Skip to main content
Category: Controlled Unclassified Information

Decontrolling

Also known as: Decontrol, CUI Decontrol
Simply put

Decontrolling is the act of ending the requirement to protect information under the Controlled Unclassified Information (CUI) program. Once information is decontrolled, authorized holders are relieved of the obligation to safeguard and handle it under CUI rules. Importantly, decontrolling is not the same as approving the information for public release, and additional review may still be required before information can be shared publicly.

Formal definition

Decontrolling refers to removing the safeguarding and dissemination controls applied to information under the CUI program, thereby relieving authorized holders of the requirement to manage and protect that information according to CUI control rules. As described in the National Archives (NARA) CUI Registry and DoD CUI guidance, decontrolling does not constitute authorization for public release; a separate public release determination process generally applies. Eligibility to decontrol, and the authority to make such a decision, is governed by program rules and may depend on factors such as who originally designated the information and applicable agency-specific guidance. Practitioners should verify current decontrol eligibility criteria and authorities against the authoritative CUI Registry and applicable DoD or agency policy, as specific procedures may vary by organization and evolve over time.

Why it matters

Decontrolling is one of the most commonly misunderstood steps in the CUI lifecycle, and the confusion carries real consequences. The central risk is treating decontrol as equivalent to a public release approval. As the NARA CUI Registry and DoD CUI guidance both make clear, decontrolling relieves authorized holders of the obligation to safeguard and handle information under CUI rules, but it does not constitute authorization for public release. Personnel who assume the two are the same can improperly disclose information that still requires a separate public release determination, exposing an organization to policy violations even when the information is technically no longer designated CUI.

Getting decontrol right also matters because the requirement to protect CUI does not persist indefinitely, and organizations that fail to decontrol appropriately can over-retain protection burdens or, conversely, apply controls inconsistently. Because eligibility to decontrol and the authority to make that decision depend on factors such as who originally designated the information and applicable agency-specific guidance, an incorrect assumption about who holds decontrol authority can lead to unauthorized removal of controls. This is why practitioners are expected to confirm both the authority and the criteria against the authoritative CUI Registry and applicable DoD or agency policy rather than relying on general practice.

For compliance officers and information system security managers, decontrol decisions are a documentation and accountability point. A decision to end CUI protection should be traceable to a proper authority and consistent with program rules, and it should not be confused with the distinct review that may still be required before information can be shared publicly.

Who it's relevant to

CUI Program Managers and Compliance Officers
These practitioners establish and enforce the rules for when and how information may be decontrolled. They must ensure decontrol decisions are made by an appropriate authority, are consistent with program rules and agency-specific guidance, and are documented. They are also responsible for making sure staff understand that decontrol does not authorize public release.
Information System Security Managers (ISSMs)
ISSMs deal with the practical effect of decontrol on how information is safeguarded within systems. When information is decontrolled, the handling and protection requirements under the CUI program no longer apply to it, which affects marking, storage, and dissemination practices that must remain aligned with current policy.
Authorized Holders and Records Personnel
Anyone handling CUI needs to understand that decontrolling relieves them of the requirement to protect the information under CUI rules, but does not permit them to release it publicly. They should confirm who holds decontrol authority for a given piece of information, since eligibility may depend on who originally designated it.
Public Affairs and Release Reviewers
Because a separate public release determination generally applies even after decontrol, personnel responsible for release decisions must treat decontrol and public release as distinct steps. Decontrolled information still requires the applicable release review process before it can be shared publicly.

Inside Decontrolling

Decontrolling Action
The formal act of removing the Controlled Unclassified Information (CUI) designation from information so that it is no longer subject to CUI safeguarding and dissemination controls. Decontrolling should be documented and traceable to an authority or condition permitting removal of the marking.
Decontrolling Authority
The role or official permitted to decontrol information. In most implementations this is generally the designating agency or an authorized official acting under agency policy; readers should verify who holds this authority for their specific information and agency, as interpretations may vary.
Triggering Conditions
The events or criteria that permit or require decontrolling, such as a predetermined date or event, expiration of a control period, a determination that the information no longer meets the CUI category criteria, or a public release decision. Specific triggers depend on the applicable category and agency policy.
Marking Updates
The process of removing or updating CUI markings, banners, and portion markings when information is decontrolled, so downstream holders can recognize that safeguarding requirements no longer apply. Handling of legacy copies and previously disseminated versions should be addressed.
Records and Traceability
Documentation that captures who decontrolled the information, under what authority, on what date, and the basis for the action, supporting auditability and consistent handling across custodians.
Relationship to Public Release
Decontrolling removes the CUI designation but is not by itself equivalent to authorization for public release; separate review or approval processes may still apply before information is publicly disclosed. Confirm the distinction against applicable agency policy.

