CUI Identification and Marking: A Practical Guide for Contractors
How to identify, mark, and handle Controlled Unclassified Information (CUI) in your organization. Includes marking examples, common CUI categories, and handling procedures.
Table of Contents(25 sections)
What Is CUI and Why Does It Matter?
Controlled Unclassified Information (CUI) is information that the government creates or possesses or that an entity creates or possesses for the government that requires safeguarding per law, regulation, or government-wide policy. It's not classified, but it's not public either.
For DoD contractors and subcontractors, CUI handling is relevant to Level 2, but the applicable solicitation or contract establishes the CMMC requirement and assessment type. Separate safeguarding obligations may require NIST SP 800-171 even when DFARS 252.204-7021 is absent. The first step is understanding the contract and what information is actually designated CUI.
Potential CUI Categories in Defense Contracting
The examples below are CUI only when they meet the CUI definition and are designated under an applicable government authority. Subject matter, proprietary status, export controls, or a contract relationship alone do not automatically make information CUI.
Technical Data
- Engineering drawings and specifications
- Test and evaluation results
- Manufacturing process documentation
- Source code for defense-related software
- Performance specifications
- Technical manuals and maintenance procedures
Contract and Acquisition Data
- Proposal information (pre-award)
- Contract pricing data
- Source selection information
- Proprietary business information submitted under contract
Export-Controlled Information
- ITAR-controlled technical data
- EAR-controlled technology
- Munitions list items and data
Other Common Categories
- Vulnerability assessment results
- Critical infrastructure information
- Privacy data (PII of military personnel)
- Law enforcement sensitive information
How to Identify CUI in Your Organization
Step 1: Contract Review
Start with your contracts. Look for:
- DFARS 252.204-7012: The primary CUI protection clause
- DFARS 252.204-7019/7020: NIST 800-171 assessment requirements
- ITAR clauses: International Traffic in Arms Regulations
- CUI marking requirements: Some contracts specify how CUI must be marked
Step 2: Data Flow Mapping
Trace where contract-related information flows:
- Where do you receive technical data from the government or primes?
- Where is it stored (file servers, cloud, email, workstations)?
- Who accesses it and through what systems?
- Where does it leave your organization (to subcontractors, deliverables)?
Step 3: System Inventory
Identify every system that touches CUI:
- Email systems (CUI in attachments or body)
- File storage (network drives, SharePoint, cloud storage)
- Engineering tools (CAD software, PLM systems)
- Communication tools (Teams, Slack are CUI discussions happening here?)
- Mobile devices (are engineers accessing CUI remotely?)
- Backup systems (when the backup set includes CUI)
CUI Marking Requirements
Document Marking
CUI documents should include:
- Banner marking: "CUI" or an authorized CUI marking at the top of each page; a bottom banner is optional under the NARA marking handbook
- Category marking: Include category or limited-dissemination markings when required by the designating agency or contract
- Distribution statement: Include when required by the governing authority
- Point of contact: Include when required or useful under agency guidance
Example Banner Marking
CUI//SP-CTI
DISTRIBUTION STATEMENT D: Distribution authorized to DoD and U.S. DoD contractors only.
Email Marking
- Subject line: A CUI indicator may be included; follow the designating agency's or contract's instructions
- Body: Include the applicable CUI banner at the top
- Attachments: Mark each attachment individually
Digital File Marking
- Include CUI designation in file metadata where possible
- Use descriptive file names that indicate CUI status
- Store in designated CUI folders/locations
Building Your CUI Boundary
The CUI boundary defines which systems, networks, and physical locations process CUI. This boundary is critical for your SSP and directly impacts your CMMC assessment scope.
Minimize Your Boundary
A carefully designed boundary can limit CUI assets, but security protection assets, contractor risk managed assets, specialized assets, people, facilities, and external service providers can remain in assessment scope:
- Segment CUI systems from general business systems
- Use a dedicated enclave for CUI processing when possible
- Limit CUI access to personnel who genuinely need it
- Consider virtual desktop infrastructure (VDI) for CUI access
Document the Boundary
Your SSP must clearly define:
- Network diagrams showing CUI-processing systems
- Physical locations where CUI is stored or accessed
- Personnel authorized to access CUI
- Data flow diagrams showing CUI movement
Common CUI Mistakes
1. CUI Sprawl
CUI ends up everywhere: personal laptops, personal email, unauthorized cloud storage. Implement technical controls to contain it.
2. Over-Classification
Not everything is CUI. Over-marking wastes resources and creates compliance fatigue. Apply CUI markings only under the applicable government authority and guidance.
3. Ignoring Derived CUI
New material created from CUI may retain CUI content or otherwise meet the CUI definition. Follow the designating agency's authority, markings, and contract guidance rather than assuming every derivative document has the same status.
4. Forgetting Backups
Backup systems that store CUI or protect the assessed environment may be in scope. Classify them using the current CMMC scoping rule and guidance.
5. No Destruction Procedures
When CUI is no longer authorized or needed, follow the applicable contract, agency, CUI Registry, and media-sanitization requirements. NIST SP 800-88 provides sanitization guidance; ordinary file deletion may not satisfy the required sanitization method.
How CMMC Command Helps with CUI Management
- Asset inventory: Track every system in your CUI boundary with scope designation
- Upload marker screening: Best-effort screening for a limited set of CUI or classification markers; it does not determine a file's information status, and CUI or classified uploads are prohibited
- SSP drafting: Creates structured boundary-documentation drafts from entered assessment data for review
- Policy templates: Starting points mapped to NIST topics that require organization-specific review
Map your CUI boundary for free. Start your assessment and document your CUI environment.
Related Resources
Organize your CMMC preparation
Review all 110 requirements and see an estimated SPRS score based on the statuses you enter. Completion time varies. Free, no credit card.