Skip to main content
Category: Controlled Unclassified Information

CUI Marking

Also known as: CUI Markings, Controlled Unclassified Information Marking
Simply put

CUI marking is the practice of labeling documents and electronic files so that people can tell the information is Controlled Unclassified Information (CUI) that needs safeguarding or limits on how it is shared. These markings signal that the information, while not classified, is still sensitive and must be protected. The purpose is to make the required handling and dissemination controls clear to anyone who receives the material.

Formal definition

CUI Marking refers to the standardized labeling of documents and electronic files containing Controlled Unclassified Information, which is unclassified information created or possessed by the U.S. Government, or by a contractor on behalf of the Government, that requires safeguarding or dissemination controls pursuant to applicable law, regulation, or Government-wide policy. Markings generally consist of designations drawn from the CUI category and banner marking structures maintained in the CUI Registry, which is associated with the National Archives and Records Administration (NARA). Specific marking conventions may vary by agency implementation, for example, DoD applies its own CUI marking guidance, and the precise category names, banner markings, and applicable authorities should be verified against the current CUI Registry and governing policy. This entry addresses the concept of marking and does not cover full safeguarding, storage, transmission, or system control requirements, which practitioners must confirm against current authoritative sources.

Why it matters

CUI marking is the mechanism that translates abstract safeguarding obligations into a signal that any recipient can act on. Because Controlled Unclassified Information is unclassified, it does not meet the criteria for classification, there is no inherent visual cue that the material is sensitive. Markings drawn from the CUI Registry structure fill that gap by telling the person holding a document or file that safeguarding or dissemination controls apply. Without consistent marking, sensitive but unclassified information can be treated as ordinary information, increasing the risk of improper storage, transmission, or release.

Marking also underpins accountability across the government and its contractors. CUI is unclassified information created or possessed by the U.S. Government, or by a contractor on behalf of the Government, that requires safeguarding or dissemination controls pursuant to applicable law, regulation, or Government-wide policy. When markings are applied correctly and consistently, downstream handlers, whether at a federal agency, a contractor facility, or a research institution, can apply the correct controls without having to independently research the underlying authority for each document.

A critical point that experts emphasize is that marking is not the same as safeguarding. Applying a banner marking signals that protection is required, but it does not by itself store, transmit, or protect the information. This entry addresses marking as a concept; the full safeguarding, storage, transmission, and system control requirements are separate obligations that practitioners must confirm against current authoritative sources. Treating a properly marked document as automatically protected is a common error.

Who it's relevant to

Government Contractors
Contractors that create or possess CUI on behalf of the Government must mark documents and electronic files so that the required safeguarding and dissemination controls are clear to anyone who receives the material. Contractors should verify the applicable category and banner markings against the current CUI Registry and any customer-specific guidance, such as DoD's own CUI marking guidance, and should not assume marking alone satisfies broader safeguarding, storage, or transmission obligations.
Compliance Officers and Information System Security Managers
Those responsible for information handling programs use CUI marking as a control point for ensuring sensitive-but-unclassified information is identified and handled correctly. They should confirm that marking practices align with the current CUI Registry structures and applicable agency implementation, and remember that marking is one element of a larger set of safeguarding requirements that must be addressed separately.
Research Institutions and Universities
Institutions handling federal information in the course of sponsored research may encounter CUI, which by definition is unclassified federal information. Documents and electronic files containing CUI must be marked according to applicable requirements. Research security and export control offices should verify the correct markings and governing authorities against current official sources, as category names and requirements may vary by agency and change over time.
Auditors and Assessors
Personnel evaluating information handling practices review whether CUI is marked consistently and in accordance with the CUI Registry and applicable agency guidance. Assessors should distinguish the presence of correct markings from the adequacy of actual safeguarding, since a properly applied marking signals that protection is required but does not demonstrate that the underlying protection controls are in place.

Inside CUI Marking

CUI Banner Marking
A marking placed at the top and bottom of each document page (or the top and bottom of a page in most implementations) that identifies the information as Controlled Unclassified Information. The banner generally indicates the overall CUI status of the document and, where applicable, the highest level of control among its contents.
CUI Category or Control Marking Designator
An indicator that identifies the specific CUI category or subcategory involved, drawn from the categories maintained in the CUI Registry (overseen by the National Archives and Records Administration Information Security Oversight Office). Categories generally fall under CUI Basic or CUI Specified, with CUI Specified reflecting a law, regulation, or government-wide policy that imposes additional handling requirements. Practitioners should verify the applicable category against the current Registry.
Designation Indicator
Information that identifies the agency or component that designated the information as CUI, commonly including the name of the designating office or point of contact. This supports traceability back to the authority responsible for the designation.
Limited Dissemination Control (LDC) Markings
Optional markings that further restrict or control dissemination of CUI (for example, controls limiting distribution) as authorized by the applicable framework. Their availability and permitted use are governed by NARA/ISOO guidance and any agency-specific implementation, which the reader should confirm.
Portion Markings (where used)
Markings applied to individual portions of a document to indicate which portions contain CUI. Portion marking of CUI is generally permitted or encouraged in certain contexts but its use may vary by agency implementation and is not universally mandated; confirm current requirements before relying on a specific practice.

