Decontrolling
Decontrolling is the act of ending the requirement to protect information under the Controlled Unclassified Information (CUI) program. Once information is decontrolled, authorized holders are relieved of the obligation to safeguard and handle it under CUI rules. Importantly, decontrolling is not the same as approving the information for public release, and additional review may still be required before information can be shared publicly.
Decontrolling refers to removing the safeguarding and dissemination controls applied to information under the CUI program, thereby relieving authorized holders of the requirement to manage and protect that information according to CUI control rules. As described in the National Archives (NARA) CUI Registry and DoD CUI guidance, decontrolling does not constitute authorization for public release; a separate public release determination process generally applies. Eligibility to decontrol, and the authority to make such a decision, is governed by program rules and may depend on factors such as who originally designated the information and applicable agency-specific guidance. Practitioners should verify current decontrol eligibility criteria and authorities against the authoritative CUI Registry and applicable DoD or agency policy, as specific procedures may vary by organization and evolve over time.
Why it matters
Decontrolling is one of the most commonly misunderstood steps in the CUI lifecycle, and the confusion carries real consequences. The central risk is treating decontrol as equivalent to a public release approval. As the NARA CUI Registry and DoD CUI guidance both make clear, decontrolling relieves authorized holders of the obligation to safeguard and handle information under CUI rules, but it does not constitute authorization for public release. Personnel who assume the two are the same can improperly disclose information that still requires a separate public release determination, exposing an organization to policy violations even when the information is technically no longer designated CUI.
Getting decontrol right also matters because the requirement to protect CUI does not persist indefinitely, and organizations that fail to decontrol appropriately can over-retain protection burdens or, conversely, apply controls inconsistently. Because eligibility to decontrol and the authority to make that decision depend on factors such as who originally designated the information and applicable agency-specific guidance, an incorrect assumption about who holds decontrol authority can lead to unauthorized removal of controls. This is why practitioners are expected to confirm both the authority and the criteria against the authoritative CUI Registry and applicable DoD or agency policy rather than relying on general practice.
For compliance officers and information system security managers, decontrol decisions are a documentation and accountability point. A decision to end CUI protection should be traceable to a proper authority and consistent with program rules, and it should not be confused with the distinct review that may still be required before information can be shared publicly.
Who it's relevant to
Inside Decontrolling
Common questions
Answers to the questions practitioners most commonly ask about Decontrolling.