Controlled Unclassified Information has to be identified before it can be protected — and marking is how everyone downstream knows what they are holding. Get it wrong and you either over-restrict information you did not need to, or worse, fail to flag information that needed safeguarding. The rules come from 32 CFR Part 2002 and the National Archives (NARA) CUI program.

The core elements of a CUI marking

  • The banner marking at the top of the document, beginning with ‘CUI,’ identifies that the material is controlled.
  • Category markings identify what kind of CUI it is — the specific category from the NARA CUI Registry (for example, export-controlled or procurement-sensitive information).
  • Limited-dissemination controls, where applicable, add handling restrictions.
  • A designation indicator shows who designated the information and provides a point of contact.

Two ways teams get it wrong

Under-marking is the dangerous one: CUI that flows through email, shared drives, and tickets without ever being flagged, so no one applies the safeguards. Over-marking is the quieter cost: labeling everything ‘CUI’ out of caution, which desensitizes people and expands your protection scope needlessly.

Marking and scope go together

Marking discipline and CUI scoping are two sides of the same coin. When you know exactly what is CUI and it is marked consistently, you can draw a tight boundary around it. When marking is sloppy, CUI sprawls — and so does the cost of protecting it.

We help contractors identify, mark, and scope CUI so the boundary — and the program around it — stays manageable. See how we help teams get their CUI under control.