Skip to main content
Category: Laws & Executive Orders

DoD Instruction 5200.48

Also known as: DoDI 5200.48, DODI 5200.48, DoDI 5200.48 CUI, Controlled Unclassified Information (DoD Instruction)
Simply put

DoDI 5200.48 is the Department of Defense instruction that establishes how the DoD handles Controlled Unclassified Information (CUI), which is sensitive government information that is not classified but still requires protection. Issued in March 2020, it replaced earlier DoD guidance and set out DoD-specific rules for identifying, marking, safeguarding, and training personnel on CUI. It is part of a phased effort to fully put the DoD's CUI Program in place, and it indicates that additional guidance was expected to follow.

Formal definition

DoD Instruction 5200.48, 'Controlled Unclassified Information (CUI),' is DoD policy issued on 6 March 2020 that established the framework for the DoD CUI Program. According to the evidence, it cancels and replaces the prior DoD Manual 5200.01, Volume 4 ('DoD Information Security Program: Controlled Unclassified Information'), and governs DoD implementation of CUI requirements including mandatory CUI training for DoD personnel with access to CUI. The evidence characterizes DoDI 5200.48 as part of the DoD's 'phased' approach to fully implementing its CUI Program, noting that the instruction itself anticipates additional implementing guidance. Practitioners should note that DoD CUI implementation is generally addressed alongside related contractual and regulatory mechanisms (for example, DFARS provisions referenced in the evidence), which are distinct authorities from this instruction; readers should verify the current text of DoDI 5200.48 and any superseding or supplemental guidance against official DoD sources, as this entry does not cover marking specifics, safeguarding controls, or contractual obligations in detail.

Why it matters

Controlled Unclassified Information sits in a difficult middle ground: it is sensitive enough to require protection but does not carry the classification markings and handling infrastructure that come with classified material. Before a consistent DoD framework existed, sensitive-but-unclassified information was handled under a patchwork of inconsistent legacy designations, which created confusion over what needed protection and how. DoDI 5200.48, issued on 6 March 2020, matters because it establishes a single DoD-specific framework for identifying, marking, safeguarding, and training personnel on CUI, replacing prior guidance under DoD Manual 5200.01, Volume 4.

Who it's relevant to

DoD personnel with access to CUI
The evidence indicates that DoDI 5200.48 underpins the mandatory CUI training requirement for DoD personnel who access CUI. Individuals who handle sensitive-but-unclassified information in the course of their duties should treat the instruction as a governing reference for identifying, marking, and safeguarding CUI, and should confirm current training obligations against official DoD sources.
Information security and compliance staff
Personnel responsible for implementing the DoD CUI Program need to understand that DoDI 5200.48 replaced DoD Manual 5200.01, Volume 4, and that it reflects a phased implementation approach anticipating additional guidance. Because this entry does not cover marking specifics or safeguarding controls in detail, these practitioners should verify the current text and any superseding or supplemental guidance directly.
Defense contractors and researchers handling CUI
Organizations working with DoD-originated CUI should note that DoD CUI implementation is generally addressed alongside related contractual and regulatory authorities, including DFARS provisions referenced in the evidence, which are distinct from DoDI 5200.48. Contractors and research institutions should not assume the instruction alone defines their obligations and should confirm applicable contractual requirements against current official sources.

Inside DoDI 5200.48

CUI Program Establishment for DoD
DoD Instruction 5200.48 establishes policy, assigns responsibilities, and provides procedures for the identification, handling, marking, safeguarding, dissemination, decontrol, and destruction of Controlled Unclassified Information (CUI) within the Department of Defense. It implements the government-wide CUI Program (established under Executive Order 13556 and 32 CFR Part 2002, administered by the National Archives and Records Administration as the CUI Executive Agent) specifically for the DoD component.
CUI Identification and Categorization
The instruction generally addresses how DoD personnel are to determine whether information qualifies as CUI by reference to the authorized categories in the NARA CUI Registry, rather than allowing ad hoc or component-invented markings. Readers should verify specific category and marking guidance against the current NARA CUI Registry and the applicable revision of the instruction.
Marking Requirements
It provides direction on applying CUI markings, including designation indicators and category or limited dissemination control markings. The precise marking formats and required elements should be confirmed against current DoD marking guidance and the CUI Registry, as details can be tailored or updated across revisions.
Safeguarding and Handling
The instruction generally sets expectations for protecting CUI at rest, in transit, and during processing. For CUI residing in or transiting non-federal information systems, protection obligations are frequently tied to NIST SP 800-171 through contractual mechanisms; the instruction itself should not be conflated with those separate NIST publications or with the DFARS clauses that impose contractor requirements.
Roles and Responsibilities
It assigns responsibilities across DoD organizational elements for implementing and overseeing the CUI Program. Specific office assignments should be verified against the current text, as responsibilities may be reassigned in subsequent revisions.
Dissemination Controls, Decontrol, and Destruction
The instruction addresses limited dissemination controls, procedures for decontrolling information that no longer requires CUI protection, and requirements for the destruction of CUI. Exact procedures should be confirmed against the applicable revision and any supplementing DoD guidance.

