Skip to main content
Category: Controlled Unclassified Information

Controlled Technical Information

Also known as: CTI, Controlled Technical Information (CUI Category)
Simply put

Controlled Technical Information (CTI) is unclassified technical information related to military or space applications that is subject to restrictions on how it can be accessed, used, shared, copied, or displayed. Although it is not classified, it is not intended for public release and must be handled with specific safeguards. It is one of the categories of Controlled Unclassified Information (CUI).

Formal definition

Controlled Technical Information (CTI) is a CUI category, identified in the National Archives CUI Registry, defined as technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. CTI is unclassified scientific and technical information that is not approved for public release. As a CUI category, its handling and safeguarding obligations generally derive from the CUI program and applicable DoD requirements; readers should verify the current authoritative definitions, marking, and contractual safeguarding requirements against the CUI Registry and governing DoD sources, as this entry does not address specific implementation, marking, or contract clause requirements.

Why it matters

Controlled Technical Information sits at the intersection of intellectual property protection and national security. Because CTI is unclassified, it can circulate through contractor networks, engineering environments, and supply chains far more freely than classified material, yet its exposure can still reveal sensitive details about military or space systems. Treating CTI as low-risk simply because it is unclassified is a common and consequential error; unclassified does not mean uncontrolled. As a CUI category identified in the National Archives CUI Registry, CTI carries handling, access, and dissemination restrictions that persist regardless of its unclassified status.

For defense contractors and the broader defense industrial base, CTI is frequently the practical trigger for cybersecurity safeguarding obligations, because much of the technical data exchanged under DoD contracts falls within this category. Mishandling CTI, whether through inadequate access controls, improper reproduction, or unauthorized dissemination, can create both compliance exposure and operational risk to the systems the information describes. Readers should note that specific contractual safeguarding requirements and marking obligations derive from governing DoD sources and the CUI program rather than from the definition alone, and these should be verified against current authoritative texts.

It is also important not to conflate the existence of a CTI category with any single implementation regime. The category definition establishes what CTI is; it does not by itself specify how a given contract requires it to be marked, stored, or transmitted. Because CUI program guidance and DoD requirements evolve, organizations should confirm current obligations rather than assume that past practice or a prior contract's terms remain sufficient.

Who it's relevant to

Defense contractors and the defense industrial base
Organizations that receive, generate, or exchange technical data under DoD contracts are most likely to encounter CTI, since much military and space technical information falls within this category. They should confirm how each contract requires CTI to be identified, marked, and safeguarded, and should not assume that unclassified status reduces their handling obligations.
Information system security managers and compliance officers
Personnel responsible for protecting CUI must ensure that systems processing CTI apply the appropriate access, reproduction, and dissemination controls. Because CTI's safeguarding obligations derive from the CUI program and DoD requirements, these teams should verify current authoritative definitions and requirements rather than rely on static internal policy.
Engineering, research, and technical data custodians
Engineers and researchers who produce or handle scientific and technical information with military or space application are often the practical point where CTI is created or received. They need to recognize when information qualifies as CTI so that it is designated and controlled appropriately rather than treated as freely shareable technical material.
Auditors and assessors
Those evaluating an organization's handling of CUI should confirm that CTI is being identified and controlled consistent with the CUI Registry definition and applicable DoD requirements. Assessors should verify marking and safeguarding practices against current authoritative sources, as category guidance and DoD requirements can change across revisions.

Inside CTI

Technical Information Focus
CTI refers to technical information with military or space application that is subject to controls on access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. It is a subset of Controlled Unclassified Information (CUI) rather than a separate, standalone category.
Association with DFARS Safeguarding Requirements
CTI is a term closely associated with DoD contracting and appears in the context of DFARS safeguarding requirements. Practitioners generally encounter it alongside the DFARS clause governing safeguarding of covered defense information and cyber incident reporting; readers should verify the current clause text and its exact scope against authoritative sources.
Technical Data and Computer Software Character
CTI generally encompasses technical data and computer software as those concepts are used in defense acquisition, meaning information of a scientific or technical nature. The precise definitional boundaries are set by the governing DoD regulations and should be confirmed against the applicable revision.
Marking and Dissemination Controls
As controlled information, CTI is subject to distribution and dissemination limitations. Determining applicable markings and handling generally depends on the specific distribution statement and the controlling DoD office, which the reader must confirm.

