Skip to content
    August 25, 2026| Top Floor Team| 16 min read

    How to Identify CUI in Your Environment: A Five-Step Procedure

    You identify Controlled Unclassified Information in your environment by tracing it, not by reading documents for sensitivity. Under 32 CFR 2002.20(a)(4), "The designating agency determines that the information qualifies for CUI status and applies the appropriate CUI marking when it designates that information as CUI." The determination is theirs. Your job is a discovery exercise with five steps: read the contract for what the government said it would send you, learn to read a CUI marking so you recognise it on arrival, handle the unmarked cases through the channel the regulation names rather than by guessing, trace every item into the systems that process, store or transmit it, and write the result down as the asset inventory, network diagram and system security plan that 32 CFR 170.19 expects. What CUI is, and how it differs from Federal Contract Information, is a separate question that FCI vs CUI already answers; this article assumes you have read it and starts where it stops.

    The procedure is the same whether you are a machine shop with one prime or a software firm with a dozen task orders, because the regulation puts the identification burden in the same two places every time: on the agency that designates, and on the contract that carries the designation to you.

    Key takeaways

    • The contractor does not self-designate. 32 CFR 2002.4(t) defines designating as a determination by an authorized holder "consistent with this part and the CUI Registry", and 2002.20(a)(4) puts the marking on the designating agency.
    • The contract is the primary evidence. DFARS 252.204-7012 defines covered defense information as CUI that is "marked or otherwise identified in the contract, task order, or delivery order" or that the contractor develops, receives or stores "in support of the performance of the contract".
    • A CUI marking has a fixed anatomy: a control marking, optional category and dissemination markings separated by double slashes, and a designation indicator naming the agency. If you can read that line, you can triage an inbox.
    • Unmarked or wrongly marked material is routed back to the government, not resolved locally. The NARA FAQ says "Questions regarding the status of information (marked or unmarked) should be directed back to the government contracting activity."
    • The output is three artifacts, not a spreadsheet of sensitive files: an asset inventory, a network diagram of the assessment scope, and asset treatment documented in the system security plan.

    Who decides, in the words of the regulation

    Everything downstream depends on getting this right, so it is worth quoting rather than paraphrasing.

    The fragment of 32 CFR 2002.4(h) that matters here is the authority clause: information is CUI only where "a law, regulation, or Government-wide policy requires or permits an agency to handle" it "using safeguarding or dissemination controls". Paragraph (t) defines designating as "When an authorized holder, consistent with this part and the CUI Registry, determines that a specific item of information falls into a CUI category or subcategory", and paragraph (u) defines the designating agency as "The executive branch agency that designates or approves the designation of a specific item of information as CUI."

    Two consequences follow. First, CUI is a pointer to an authority in the CUI Registry, which the National Archives maintains as Executive Agent under Executive Order 13556 per its programme page. If no law, regulation or Government-wide policy in that registry covers a document, the document is not CUI no matter how sensitive it feels. Second, the person who applies the pointer is the agency. Section 2002.20(a)(4) says the designating agency "applies the appropriate CUI marking when it designates that information as CUI", and the NARA FAQ answers the contractor question directly: "Contractors need to follow what is in their contracts. CUI requirements do not bind the public, except as authorized by a law, regulation, or as incorporated into a contract or agreement."

    The regulation also builds the reverse path. Under 2002.50, authorized holders who in good faith believe a designation is improper or incorrect may notify the disseminating agency, and while the challenge is pending they should continue to safeguard the information at its current marking. So the model is not "the government marks, you obey silently". It is "the government marks, you protect what arrives, and you raise disagreement through a named process". Deciding on your own that a marked document is not really CUI is the one move the regulation does not give you.

    Step one: read the contract for what was promised to you

    The clause set is the first place CUI is identified, and for defence work the identification is literally in the definition. DFARS 252.204-7012 defines covered defense information as unclassified controlled technical information or other information described in the CUI Registry that requires safeguarding or dissemination controls and is either "Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract" or "Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract."

    Read those two prongs as your first two search queries.

    Prong one is inbound. Somewhere in the contract, task order or delivery order, the government is supposed to have identified the CUI it will provide. Find that language. It may be an explicit list of CUI categories, a reference to a statement of work section, or a data item description. If the clause is present and the identification is absent, that absence is your first written question to the contracting officer, and the answer is evidence you will want on file for years.

