Controlled Technical Information
Controlled Technical Information (CTI) is unclassified technical information related to military or space applications that is subject to restrictions on how it can be accessed, used, shared, copied, or displayed. Although it is not classified, it is not intended for public release and must be handled with specific safeguards. It is one of the categories of Controlled Unclassified Information (CUI).
Controlled Technical Information (CTI) is a CUI category, identified in the National Archives CUI Registry, defined as technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. CTI is unclassified scientific and technical information that is not approved for public release. As a CUI category, its handling and safeguarding obligations generally derive from the CUI program and applicable DoD requirements; readers should verify the current authoritative definitions, marking, and contractual safeguarding requirements against the CUI Registry and governing DoD sources, as this entry does not address specific implementation, marking, or contract clause requirements.
Why it matters
Controlled Technical Information sits at the intersection of intellectual property protection and national security. Because CTI is unclassified, it can circulate through contractor networks, engineering environments, and supply chains far more freely than classified material, yet its exposure can still reveal sensitive details about military or space systems. Treating CTI as low-risk simply because it is unclassified is a common and consequential error; unclassified does not mean uncontrolled. As a CUI category identified in the National Archives CUI Registry, CTI carries handling, access, and dissemination restrictions that persist regardless of its unclassified status.
For defense contractors and the broader defense industrial base, CTI is frequently the practical trigger for cybersecurity safeguarding obligations, because much of the technical data exchanged under DoD contracts falls within this category. Mishandling CTI, whether through inadequate access controls, improper reproduction, or unauthorized dissemination, can create both compliance exposure and operational risk to the systems the information describes. Readers should note that specific contractual safeguarding requirements and marking obligations derive from governing DoD sources and the CUI program rather than from the definition alone, and these should be verified against current authoritative texts.
It is also important not to conflate the existence of a CTI category with any single implementation regime. The category definition establishes what CTI is; it does not by itself specify how a given contract requires it to be marked, stored, or transmitted. Because CUI program guidance and DoD requirements evolve, organizations should confirm current obligations rather than assume that past practice or a prior contract's terms remain sufficient.
Who it's relevant to
Inside CTI
Common questions
Answers to the questions practitioners most commonly ask about CTI.