Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
MARKING WORKFLOW

CUI Marking for Defense Contractors: Files, Email, Media, and Common Mistakes

A contractor-focused CUI marking guide covering banner markings, Basic vs Specified CUI, email and media handling, source authority, and what to do when markings are missing or unclear.

Marking is a handling signal, not the source of CUI status. Defense contractors therefore need two skills at the same time: recognize the Government-authorized CUI category/marking framework and avoid inventing markings merely because information feels sensitive.

CUI marking is not a branding exercise and it is not a substitute for determining whether information is actually Controlled Unclassified Information. The National Archives CUI Registry is the Government-wide reference for CUI categories, safeguarding or dissemination authorities, and authorized markings. Defense contractors also need to read the contract, agency instructions, and the way DoD identifies covered defense information under DFARS 252.204-7012.

The practical problem is that files arrive through many channels: government portals, prime-contractor repositories, email attachments, engineering systems, test data, scans, and contractor-generated work product. Some are clearly marked, some are not, and some contain a mixture of CUI and ordinary business information. A reliable process therefore needs an escalation path for uncertain material instead of a rule that assumes every government-related document is CUI or that every unmarked document is safe.

A useful program treats marking as a lifecycle problem: receipt, creation, derivation, email, collaboration, printing, removable media, transmission, decontrol, and disposal. The evidence should show that employees know what to do when the marking is missing or questionable; do not assume every file arrives perfectly labeled.

Start with the authority, not the color of the banner

CUI exists because a law, regulation, or Government-wide policy requires safeguarding or dissemination controls. The CUI Registry organizes those authorities into categories and shows whether the applicable authority is treated as CUI Basic or CUI Specified. A banner may help the user recognize the information, but the legal or policy basis is what makes the information CUI.

For defense work, DFARS 252.204-7012 defines covered defense information in part by reference to the CUI Registry and by how the information is marked or otherwise identified in the contract, task order, or delivery order, or created or received in support of performance. That is why a contractor should not reduce the analysis to 'does the file say CUI at the top?' Contract identification and the nature of the information matter too.

Create a contract-level information guide that lists the expected CUI categories, source documents, customer marking instructions, approved repositories, and the person to contact when a document is ambiguous. This is much more useful to employees than giving them the entire CUI Registry and asking them to make legal classification decisions on the fly.

Understand Basic and Specified markings before copying examples

The NARA marking tables show that CUI Basic commonly uses the banner CUI, while CUI Specified categories can require a banner that includes SP and the relevant category marking. Some Basic categories may allow or use category markings depending on agency policy, while Specified categories can carry more prescriptive marking requirements because the underlying authority says so.

Do not copy a banner from another program merely because it looks familiar. The correct category and limited dissemination control depend on the authority and agency direction for the information in front of you. A contractor that invents category codes can create confusion just as easily as a contractor that strips required markings.

When contractor personnel create a new document from marked CUI, preserve the applicable marking rules for the derived material. If the customer or prime provides a program-specific marking guide, use it together with the contract and CUI Registry. When instructions conflict or the source is unclear, ask the authorized customer channel instead of quietly downgrading the document.

Treat the whole lifecycle as a marking problem

Marking does not stop at the original file. Think through screenshots, exported reports, printed pages, scanned copies, transformed spreadsheets, presentation slides, and excerpts pasted into tickets or engineering notes. If the new artifact contains CUI, the handling process needs a consistent way to identify it and keep it inside the approved environment.

For printed material, use the organization's approved CUI marking and storage procedure. NARA provides a standard CUI coversheet and media-label resources, but the exact use should follow agency and contract instructions. A cover sheet can help prevent casual viewing, but it does not change who is authorized to access the contents or where the document may be stored.

For digital media, a label is only one layer. NIST SP 800-171 Rev. 2 separately addresses protection, access, marking, transport accountability, encryption during transport, removable media controls, and sanitization. A correctly labeled USB drive that is uncontrolled or unencrypted where cryptographic protection is required is still a security problem.

