 2 has no line for a decontrol date, so a DoD document can be marked exactly as the instruction requires and still carry none. ISOO Notice 2026-07 now tells agencies to include a decontrolling date or event with all CUI, so expect this to show up more often on newly created material.
Marking, Handling, and Dissemination While the Information Is Still CUI
Until one of the decontrol routes has actually occurred, the full set of CUI duties applies. These are the ones that interact with decontrol questions most often.
Marking
Under 32 CFR 2002.20(b), designators must mark all CUI with a CUI banner marking, whose mandatory element is the control marking: the word "CONTROLLED" or the acronym "CUI." Under 2002.20(c)(1), the content of the banner must apply to the whole document and be the same on each page that includes CUI. Under 2002.20(d), all documents containing CUI must carry a designation indicator that identifies at least the designator's agency. DoD tightens this: DoDI 5200.48 paragraph 3.4.a requires the acronym "CUI" in the banner and footer of unclassified DoD documents, and paragraph 3.4.f requires a generic "CUI" marking at the top and bottom of each page plus the designation indicator on the first page or cover. For media, NIST SP 800-171 Revision 2 requirement 3.8.4 is to mark media with necessary CUI markings and distribution limitations, which we cover on the 3.8.4 media marking page. Our DoDI 5200.48 explainer walks through the DoD marking minimums.
Legacy markings are not a decontrol signal
Old markings such as FOUO cause a specific mistake: someone reads "legacy marking" as "no longer controlled." The sources say something narrower. Under 32 CFR 2002.20(a)(2), if legacy markings remain on information, the legacy markings are void and no longer indicate that the information is protected or that it is or qualifies as CUI. Under DoDI 5200.48 paragraph 3.2.b, DoD legacy information does not automatically become CUI and must be reviewed. Paragraph 3.2 also says any new document created with information derived from legacy material must be marked as CUI if the information qualifies as CUI. A void marking is therefore a prompt to find out what the information is, not a finding that it is free to share.
Dissemination controls
Limited dissemination control markings are the third, optional element of the banner under 32 CFR 2002.20(b)(3), and agency policy decides which authorized holders may apply them. DoDI 5200.48 paragraph 4.1 explains why they matter here: dissemination statements facilitate control, secondary sharing, decontrol, and release without the need to repeatedly obtain approval or authorization from the controlling DoD office. In other words, a well-marked document already tells you who may receive it, which removes much of the pressure to get it decontrolled in the first place. Day-to-day handling for suppliers further down the chain is covered in CUI handling for DoD subcontractors and the CUI handler field manual.
Destruction is usually the faster route
If the real goal is to stop carrying old CUI, destruction is the lever a contractor controls, subject to the contract's records and disposition terms. DoDI 5200.48 paragraph 4.5.a says that when destroying CUI, including in electronic form, agencies must do so in a manner making it unreadable, indecipherable, and irrecoverable, and paragraph 5.3.e requires CUI records held by non-DoD entities to follow the approved mandatory disposition authorities. NIST SP 800-171 Revision 2 requirement 3.8.3 is to sanitize or destroy system media containing CUI before disposal or release for reuse. See sanitize or destroy CUI media before disposal for methods and evidence.
What Decontrol Does to CMMC and NIST SP 800-171 Scope
Start with what the standard does not say. We searched the full text of NIST SP 800-171 Revision 2 and Revision 3 for the word "decontrol." It appears once in each, in the introduction, in a sentence describing what the federal CUI regulation covers. Neither revision contains a decontrol requirement, a decontrol procedure, or an assessment objective about decontrol. NIST leaves the subject to 32 CFR Part 2002, and so should your System Security Plan.
What NIST and the CMMC rule do define is scope. NIST SP 800-171 Revision 3, section 1.1, says the security requirements are only applicable to components of nonfederal systems that process, store, or transmit CUI or that provide protection for such components. The CMMC rule at 32 CFR 170.19(c)(1), Table 3, defines CUI Assets as assets that process, store, or transmit CUI, and puts them in the Level 2 assessment scope. Scope follows where CUI is. Two consequences follow, and the second one is our reading rather than a quotation.
- Decontrol is not a scoping tool you control. Because the decision belongs to the designating agency, a contractor cannot shrink its assessment boundary by declaring old project data no longer CUI. An assessor who finds formerly marked files on an out-of-scope file share will ask for the agency's decision, and "we judged it stale" is not one.
