ScopeHunter · Reference
What is CUI, and how is it marked?
A plain-language guide to Controlled Unclassified Information: what qualifies, what doesn't, and how to read and apply the markings. Written for small defense contractors; grounded in 32 CFR Part 2002, DoDI 5200.48 and the NARA CUI Registry.
The definition
CUI is information the government creates or possesses — or that you create or receive on the government's behalf — that a law, regulation, or government-wide policy says must be safeguarded or dissemination-controlled. It is not classified, but it is not public either. The exhaustive list of what counts lives in the NARA CUI Registry; nothing outside the Registry's categories is CUI.
Typically IS CUI (defense work)
Controlled Technical Information (CTI) — drawings, specs, test data delivered under a DoD contract with a distribution statement B–F · export-controlled technical data (ITAR/EAR) · procurement-sensitive information · covered defense information identified in your contract (DFARS 252.204-7012) · certain PII/health/legal categories when the government hands them to you.
Is NOT CUI
Your own commercial IP and internal business data · publicly released information (Distribution Statement A) · everything on a contract just because a contract exists — CUI is what the government designates, not everything nearby · classified information (that is a different regime entirely) · legacy "FOUO" material, unless it has been re-designated as CUI.
Who tells you?
The contract should. DFARS-covered awards identify covered defense information; the proposed FAR CUI rule (re-proposed June 2026) adds a Standard Form the agency must complete naming exactly what CUI is involved. If a document arrives marked, the marking is the sender telling you. If you believe something is CUI but nothing says so, ask the contracting officer — do not guess in either direction.
CUI Basic vs CUI Specified
| CUI Basic | CUI Specified | |
|---|---|---|
| What it means | The default: the underlying law says "protect this" but not how. | The underlying law prescribes specific handling (export control is the classic case). |
| Handling | Uniform 32 CFR 2002 baseline (NIST SP 800-171 on contractor systems). | The 2002 baseline PLUS whatever the specific law requires. |
| Marking | CUI banner; category optional. | Category marking required, with the SP- prefix: CUI//SP-CTI. |
Reading and applying the markings
Three parts, per 32 CFR 2002.20 and DoDI 5200.48:
1. The banner — top and bottom of every page
or, with a Specified category and a limited-dissemination control:
The banner word may be CUI or CONTROLLED. Category codes follow after // (SP- prefix means Specified). Dissemination controls come last: NOFORN (no foreign nationals), FEDCON (federal employees and contractors only), REL TO (releasable to listed countries), DL ONLY (named distribution list).
2. The designation indicator — on the first page or cover
This is the block that answers "who says this is CUI and under what category." A document you produce that contains CUI you received should carry a designation indicator pointing back at the designating office — you don't become the designator by copying.
3. Portion markings — optional
Marking individual paragraphs (CUI) is allowed but not required. If you portion-mark anything, portion-mark everything in the document.
Common traps
- FOUO is not CUI. "For Official Use Only" is the legacy regime; it stays legacy until the owner re-designates it. Don't re-stamp old FOUO as CUI on your own authority — and don't ignore it either; ask the source.
- Over-marking is a real violation too. Marking non-CUI as CUI restricts information the public may be entitled to and is contrary to the rule. Mark what is designated; nothing else.
- Mobile code ≠ mobile devices, and CUI ≠ "anything sensitive." Terms of art have definitions; the Registry is the authority for CUI the way the NIST glossary is for control language.
- Distribution Statement A means public release — it is the one distribution statement that is not CUI.
What receiving CUI obligates you to
On contractor systems, CUI must be protected per NIST SP 800-171 (Revision 2, for current DoD assessments) — which is exactly what a CMMC Level 2 assessment measures and what an SPRS score summarizes. Marked CUI arriving in a system not authorized to hold it is a reportable event under DFARS 252.204-7012's 72-hour rule when it constitutes a cyber incident on a covered system.
ScopeHunter's compliance workspace tracks those controls against live host evidence, flags CUI-marked content entering the platform, and keeps the POA&M and SSP that an assessor asks for. See how the workspace works or how the host evidence is automated.
Primary sources
- 32 CFR Part 2002 — the CUI Program rule (marking rules at §2002.20)
- NARA CUI Registry — the exhaustive category list
- DoD CUI Program and DoDI 5200.48 — DoD implementation and marking guide
- DFARS 252.204-7012 — safeguarding covered defense information + 72-hour incident reporting
This guide is educational, not legal advice; your contract and the designating agency's instructions control. Last reviewed September 2026 — the FAR CUI rule and the 800-171 R3 transition are both in active rulemaking.