Common questions

Answers to the questions practitioners most commonly ask about CTI.

Is Controlled Technical Information (CTI) the same thing as CUI?
Not exactly. CTI is generally treated as a category or subset of technical information within the broader Controlled Unclassified Information (CUI) framework rather than a synonym for CUI as a whole. CTI specifically refers to technical information with military or space application that is subject to controls on access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. CUI is the wider umbrella of information that laws, regulations, or government-wide policies require to be safeguarded. Treating the two as interchangeable can lead to misclassification, so you should confirm the specific marking and category against current authoritative sources and the applicable contract.
Does the fact that information is technical automatically make it CTI?
No. Technical content alone does not make information CTI. To be CTI, technical information must be subject to specific controls on its access and dissemination, and it is generally tied to military or space application. Technical information that is publicly available or not otherwise subject to controls would generally fall outside the CTI designation. Because designation depends on the governing controls and the terms of the applicable contract, you should verify how the information is marked and identified rather than assuming any technical document qualifies.
How do I know whether information on a given program qualifies as CTI?
Determination generally depends on how the information is designated and marked, and on the requirements flowed down through the applicable contract. Rather than making an independent judgment based on the technical nature of the content, review the contract terms, any distribution statements or markings applied to the information, and guidance from the contracting authority. When the designation is unclear, confirm with the responsible government point of contact and against current official sources.
What should I do if I receive information I believe may be CTI but it is not marked?
Unmarked or ambiguously marked information does not remove any underlying safeguarding obligations, but the appropriate handling depends on the governing controls and contract terms. As a practical step, treat the information cautiously, avoid unnecessary dissemination, and seek clarification from the contracting authority or responsible government point of contact regarding its proper designation and handling. Verify the correct treatment against the applicable contract and current authoritative sources before acting.
How does CTI relate to the safeguarding obligations under my contract?
Safeguarding obligations for CTI are generally established through contract terms rather than through the term itself. The specific protection, dissemination, and handling requirements flow from the applicable contract clauses and any associated markings or distribution statements. Because contractual requirements and their scope can vary, review your specific contract language and confirm the current obligations against official sources rather than assuming a uniform standard applies across all agreements.
Where should I confirm the current, authoritative definition and handling requirements for CTI?
You should anchor your understanding to the governing regulation and any markings, distribution statements, or clauses applied to the information, and confirm the current text against official sources. Because designations depend on contract-specific flow-downs and can be interpreted in agency-specific ways, verify the definition, marking, and handling expectations with the responsible government point of contact and the applicable contract rather than relying on a general summary.

Common misconceptions

CTI is a wholly separate category from CUI with its own independent handling regime.
CTI is generally treated as a subset of Controlled Unclassified Information rather than an entirely distinct category. It carries CUI handling expectations while reflecting its specific technical and military or space application character; readers should confirm the categorization under current authoritative guidance.
CTI is classified information.
CTI is controlled but unclassified. It is subject to access and dissemination controls, but it is not handled under classified information rules such as those governing national security systems. Classified material follows separate authorities that are out of scope for this term.
Meeting DFARS safeguarding requirements for CTI is equivalent to being fully secure or fully compliant across all frameworks.
Safeguarding CTI under applicable DFARS requirements addresses specific contractual obligations, but compliance is not the same as security, and it does not automatically satisfy other frameworks or authorizations. Practitioners should verify which requirements, revisions, and clauses apply to their specific contracts.

Best practices

Verify whether information in scope actually meets the CTI definition and its association with covered defense information under the current governing DoD regulation, rather than assuming a broad or informal interpretation.
Confirm the applicable DFARS safeguarding and cyber incident reporting requirements and their current clause text against authoritative sources, because clause references and requirements change across revisions.
Treat CTI as a subset of CUI and apply the corresponding handling, marking, and dissemination controls, confirming the correct distribution statement with the controlling DoD office.
Coordinate with the appropriate contracting and program authorities to identify the specific distribution and dissemination limitations that attach to a given item of CTI before release or sharing.
Document how CTI is identified, marked, and protected within your environment so that safeguarding obligations can be demonstrated during assessment, while recognizing that compliance activities are distinct from overall security posture.
Do not assume that satisfying one framework or authorization covers CTI safeguarding obligations; verify the specific contractual and regulatory requirements applicable to each engagement.