Build an escalation path for unmarked or questionable information

A common contractor mistake is to create a local rule that all unmarked information is non-CUI. That is too simple for defense work because contract documents can identify covered information and contractor-generated information can inherit protection requirements based on its content and purpose. The opposite mistake—treating every nonpublic file related to a DoD contract as CUI—creates unnecessary scope and operational burden.

Give users a middle option: quarantine and ask. The procedure can tell an employee to keep the item inside the approved CUI environment, avoid forwarding or re-sharing it, record where it came from, and send a question to the contract security or program contact. The reviewer then checks the contract, data item description, security classification guidance when applicable, customer instructions, and CUI Registry authority.

Retain the answer when it will recur. If a customer confirms that a recurring report type is CUI or is not CUI, add the decision to the contract information guide with the date, source, and any marking instructions. Over time the organization builds a practical data map instead of resolving the same ambiguity repeatedly.

Handle the unmarked-file problem without guessing

If a file appears to contain information that should be controlled but arrives without a clear marking, do not create a category from memory and do not silently downgrade the information. Preserve the file, identify the source/contract or data owner, and use the organization's escalation path to confirm the applicable CUI authority and marking.

The same discipline applies to derivative work. A contractor-created spreadsheet, screenshot, drawing extract, or briefing can carry forward CUI content even though the new file did not originate with a Government banner. Train employees to ask what information the new artifact contains and what marking instruction applies.

  • Preserve the original received artifact
  • Identify the contract/data owner and source system
  • Check the CUI Registry/agency marking instruction
  • Correct or escalate the marking before wider distribution

Make email and collaboration markings consistent with handling

NARA publishes an email-marking tip among its CUI resources because email can contain CUI in the message body, attachment, or both. The organization should define how users identify those conditions, what marking belongs in the message or subject when required by the applicable instructions, and which mail systems are authorized for CUI. Marking a message does not make an unapproved mailbox acceptable.

Collaboration platforms create similar issues. A user may upload a correctly marked file into a project channel whose membership is broader than the file's authorized audience. Require users to check both the marking and the destination. Access controls, external sharing, sync clients, guest accounts, retention, and download rights are part of the handling decision.

Train users on a few real examples from the company's contracts: an engineering drawing, a customer email with a CUI attachment, a contractor-generated test report derived from CUI, and a public solicitation attachment. Concrete examples teach the difference between information status and transport method better than a slide that only shows banner syntax.

Audit the marking process without turning it into paperwork

Sample actual work products. Pick several active contracts and inspect a small set of files, emails, printed documents, and transfer records. Ask whether the marking matches the contract or customer instruction, whether the file lives in an approved repository, and whether users know what to do when the status is unclear.

Track mistakes by cause. If users repeatedly fail to mark exported reports, fix the export workflow or template. If they put CUI into an ordinary ticketing system because the approved process is cumbersome, redesign the ticket process. If they overmark everything because they are afraid to make a decision, improve the contract information guide and escalation response time.

The goal is not perfect decorative consistency. It is reliable recognition and handling of information that requires protection. A mature process makes the correct path easy, gives users a safe way to ask questions, and ties markings back to the authoritative source, not local folklore.

Sample the process from both directions during an internal review: start with a marked CUI artifact and follow where it went, then start with a collaboration workspace or removable-media record and verify that any CUI stored there is marked and handled consistently. This catches lifecycle failures that a document-only spot check misses.

WORKING CHECKLIST

A short working check

  • Map expected CUI categories and customer instructions by contract
  • Use the CUI Registry to verify category and marking authority
  • Preserve required markings on derived files and copies
  • Define email, print, media, and collaboration marking procedures
  • Quarantine and escalate unmarked or questionable material
  • Sample real work products for marking and handling consistency

Common questions

Is every unmarked DoD-related file automatically non-CUI?

No. Markings are important, but contract identification and the nature of covered defense information also matter. Use the contract and authorized customer guidance when status is unclear.

Does a CUI label make an ordinary email account acceptable for CUI?

No. Marking identifies the information; the system used to process, store, or transmit it must still meet the applicable safeguarding requirements.

Official sources used for this guide

Open the primary source before making a contract-specific decision. Regulations and program implementation can change.