- A real decontrol can change what an asset holds, and you have to prove it. If the designating agency does decontrol a body of information, 32 CFR 2002.18(e) relieves you of the CUI handling requirements for it. Before you treat a server or share as out of scope, keep the agency's notice, confirm that nothing else on the asset is CUI, and update the asset inventory, data flow diagram, and System Security Plan so the boundary on paper matches the boundary in fact.
The levers that reliably reduce scope are the ones you own: retention and destruction, and boundary design. Section 1.1 of Revision 3 says organizations may limit the scope of the security requirements by isolating the designated system components in a separate security domain. That is the enclave approach, which depends on the flow enforcement covered on the control CUI flow page, and mapping where CUI actually lives is the first deliverable of our CMMC gap assessment. A decontrol notice by itself does not implement or remove any security requirement, so it does not move a self-assessment score; if you are working on that number, the SPRS calculator walks through all 110 requirements with the DoD weights of 5, 3, and 1. For the full Level 2 picture, see CMMC Level 2 compliance.
A Worked Example: The Ten-Year-Old Drawing Package
This example is hypothetical. It is a composite of questions we hear, not a client story.
A 40-person machine shop finished a DoD subcontract years ago. Its engineering share still holds the drawing package, every sheet marked "CUI" top and bottom, with a designation indicator naming a DoD program office. The shop is preparing for a Level 2 assessment, and the IT manager proposes moving the package to the general file server to keep the engineering share out of scope. His reasoning: the program is over and the drawings are old.
- Check the first page for a decontrol date or event. If the designator marked one and it has passed, 32 CFR 2002.20(e)(2) lets the shop treat those items as decontrolled without further communication. This package has none.
- Check for a termination notice. Under DoDI 5200.48 paragraph 4.4.b, known holders are notified when CUI status is terminated. The shop has received nothing from the prime or the program office.
- Test the IT manager's two reasons against the rule. Program completion is not a condition in 32 CFR 2002.18(b) or (c). Age is not either, and DoDI 5200.48 paragraph 3.3.a.(2) says there are no specific timelines. The package is still CUI.
- Pick a lawful route. The shop can request decontrol through the prime under 32 CFR 2002.18(h), or, if the contract's disposition terms allow, destroy the package to the unreadable, indecipherable, and irrecoverable standard and keep the record. If it needs the drawings for future quotes, it keeps them inside the CUI boundary.
- If the agency says yes, finish the job properly. File the written decision. Apply the marking rule in 2002.18(f). Remember 2002.18(e) and (l): the drawings are still not cleared for the company website, and if they are export controlled, the distribution statement and export warning described in DoDI 5200.48 paragraph 4.3.c still govern who may receive them.
The second option in step four is usually the practical one. Destruction under the contract's terms is within the shop's control, while a decontrol request depends on an answer from an agency office. Either way, the move to the general file server does not happen on the IT manager's say-so.
Frequently Asked Questions: Who Can Decontrol CUI
Who can decontrol CUI?
The agency that designated the information, acting through the personnel it authorizes under 32 CFR 2002.18(d). Inside the Department of Defense, DoDI 5200.48 paragraph 3.3.a.(2) names the originator of the information, the original classification authority (OCA) if identified in a security classification guide, or designated offices for decontrolling CUI. The Archivist of the United States may decontrol records transferred to the National Archives under 32 CFR 2002.18(m).
Who can decontrol CUI: the OCA, the originator, or a designated office?
All three appear in DoDI 5200.48 paragraph 3.3.a.(2), which says decontrolling and releasing CUI records will be executed by the originator of the information, the original classification authority if identified in a security classification guide, or designated offices for decontrolling CUI. We do not publish the answer key for the DoD CUI training course. An answer choice that matches that list matches the instruction.
Can a contractor decontrol CUI?
Not on its own decision. Under 32 CFR 2002.18(h), an authorized holder may request that the designating agency decontrol certain CUI, and under 2002.18(c)(1) the agency may agree. A holder may also treat an item as decontrolled when a decontrol date or event marked by the designator arrives, under 32 CFR 2002.20(e)(2). Send requests through your contracting officer and keep the written answer.
What can decontrol CUI automatically?
32 CFR 2002.18(b) lists four conditions: the governing law, regulation, or government-wide policy no longer requires control and the holder has the appropriate authority under it; the designating agency proactively releases the information to the public; the agency discloses it under an access statute such as the Freedom of Information Act and incorporates such disclosures into its public release processes; or a predetermined date or event occurs.