Common questions

Answers to the questions practitioners most commonly ask about CUI Marking.

Does marking a document as CUI make it classified information?
No. CUI is not classified information, and marking something as CUI does not confer any level of classification. CUI is a category for unclassified information that nonetheless requires safeguarding or dissemination controls under law, regulation, or government-wide policy. Classified information under systems governed by the NISPOM follows an entirely separate marking and handling regime. Conflating the two is a common error; CUI marking indicates a handling obligation for unclassified information, not a classification determination. Confirm the specific handling requirements against the applicable authority and your agency's implementing guidance.
Is applying a CUI marking the same as actually protecting the information?
No. Marking is an indicator and handling instruction; it is not itself a safeguarding control. Correctly marking a document tells recipients how the information must be handled, but the actual protection depends on implementing the associated safeguarding and dissemination controls in the environments where the information is stored, processed, or transmitted. Treating a marking as equivalent to security is a mistake an expert would correct: marking supports compliance obligations, but protection requires the corresponding technical, physical, and administrative controls. Verify the applicable safeguarding requirements against current authoritative sources for your context.
Where on a document should CUI markings generally be placed?
In most implementations, CUI markings are applied so that recipients can readily identify the information's status and handling requirements, which generally includes a banner marking and, where applicable, portion markings and a designation indicator identifying the source of the CUI determination. The precise placement conventions are governed by the applicable CUI marking guidance rather than left to individual preference. Because agency-specific practices and the governing marking guidance may vary in detail, confirm exact placement, format, and content against the current authoritative marking guidance applicable to your organization.
Who is responsible for determining that information is CUI and applying the marking?
Responsibility for the CUI designation generally rests with the authorized holder or the entity that originates or possesses the information under an applicable law, regulation, or government-wide policy that categorizes it as CUI. The designation indicator is typically used to identify the source of the determination. Because roles and delegations differ across agencies and contractual arrangements, and because contractors may inherit marking obligations through their agreements, confirm who holds designation authority in your specific situation against current official guidance and your applicable agreements.
How should CUI be handled when it is combined or commingled with other information?
When CUI is incorporated into a larger document or dataset, the marking and handling generally must reflect the presence of the CUI, and portion-level indicators may be used where applicable to show which parts carry the CUI obligation. The overall handling requirements typically follow the most restrictive applicable controls present in the combined material. Because the treatment of commingled information can carry agency-specific interpretations, verify the correct approach against the governing marking guidance and your agency's implementing policy before disseminating.
What should be done if a document is found to be improperly marked or unmarked but contains CUI?
Improper or missing markings do not remove the underlying safeguarding obligation; information that meets the criteria for CUI generally remains subject to its handling requirements regardless of whether it was marked correctly. Organizations typically have processes for correcting markings, addressing suspected mismarking, and reporting concerns, and these processes are defined by the applicable CUI guidance and agency policy. This entry does not cover incident-reporting or remediation specifics, so confirm the required corrective and reporting steps against current authoritative sources and your organization's procedures.

Common misconceptions

CUI marking is the same as classification marking, and CUI is a level of classified information.
CUI is a distinct category of unclassified information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy. It is not classified national security information governed by the classification system used for Confidential, Secret, and Top Secret material under separate authorities. Marking something CUI does not make it classified, and classified material follows different marking rules entirely.
The legacy 'For Official Use Only' (FOUO) marking and similar older markings are interchangeable with CUI markings.
The CUI program was established to replace a patchwork of legacy control markings such as FOUO with a standardized approach under the CUI Registry. Legacy markings are not automatically equivalent to CUI markings, and mixing or substituting them can create handling ambiguity. Practitioners should apply current CUI marking guidance rather than relying on retired terminology.
Applying CUI markings by itself satisfies the security and compliance obligations for the information.
Marking identifies information and communicates handling expectations, but it does not by itself protect the information. Safeguarding CUI generally also requires implementing the associated security controls and handling practices (for example, protections associated with CUI on non-federal systems), and compliance with marking rules is not a substitute for those controls.

Best practices

Verify the applicable CUI category and any CUI Specified requirements against the current CUI Registry maintained by NARA/ISOO before applying markings, since categories and their associated handling requirements can change.
Include the required elements consistently, such as the banner marking, category designators, and a designation indicator identifying the designating office or point of contact, so recipients can trace and correctly handle the information.
Distinguish CUI markings from classified information markings and avoid mixing CUI and classified marking conventions on the same material without confirming the correct rules for each.
Retire legacy control markings such as FOUO in favor of standardized CUI markings, and establish a process to review and re-mark existing documents where required by your agency's implementation.
Confirm agency-specific implementation guidance, because portion marking, limited dissemination controls, and formatting details may vary across departments and components.
Treat marking as one part of a broader safeguarding program, pairing correct markings with the security controls and handling procedures required for the CUI involved rather than relying on markings alone.