CUI Handling Requirements: The 5 Things Defense Manufacturers Miss
A practical guide for defense manufacturers and services firms: what Controlled Unclassified Information (CUI) actually is, the five handling requirements your program has to meet, and the specific places contractors get caught short at C3PAO assessment.
The 50-Word Answer
CUI handling requires five disciplines: marking (preserve and apply government markings), access control (least privilege, MFA, audit), transmission (encrypted channels, FedRAMP Moderate equivalency), storage (compliant endpoints, encrypted at rest, segmented networks), and destruction (NIST 800-88 sanitization with documented certificates of destruction). Defense manufacturers most commonly miss transmission and destruction.
What Is Controlled Unclassified Information?
Controlled Unclassified Information (CUI) is a federal designation for sensitive unclassified information that the government requires contractors to safeguard under law, regulation, or government-wide policy. It was created by Executive Order 13556 in 2010 and codified in 32 CFR Part 2002 to replace the unmanaged patchwork of prior markings — For Official Use Only (FOUO), Sensitive But Unclassified (SBU), Limited Distribution (LIMDIS), and similar legacy categories. CUI is what those markings became.
For defense manufacturers, CUI is the operational trigger for CMMC Level 2. The presence of DFARS 252.204-7012 in a contract means the contract might involve CUI. The presence of CUI markings on technical data packages, drawings, or correspondence means the contract definitely involves CUI. And CUI handling means 110 NIST SP 800-171 controls, a C3PAO assessment every three years, and a compliance program that costs six figures to stand up.
The CUI designation is authoritative, not advisory. Failing to handle CUI properly is a contractual breach, potentially a False Claims Act issue if the contractor affirmed compliance, and often a statutory violation under ITAR or the Export Administration Regulations when the underlying information is export-controlled. This is not a marketing category. It is a legally enforceable handling regime.
The 15 CUI Categories You Might Encounter
The official CUI Registry at archives.gov/cui lists 125 CUI categories across 20 groupings. The vast majority of defense manufacturers encounter a narrow subset — fewer than 15 in any realistic scenario. Knowing which categories apply to your contracts is the first step in scoping your handling program. The table below lists the most common categories seen in U.S. defense manufacturing, with examples and typical marking strings.
| CUI Category | Common Marking | Typical Source |
|---|---|---|
| Controlled Technical Information | CUI//CTI | DoD technical drawings, specs, TDPs |
| Export Controlled | CUI//SP-EXPT | ITAR / EAR technical data |
| Proprietary Business Information | CUI//SP-PROP | Vendor proposals, cost data |
| Procurement & Acquisition | CUI//PROC | Source-selection, bids, evaluations |
| Privacy / PII | CUI//PRVCY | Employee SSNs, clearance info |
| Financial | CUI//SP-FIN | Contract financials, invoices |
| Critical Infrastructure Security Information | CUI//CRIT | Plant security plans |
| International Agreements | CUI//SP-IAG | Foreign partner technical data |
| Law Enforcement Sensitive | CUI//SP-LES | Background investigation data |
| Defense – NNPI | CUI//SP-NNPI | Naval nuclear propulsion information |
| Patent Application Information | CUI//SP-PAT | Pre-publication patent work |
| Personnel Security | CUI//SP-PERS | Security clearance investigations |
| Source Selection Information | CUI//SP-SSEL | Government evaluation criteria |
| Statistical Information | CUI//SP-STAT | Protected survey data |
| Unclassified Controlled Nuclear Information | CUI//SP-UCNI | Nuclear-related technical data |
Most common CUI categories in U.S. defense manufacturing. Specified (SP) categories carry additional statutory protections.
Marking
CUI markings are the visible mechanism by which the government communicates the handling regime. A document marked CUI must be handled as CUI from the moment it enters your environment to the moment it is destroyed. There is no gray area on marking preservation.
Three rules govern contractor marking behavior. First, preserve markings on received documents. If the government originator marked a technical data package CUI//SP-EXPT, that marking stays on every copy, every derivative document, and every handoff to subcontractors. Stripping markings is a contractual breach.
Second, apply markings to derivative documents. If you produce a drawing derived from a CUI source document, the derivative document carries the same CUI designation. If you produce an email summary of a CUI technical exchange, the email carries CUI markings. If you create a project management record referencing CUI content, that record carries markings. Derivatives inherit marking obligations.
