Limited Dissemination Controls
Limited Dissemination Controls (LDCs) are optional markings that a government agency can add to Controlled Unclassified Information (CUI) to restrict who may receive it, even among people who otherwise have a lawful government reason to access it. When no LDC is applied, anyone with an authorized lawful government purpose is generally permitted access to the information. LDCs narrow that access to a specific audience.
Limited Dissemination Controls (LDCs) are CUI Executive Agent-approved controls that agencies may apply to further limit or specify the dissemination of CUI beyond the baseline requirement that it be shared only for a lawful government purpose. As described in the CUI Registry maintained by the National Archives and Records Administration (NARA) as the CUI Executive Agent, and reflected in DoD CUI guidance, LDCs identify the specific audience deemed to have an authorized lawful government purpose to be authorized holders of the marked information. The absence of an LDC generally means that any person with an authorized lawful government purpose may access the information. LDC markings constitute one class of CUI markings, distinct from category markings; they should not be conflated with the CUI Basic and CUI Specified designations, which classify the safeguarding/dissemination control level of the CUI rather than the type of marking. Practitioners should note that applying an LDC does not itself authorize decontrol or public release; per the governing CUI regulatory framework (32 CFR Part 2002), only the designating agency, or personnel it specifically delegates, may decontrol CUI and authorize its public release. Readers should verify the current list of approved LDCs and applicable requirements against the official CUI Registry and current agency guidance, as the set of approved controls and their descriptions may be revised.
Why it matters
Limited Dissemination Controls address a gap that the baseline CUI framework leaves open. Without an LDC, Controlled Unclassified Information is generally accessible to anyone who has an authorized lawful government purpose, which can be a broad population across agencies, contractors, and mission partners. LDCs give the designating agency a mechanism to narrow that audience to the specific holders it determines actually need the information, providing a finer level of control than the lawful-government-purpose standard alone. For compliance officers and information system security managers, this means access decisions cannot rely solely on whether a recipient has a general lawful purpose; the presence of an LDC marking changes who counts as an authorized holder.
Getting LDCs right also matters because they are frequently misunderstood in ways that create real compliance exposure. A common and consequential error is assuming that applying or removing an LDC is equivalent to authorizing decontrol or public release. It is not. Under the governing CUI regulatory framework (32 CFR Part 2002), only the designating agency, or personnel it specifically delegates, may decontrol CUI and authorize its public release. Treating LDC decisions as release decisions can lead to improper disclosure of information that remains controlled.
Because LDCs are one of the classes of CUI markings maintained through the CUI Registry, errors in applying them can propagate through document marking, distribution, and downstream handling. Practitioners should treat the CUI Registry and current agency guidance as the authoritative source for which LDCs are approved and how they are applied, since the set of approved controls and their descriptions may be revised over time.
Who it's relevant to
Inside LDC
Common questions
Answers to the questions practitioners most commonly ask about LDC.