Skip to main content
Compliance

CUI Identification and Marking: A Practical Guide for Contractors

How to identify, mark, and handle Controlled Unclassified Information (CUI) in your organization. Includes marking examples, common CUI categories, and handling procedures.

CMMC Command Team
Compliance Engineering
Mar 6, 20268 min read
Table of Contents(25 sections)

What Is CUI and Why Does It Matter?

Controlled Unclassified Information (CUI) is information that the government creates or possesses or that an entity creates or possesses for the government that requires safeguarding per law, regulation, or government-wide policy. It's not classified, but it's not public either.

For DoD contractors and subcontractors, CUI handling is relevant to Level 2, but the applicable solicitation or contract establishes the CMMC requirement and assessment type. Separate safeguarding obligations may require NIST SP 800-171 even when DFARS 252.204-7021 is absent. The first step is understanding the contract and what information is actually designated CUI.

Potential CUI Categories in Defense Contracting

The examples below are CUI only when they meet the CUI definition and are designated under an applicable government authority. Subject matter, proprietary status, export controls, or a contract relationship alone do not automatically make information CUI.

Technical Data

  • Engineering drawings and specifications
  • Test and evaluation results
  • Manufacturing process documentation
  • Source code for defense-related software
  • Performance specifications
  • Technical manuals and maintenance procedures

Contract and Acquisition Data

  • Proposal information (pre-award)
  • Contract pricing data
  • Source selection information
  • Proprietary business information submitted under contract

Export-Controlled Information

  • ITAR-controlled technical data
  • EAR-controlled technology
  • Munitions list items and data

Other Common Categories

  • Vulnerability assessment results
  • Critical infrastructure information
  • Privacy data (PII of military personnel)
  • Law enforcement sensitive information

How to Identify CUI in Your Organization

Step 1: Contract Review

Start with your contracts. Look for:

  • DFARS 252.204-7012: The primary CUI protection clause
  • DFARS 252.204-7019/7020: NIST 800-171 assessment requirements
  • ITAR clauses: International Traffic in Arms Regulations
  • CUI marking requirements: Some contracts specify how CUI must be marked

Step 2: Data Flow Mapping

Trace where contract-related information flows:

  • Where do you receive technical data from the government or primes?
  • Where is it stored (file servers, cloud, email, workstations)?
  • Who accesses it and through what systems?
  • Where does it leave your organization (to subcontractors, deliverables)?

Step 3: System Inventory

Identify every system that touches CUI:

  • Email systems (CUI in attachments or body)
  • File storage (network drives, SharePoint, cloud storage)
  • Engineering tools (CAD software, PLM systems)
  • Communication tools (Teams, Slack are CUI discussions happening here?)
  • Mobile devices (are engineers accessing CUI remotely?)
  • Backup systems (when the backup set includes CUI)

CUI Marking Requirements

Document Marking

CUI documents should include:

  • Banner marking: "CUI" or an authorized CUI marking at the top of each page; a bottom banner is optional under the NARA marking handbook
  • Category marking: Include category or limited-dissemination markings when required by the designating agency or contract
  • Distribution statement: Include when required by the governing authority
  • Point of contact: Include when required or useful under agency guidance

Example Banner Marking

CUI//SP-CTI
DISTRIBUTION STATEMENT D: Distribution authorized to DoD and U.S. DoD contractors only.

Email Marking

  • Subject line: A CUI indicator may be included; follow the designating agency's or contract's instructions
  • Body: Include the applicable CUI banner at the top
  • Attachments: Mark each attachment individually

Digital File Marking

  • Include CUI designation in file metadata where possible
  • Use descriptive file names that indicate CUI status
  • Store in designated CUI folders/locations

Building Your CUI Boundary

The CUI boundary defines which systems, networks, and physical locations process CUI. This boundary is critical for your SSP and directly impacts your CMMC assessment scope.

Minimize Your Boundary

A carefully designed boundary can limit CUI assets, but security protection assets, contractor risk managed assets, specialized assets, people, facilities, and external service providers can remain in assessment scope:

  • Segment CUI systems from general business systems
  • Use a dedicated enclave for CUI processing when possible
  • Limit CUI access to personnel who genuinely need it
  • Consider virtual desktop infrastructure (VDI) for CUI access

Document the Boundary

Your SSP must clearly define:

  • Network diagrams showing CUI-processing systems
  • Physical locations where CUI is stored or accessed
  • Personnel authorized to access CUI
  • Data flow diagrams showing CUI movement

Common CUI Mistakes

1. CUI Sprawl

CUI ends up everywhere: personal laptops, personal email, unauthorized cloud storage. Implement technical controls to contain it.

2. Over-Classification

Not everything is CUI. Over-marking wastes resources and creates compliance fatigue. Apply CUI markings only under the applicable government authority and guidance.

3. Ignoring Derived CUI

New material created from CUI may retain CUI content or otherwise meet the CUI definition. Follow the designating agency's authority, markings, and contract guidance rather than assuming every derivative document has the same status.

4. Forgetting Backups

Backup systems that store CUI or protect the assessed environment may be in scope. Classify them using the current CMMC scoping rule and guidance.

5. No Destruction Procedures

When CUI is no longer authorized or needed, follow the applicable contract, agency, CUI Registry, and media-sanitization requirements. NIST SP 800-88 provides sanitization guidance; ordinary file deletion may not satisfy the required sanitization method.

How CMMC Command Helps with CUI Management

  • Asset inventory: Track every system in your CUI boundary with scope designation
  • Upload marker screening: Best-effort screening for a limited set of CUI or classification markers; it does not determine a file's information status, and CUI or classified uploads are prohibited
  • SSP drafting: Creates structured boundary-documentation drafts from entered assessment data for review
  • Policy templates: Starting points mapped to NIST topics that require organization-specific review

Map your CUI boundary for free. Start your assessment and document your CUI environment.

CUINIST 800-171DFARSData Classification

Organize your CMMC preparation

Review all 110 requirements and see an estimated SPRS score based on the statuses you enter. Completion time varies. Free, no credit card.