Third, do not originate CUI markings. Only the government originator can designate information as CUI. If you receive unmarked information that appears sensitive, contact the government customer for a marking determination. Self-designating as CUI is incorrect — and creates enforcement exposure when documents lack the government authority to support the marking.
Physical marking placement: top and bottom of each page, classification banner, portion markings for mixed-sensitivity documents. Digital marking: document metadata, filename convention, header/footer insertion, email subject-line prefix. Automated tooling like Microsoft Information Protection (MIP) or Microsoft 365 sensitivity labels is the modern answer for digital marking at scale.
Access Control
Access to CUI is restricted to personnel with a lawful government purpose and a demonstrated need-to-know. This is the strict reading of 32 CFR 2002 and the operational reality of NIST 800-171 controls 3.1.1 through 3.1.22. It is the single area where defense manufacturers most frequently over-authorize.
Three access principles drive the implementation. Need-to-know. Only personnel whose assigned tasks require CUI access should have it. Not project team members generally; only the specific engineers, buyers, or managers whose work directly touches the CUI-containing deliverable. Least privilege, enforced through role-based access control.
Authentication. Access requires multi-factor authentication for all CUI-handling systems. Single-factor passwords are insufficient. MFA is not optional for CUI environments — this is control 3.5.3 and it is weighted heavily in SPRS scoring precisely because the government considers it foundational.
Audit. Every access event to CUI-handling systems must be logged, retained, and reviewed. Failed access attempts, privileged access use, after-hours access, access from unusual locations. These logs feed a SIEM or managed SOC. Without audit trails, access control is unverifiable, and unverifiable controls fail assessment.
The practical implementation for a defense manufacturer is a CUI enclave with dedicated Active Directory groups, conditional access policies enforcing MFA, centralized audit logging to a SIEM, and quarterly access reviews by the data owner. Bring-Your-Own-Device is incompatible with this model in practical terms — expect to provide managed endpoints to any CUI-touching employee.
Transmission (Email, File Transfer)
CUI transmission — email, file transfer, APIs, chat, video conferencing — requires encrypted channels that meet FedRAMP Moderate equivalency. This requirement catches defense manufacturers more than any other handling requirement because the default Microsoft 365 commercial tenant does not meet it.
Commercial Microsoft 365, Gmail, and standard corporate email do not meet CUI transmission requirements. The authorized paths are Microsoft 365 GCC High with Office 365 Message Encryption, CMMC-assessed email gateways like Virtru for Defense, and DoD-approved tenants on cloud service providers with FedRAMP Moderate authorization. Migrating a manufacturer from Microsoft 365 Commercial to GCC High is a 60-to-120-day project that typically costs $35K to $85K in labor plus $18–$22/user/month incremental licensing. Plan it before the CUI flows, not after.
File Transfer
For larger files and direct government-to-contractor transfers, DoD SAFE (safe.apps.mil) is the authorized mechanism for unclassified and CUI file exchange. For contractor-to-subcontractor CUI transfers, the options are SFTP with FIPS 140-2 validated cryptography, Microsoft 365 GCC High SharePoint with proper labeling, or specialized file-transfer services with documented FedRAMP Moderate status. Dropbox, Box.com, standard OneDrive, and similar consumer-grade services do not qualify. Neither does FTP, HTTP, or unencrypted email attachments.
Chat and Collaboration
Microsoft Teams on GCC High is authorized; Teams on Commercial is not. Slack is generally not authorized for CUI unless on the Slack Enterprise Grid with GovCloud configuration. Zoom must be on Zoom for Government, not Zoom Commercial. Signal, WhatsApp, Discord, and similar consumer applications are flatly not authorized for CUI discussion regardless of end-to-end encryption — encryption is necessary but not sufficient; FedRAMP Moderate equivalency is the bar.
Transmission Markings
Emails containing CUI carry a prefix in the subject line: [CUI] or [CUI//SP-PROP]. Email body begins with a banner indicating CUI content. Attached files carry their own markings in headers, footers, and metadata. These markings are mechanical and should be automated via Data Loss Prevention (DLP) rules and sensitivity labels. Manual marking scales poorly and produces inconsistent results at scale.
Storage (Physical + Digital)
CUI at rest must be protected through physical access controls, logical access controls, and cryptographic protection — with each layer documented, tested, and maintained.