Common questions

Answers to the questions practitioners most commonly ask about DoDI 5200.48.

Does DoDI 5200.48 create a new category of protected information separate from CUI?
No. DoDI 5200.48 establishes DoD policy and responsibilities for identifying, marking, safeguarding, and disseminating Controlled Unclassified Information; it does not create a category distinct from CUI. It implements the broader CUI framework within the Department of Defense rather than replacing it. Readers should verify the current text of the instruction and related DoD and National Archives CUI Registry guidance, as terminology and program details may be updated across revisions.
Does complying with DoDI 5200.48 by itself mean a system is secure or fully authorized to operate?
No. DoDI 5200.48 addresses policy for handling CUI within DoD; it is not a substitute for the technical safeguarding, assessment, and authorization processes carried out under separate authorities. Compliance with marking and handling policy does not equate to security, nor does it constitute an Authority to Operate, which is time-bound and subject to continuous monitoring under the applicable authorization process. Confirm how the instruction interacts with your system's security and authorization requirements against current official sources.
Who within a DoD component is generally responsible for determining that information is CUI under DoDI 5200.48?
The instruction generally assigns responsibility for identifying and designating CUI to authorized personnel acting within the roles the policy defines, rather than leaving designation to any individual holder of the information. Because specific role assignments and delegations can vary by component and may change across revisions, confirm the current responsibilities and your component's implementing guidance before relying on a particular assignment.
How does DoDI 5200.48 address marking of CUI?
The instruction generally directs that CUI be marked in accordance with the DoD CUI program and the broader CUI framework so that recipients can readily identify handling requirements. It focuses on policy for consistent identification and marking rather than prescribing every technical or document-formatting detail. Consult the current instruction text and associated marking guidance, including the National Archives CUI Registry, for the applicable marking conventions, which may be updated over time.
Does DoDI 5200.48 apply to contractors handling DoD CUI?
The instruction sets DoD policy for handling CUI, and its requirements can extend to non-DoD entities, including contractors, through contractual and other mechanisms rather than by the instruction alone. Contractor obligations are typically imposed through applicable contract clauses and related requirements, which are governed by separate authorities. Verify the specific contractual flow-down and safeguarding obligations that apply to your situation against current official sources, as these are outside the scope of the instruction's internal policy statements.
How should personnel handle disseminating CUI under DoDI 5200.48?
The instruction generally establishes policy for controlling dissemination of CUI consistent with the broader CUI framework, including the use of applicable dissemination controls and limitations. It addresses policy and responsibilities rather than every operational procedure. Confirm the specific dissemination controls, limited dissemination markings, and any component-specific interpretations against the current instruction and the National Archives CUI Registry, as these details may vary and evolve.

Common misconceptions

DoDI 5200.48 is the same thing as NIST SP 800-171, so complying with one satisfies the other.
DoDI 5200.48 is a DoD policy instruction that establishes the CUI Program within the Department, while NIST SP 800-171 is a separate NIST publication providing security requirements for protecting CUI in nonfederal systems. They are distinct authorities issued by different bodies; the instruction may reference safeguarding expectations, but it does not replace the NIST control requirements or the contractual mechanisms (such as DFARS clauses) that impose them.
CUI is a classification level, and marking something CUI works like marking it Confidential or Secret.
CUI is not classified national security information governed by classification authorities; it is unclassified information that laws, regulations, or government-wide policies require to be protected or disseminated with controls. The CUI Program and its markings operate under a separate framework (EO 13556, 32 CFR Part 2002, and the NARA CUI Registry) rather than under classification rules.
DoD components can create their own CUI categories and markings as needed.
CUI categories are drawn from the authorized categories maintained in the NARA CUI Registry as the government-wide reference, not invented locally. DoD implementation through the instruction is intended to standardize handling against that registry rather than permit component-specific improvised markings.

Best practices

Verify CUI category determinations and marking formats against the current NARA CUI Registry and the applicable revision of DoDI 5200.48 rather than relying on legacy markings such as 'FOUO' or on informal local conventions.
Keep DoDI 5200.48 obligations conceptually separate from NIST SP 800-171 safeguarding requirements and from DFARS contractual clauses, and confirm which authority actually governs a given system or contract before asserting compliance.
Consult the current version of the instruction directly, because responsibilities, procedures, and marking details can change across revisions and may be supplemented by additional DoD guidance.
Establish and document decontrol and destruction procedures for CUI so that protection is removed or applied appropriately as information changes status, rather than leaving markings in place indefinitely.
Coordinate with the responsible DoD oversight office and legal or contracting personnel when handling CUI that will reside on or transit nonfederal or contractor systems, since additional protection and flow-down obligations typically apply through separate mechanisms.
Train personnel to distinguish CUI handling from classified information handling, reinforcing that CUI is unclassified but controlled and follows the government-wide CUI framework rather than classification rules.