Does CUI expire after a certain number of years?
No general clock exists. DoDI 5200.48 paragraph 3.3.a.(2) says there are no specific timelines to decontrol CUI unless specifically required in a law, regulation, or government-wide policy. A specific item is decontrolled by date only if the designator marked a decontrol date or event on it, which 32 CFR 2002.20(e)(1) requires where feasible and which ISOO Notice 2026-07 now tells agencies to include with all CUI.
Is decontrolled CUI cleared for public release?
No. 32 CFR 2002.18(e) says decontrolling CUI relieves authorized holders from requirements to handle the information under the CUI Program, but does not constitute authorization for public release. Under DoDI 5200.48 paragraph 4.4.b, information with a terminated CUI status will not be publicly released without review and approval in accordance with DoDIs 5230.09, 5230.29, and 5400.04.
Do I have to remove CUI markings after decontrol?
Only in some cases. Under 32 CFR 2002.18(f), holders must clearly indicate that CUI is no longer controlled when restating, paraphrasing, re-using, releasing to the public, or donating it to a private institution, and must remove all CUI markings for the decontrolled information in any newly created document. Otherwise no action is required. DoDI 5200.48 paragraph 4.4.b says holders remove the markings upon notification but do not need to retrieve records on file solely for that purpose.
Does a leak or an accidental public posting decontrol CUI?
No. 32 CFR 2002.18(j) says unauthorized disclosure of CUI does not constitute decontrol, and 2002.18(k) bars agencies from decontrolling CUI to conceal, or to circumvent accountability for, an identified unauthorized disclosure. The information is still CUI. If the disclosure was a cyber incident affecting a covered contractor information system, DFARS 252.204-7012 requires a report to DoD within 72 hours of discovery.
Does decontrol reduce my CMMC assessment scope?
Not by your own declaration. CMMC Level 2 scope under 32 CFR 170.19(c)(1) follows the assets that process, store, or transmit CUI, and a contractor has no authority to decide that information has stopped being CUI. If an agency does decontrol information you hold, keep its written notice and update your asset inventory and System Security Plan before treating any system as out of scope. Petronella Technology Group, Inc., RPO #1449, maps this during a gap assessment. Call 919-348-4912.
Sources and Authorities
Every regulatory statement on this page traces to one of these documents, which we retrieved and read on 2026-09-20. Read them directly before making a compliance decision. Where the page describes our own practice or our own reading, it says so.
- 32 CFR 2002.18, Decontrolling (eCFR, current as of August 17, 2026)
- 32 CFR 2002.20, Marking, including paragraph (e), CUI decontrolling indicators, and paragraph (g), commingling with classified information
- 32 CFR 2002.4, Definitions (authorized holder, decontrolling, designating agency, public release)
- 32 CFR 2002.50, Challenges to designation of information as CUI, and 32 CFR 2002.34, Transferring records
- DoD Instruction 5200.48, "Controlled Unclassified Information (CUI)," effective March 6, 2020, paragraphs 3.2, 3.3.a, 3.4, 4.1, 4.3.c, 4.4, 4.5, 5.3, and Figure 2. Published by the DoD Directives Division at esd.whs.mil.
- CUI Registry: Decontrol, National Archives and Records Administration
- ISOO Notice 2026-07, "Executive Agent Guidance for Implementation of the Controlled Unclassified Information Program," September 2, 2026
- CUI Joint Memo 2018-11-19, "Decontrolling Controlled Unclassified Information (CUI) in response to a Freedom of Information Act (FOIA) request," ISOO and the Department of Justice Office of Information Policy
- NIST SP 800-171 Revision 2 (requirements 3.1.22, 3.8.3, 3.8.4) and NIST SP 800-171 Revision 3 (section 1.1)
- 32 CFR 170.19, CMMC scoping, paragraph (c)(1), Table 3
- DFARS 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting" (definition of rapidly report: within 72 hours of discovery of any cyber incident)
This page is compliance education from a CMMC Registered Provider Organization. It is not legal advice, and it is not an official statement of any agency. For a binding answer about a specific document, ask the designating agency through your contracting officer.
Not sure what in your environment is still CUI?
Most decontrol questions are really scoping questions: what do we hold, who designated it, and where does it live. Petronella Technology Group, Inc. is a CMMC Registered Provider Organization, RPO #1449, and our Registered Practitioners map CUI for defense contractors before an assessor does. Call Penny at 919-348-4912 and ask for a CMMC Registered Practitioner.