Digital Storage
CUI stored digitally must be on systems that meet NIST 800-171 controls. Organization-owned endpoints with endpoint detection and response, full-disk encryption with FIPS 140-2 validated cryptography, centralized audit logging, and enforced configuration baselines. Cloud storage is permissible if the cloud service has FedRAMP Moderate authorization — Microsoft 365 GCC High, Azure Government, AWS GovCloud, and similar authorized environments. Commercial cloud tenants without FedRAMP Moderate equivalency do not meet the requirement, full stop.
Physical Storage
Paper CUI, removable media carrying CUI, and CUI-containing hardware must be stored in controlled physical areas. The control family (NIST 800-171 3.10) requires limited physical access, physical access logs, escort of visitors in CUI areas, and sanitization of media before reuse outside the CUI scope. Most defense manufacturers handle this by restricting CUI work to a designated building zone with card-reader access, visitor logs, and no-unescorted-access policies. The CITADEL portfolio at Armorstack is organized specifically around integrating physical access control with logical access control for this purpose.
Encryption at Rest
All CUI-containing storage — laptops, servers, backup tapes, removable drives, cloud storage — must be encrypted at rest using FIPS 140-2 Validated cryptography (currently Level 1 acceptable for most CUI scenarios, Level 2 or 3 for elevated sensitivity). BitLocker with appropriate configuration, native Azure Storage Service Encryption, AWS KMS with FedRAMP Moderate scope, and hardware security modules are acceptable. Consumer-grade encryption products that are not FIPS-validated are not acceptable regardless of algorithm strength.
Backup Storage
CUI backups inherit the same storage requirements as primary CUI. Backup media stored off-site must remain within CUI-authorized environments — which usually means FedRAMP Moderate cloud backup rather than commercial cloud backup. Tape rotation to an off-site vendor requires the vendor to be authorized and the tapes encrypted with validated cryptography. Most defense manufacturers under-engineer this area, creating gaps auditors identify quickly.
Destruction
When CUI is no longer needed, it must be destroyed through a process that prevents reconstruction. NIST Special Publication 800-88 Rev 1 (“Guidelines for Media Sanitization”) defines the authoritative standards and is referenced directly by NIST 800-171 control 3.8.3.
Paper and Printed Media
Paper CUI must be destroyed by cross-cut shredding to maximum particle size of 1mm x 5mm. Strip-cut shredders do not meet the requirement. Outsourced shredding services must provide certificates of destruction; mobile shredding trucks with witnessed destruction are preferred over pick-up-and-ship models because they eliminate the transportation risk window.
Digital Media: Clearing, Purging, Destroying
NIST 800-88 defines three sanitization levels. Clearing — logical wiping that prevents casual recovery (acceptable for reuse within the CUI boundary). Purging — cryptographic erase or advanced wiping preventing recovery with laboratory forensics (acceptable for media leaving the CUI boundary). Destroying — physical destruction making the media unusable and unreadable (required for end-of-life disposal of media that held high-sensitivity CUI).
The delete key, the recycle bin, standard format commands, and “quick erase” do not meet any of the three standards. Authorized tools include DBAN (for HDDs), manufacturer-provided secure erase utilities for SSDs, and NSA-evaluated degaussers for magnetic media. For end-of-life destruction, certified destruction vendors with NAID AAA Certification or equivalent are the operational standard.
Certificates of Destruction
Every CUI destruction event must be documented with a certificate capturing: date, method, operator, witness, serial numbers (for devices), pounds or volume (for paper), and the CUI category destroyed. These certificates are retained as audit evidence for the life of the CUI designation plus at least three years. Most defense manufacturers produce these inconsistently — which surfaces quickly in a C3PAO assessment.
Where Defense Manufacturers Get This Wrong
Five patterns show up repeatedly in defense manufacturing assessments nationwide. Each one is avoidable; each one is expensive when missed.
1. Email transmission on commercial Microsoft 365. The single most common failure. A manufacturer receives a CUI drawing from a prime contractor, and it arrives in a commercial M365 mailbox. Now the drawing lives in an environment that does not meet FedRAMP Moderate. Remediation requires GCC High migration, which costs time and money that was not in the original CMMC budget. Migrate before CUI arrives.
2. Shop-floor terminals with CUI exposure. Manufacturing-floor workstations running CAM software, CNC programming, or quality systems frequently pull from engineering drawings that are CUI. These terminals often run older Windows versions, lack EDR, and operate on flat networks with no CUI segmentation. They become the silent scope expansion nobody planned for. Survey the shop floor explicitly.