Common questions

Answers to the questions practitioners most commonly ask about Decontrolling.

Does decontrolling CUI mean the information is now automatically releasable to the public?
No. Decontrolling removes the requirement to handle information under the CUI Program's safeguarding and dissemination controls, but it is not the same as authorizing public release. Information may be decontrolled yet still be subject to other review processes, such as a public release or Freedom of Information Act determination, before it can be disclosed. Treating decontrol as equivalent to a release authorization is a common error. Confirm the specific release requirements against your agency's policies and the governing CUI guidance.
Is decontrolling the same as declassification?
No. These are distinct processes tied to different information categories and authorities. Declassification applies to classified national security information and follows separate executive branch procedures, while decontrolling applies to Controlled Unclassified Information under the CUI Program. Conflating the two can lead to mishandling. Because the governing authorities and procedures differ, verify which regime applies to the information in question and follow the corresponding official guidance.
Who has the authority to decontrol CUI?
Authority to decontrol is generally tied to the designating agency or a designated official acting under that agency's CUI implementing policies. In most implementations, the decision rests with the originator or an authorized official rather than any holder of the information. Because specific delegation of authority varies by agency, confirm who holds decontrolling authority for a given category against your agency's CUI policy and the applicable governing guidance.
What events or conditions typically trigger decontrolling?
Decontrolling can generally be triggered by conditions such as the passage of a specified time period, the occurrence of a stated event, a decision by an authorized official, or a determination that the information no longer meets the criteria for CUI. The specific triggers depend on the applicable category and agency implementation. Review the marking and any decontrol instructions on the information, and verify the current criteria against the governing CUI guidance.
How should decontrolling be documented and reflected on markings?
In most implementations, decontrolling involves updating or removing CUI markings so holders understand the information is no longer controlled, and recording the decontrol decision consistent with agency recordkeeping practices. The precise steps for annotating documents and notifying downstream recipients are established by agency policy. Confirm the required marking and documentation procedures against your agency's CUI implementation and the applicable official guidance.
What should a holder do with information that appears eligible for decontrolling but lacks a decontrol instruction?
A holder who is not the designating authority generally should not unilaterally decontrol information. The appropriate step is typically to continue safeguarding the information and to consult the designating agency or authorized official to determine whether decontrolling is warranted. Because authority and procedures vary, verify the correct escalation path against your agency's CUI policy and the governing guidance before taking action.

Common misconceptions

Decontrolling CUI is the same as clearing information for public release.
Removing the CUI designation and authorizing public release are distinct actions. Decontrolling ends CUI safeguarding obligations, but a separate public release or disclosure review may still be required before the information can be released publicly. These should be confirmed against the governing agency policy.
Any holder of the information may decontrol it.
Decontrolling is generally limited to the designating agency or an authorized official under agency policy, not to every custodian of the information. Practitioners should verify who holds decontrolling authority for the specific information before acting.
Once information is decontrolled, all existing copies are automatically updated.
Decontrolling does not automatically re-mark or revise previously disseminated copies. Marking updates and communication to downstream holders are typically needed so that legacy copies are handled consistently.

Best practices

Confirm who holds decontrolling authority for the specific information and category before removing any CUI designation, rather than assuming any custodian may decontrol.
Document each decontrolling action, including the authority relied upon, the triggering condition, the date, and the basis, to preserve traceability and support audits.
Treat decontrolling and public release as separate determinations, and complete any required release or disclosure review before publicly disseminating decontrolled information.
Update or remove CUI markings, banners, and portion markings when decontrolling, and address how previously disseminated or legacy copies will be handled.
Communicate decontrolling decisions to affected downstream holders so safeguarding is applied or lifted consistently across all custodians.
Verify decontrolling procedures and triggering conditions against current applicable agency policy and authoritative CUI guidance, as interpretations and requirements may vary by agency and revision.