3. Outsourced IT without CUI awareness. Traditional MSPs serving defense manufacturers often lack CUI handling expertise. They rebuild a failed workstation by imaging from a standard template and shipping it back — without confirming whether the workstation held CUI and whether sanitization was required. This creates CUI spillage events. If your IT provider has never been through a C3PAO assessment themselves, they are a compliance risk.
4. Physical destruction of hardware without certificates. An end-of-life CUI-handling laptop goes to the IT closet, then to a drop-off recycler, then to a shredder. No certificate at any step. At assessment, the auditor asks for the chain of custody and finds none. The control fails. Every device destruction needs documented chain-of-custody from end-user through final destruction.
5. Supplier flow-down gaps. Defense manufacturers who are primes or higher-tier subs often flow down CUI to their own machine shops, coating houses, and service providers — without enforcing DFARS 252.204-7012 or CMMC on those vendors. When the downstream vendor has a breach, the prime's CMMC program is implicated. Supplier management is as important as internal controls.
CUI Requirements + CMMC Level 2 Controls
The five CUI handling requirements map directly to specific NIST 800-171 control families that are tested during a CMMC Level 2 C3PAO assessment. The table below shows the authoritative mapping so a compliance program can align implementation evidence with assessment expectations.
| CUI Requirement | Primary NIST 800-171 Controls | SPRS Weight |
|---|---|---|
| Marking | 3.8.4, 3.1.3, 3.12.3 | Light (documentation) |
| Access Control | 3.1.1–3.1.22, 3.5.1–3.5.11 | Heavy (42 points) |
| Transmission | 3.1.13, 3.13.8, 3.13.11, 3.13.15, 3.13.16 | Heavy (11 points) |
| Storage | 3.8.1–3.8.9, 3.13.16, 3.10.1–3.10.6 | Heavy (21 points) |
| Destruction | 3.8.3, 3.8.7 | Medium (3 points) |
CUI handling requirements to NIST 800-171 / CMMC Level 2 control mapping. The Access Control + Storage combination accounts for over half of total SPRS-weighted controls.
CUI Handling Requirements: Q&A
What is the difference between CUI and FCI?
Federal Contract Information (FCI) is transactional information developed for the government that is not intended for public release. Controlled Unclassified Information (CUI) is a specific category of sensitive unclassified information the government requires safeguarding under law, regulation, or executive order. CUI is a subset of FCI by sensitivity: all CUI is FCI; not all FCI is CUI. CMMC Level 2 is triggered by CUI handling, not FCI handling.
Who is authorized to mark documents as CUI?
Only the government originator — the federal agency that generated the information — can mark a document as CUI. Contractors are required to preserve CUI markings and apply them to derivative documents that contain CUI, but contractors cannot originate new CUI markings. If you receive unmarked information that appears sensitive, contact the government customer for a marking determination before proceeding.
Can CUI be stored on a personal laptop?
No. CUI must be stored on systems that meet NIST 800-171 controls — which a personal laptop by definition does not. CUI storage requires organization-owned endpoints with endpoint detection and response, encryption, configuration management, and access control. Bring-Your-Own-Device (BYOD) is effectively incompatible with CUI handling in any practical implementation.
What is the correct way to email a document containing CUI?
Use a government-authorized encrypted channel: Microsoft 365 GCC High with message encryption, a CMMC-assessed email gateway, or a DoD-approved file-transfer service like DoD SAFE. Commercial Gmail, personal Outlook.com, and standard Microsoft 365 commercial tenants do not meet the FedRAMP Moderate equivalency required for CUI transmission. Build the channel before the need arises.
How should CUI be destroyed?
For physical media: cross-cut shredding to 1mm x 5mm particle size or smaller. For digital media: NIST 800-88 Rev 1 clearing or purging, with documented certificates of destruction. Do not use delete keys, format commands, or recycle bins — they do not sanitize the underlying media. Destruction must be documented and retained as evidence for audit purposes.
What are the 15 CUI categories a defense manufacturer is most likely to see?
The most common CUI categories in U.S. defense manufacturing are Controlled Technical Information (CTI), Export Controlled (EXPT, often ITAR/EAR-driven), Proprietary Business Information (PROP), Procurement and Acquisition (PROC), and Privacy-related categories (PRVCY, PII). The DoD-maintained CUI Registry at archives.gov/cui lists all 125 CUI categories — only a handful typically apply to any given manufacturer.