    Prong two is what you make. Information you develop in performance of the contract can be covered defense information even though the government never sent it to you. A drawing you produce from a government specification, test results you generate on a government part, a process sheet you write for a defence end item: the definition reaches all of these. This is the prong most contractors miss, because they search for what arrived and never search for what they created.

    The general CUI programme sets the same expectation outside DoD. 32 CFR 2002.16(a)(5) says agencies should enter into agreements with any non-executive branch or foreign entity with which they share or intend to share CUI, and 2002.4(c) defines agreements and arrangements as "Any vehicle that sets out specific CUI handling requirements for contractors and other information-sharing partners when the arrangement with the other party involves CUI." Your contract is that vehicle. If it is silent on CUI and you are receiving marked material anyway, the contract and the reality disagree, and the disagreement is worth surfacing before an assessor finds it.

    Which CMMC level the answer implies is a different decision, and what CMMC level do you need owns it. This step produces the input to that decision, per contract, in writing.

    Step two: learn to read a marking, so you recognise CUI on arrival

    Once you know what the contract promised, the next filter is visual, and it is faster than most people expect because the marking scheme has a fixed anatomy. The CUI Marking Handbook (version 1.1, December 6, 2016) is the National Archives' illustrated guide to 32 CFR 2002.20, and its rules are what you train an inbox triage on.

    ElementWhat it looks likeWhat it tells you
    CUI control marking"CONTROLLED" or "CUI"; the handbook has the banner at the top of each page, in bold capitalsMandatory on every document containing CUI (2002.20(b)(1)). Its presence settles the question; its absence does not
    Category markingFollows the control marking after a double slash, for example CUI//SP-CTI; multiple categories alphabetised and separated by single slashesRequired for CUI Specified, which carries an "SP-" prefix; optional for CUI Basic unless agency policy mandates it (2002.20(b)(2)(ii))
    Limited dissemination controlA further double slash, then a marking from the Registry list such as NOFORN, FED ONLY, FEDCON, NOCON or DL ONLYWho may not receive it. Only markings in the Registry list are authorised
    Designation indicatorLetterhead, a signature block with the agency, or a "Controlled by:" lineWho designated it. 2002.20(d)(1): "All documents containing CUI must carry an indicator of who designated the CUI within it. This must include the designator's agency (at a minimum)"
    Portion marking"(CUI)" or "(U)" at the start of a paragraphOptional in unclassified documents, but where used it isolates exactly which portion is controlled

    Three of the handbook's rules are worth memorising because they decide edge cases.

    The banner reflects the whole document. Per the handbook, the banner on a multi-page document is "essentially the sum of all of the CUI markings in the document", and "The presence of EVEN ONE item of CUI in a document requires CUI marking of that document." So a hundred-page proposal with one controlled paragraph is a CUI document, and the question of where it may be stored is answered by that paragraph.

    "SP-" changes the handling. CUI Basic is, in 2002.4(j), the subset "for which the authorizing law, regulation, or Government-wide policy does not set out specific handling or dissemination controls." CUI Specified, in 2002.4(r), is the subset where the authority "contains specific handling controls that it requires or permits agencies to use that differ from those for CUI Basic." The handbook is careful that CUI Specified "is NOT a 'higher level' of CUI, it is simply different", and different means the underlying authority has its own rules that your default handling may not satisfy. When you see SP- in a banner, look up the authority.

    Electronic media carry a reduced marking. The handbook says media such as USB sticks, hard drives and CD-ROMs "must be marked to alert holders to the presence of CUI stored on the device", and that where space is short the minimum is the control marking and the designating agency. If your search of the estate ignores removable media because "we do not label those", that is a gap in the search rather than an absence of CUI.

    Step three: the unmarked and mis-marked cases go back to the government

    Markings are frequently missing, wrong or old. The regulation anticipates all three and names a channel for each.

    Unmarked information that qualifies. 2002.20(m) says to "Treat unmarked information that qualifies as CUI as described in the Order, § 2002.8(c), and the CUI Registry." Section 2002.8(c)(12) requires each agency's CUI senior agency official to establish "a mechanism by which authorized holders (both inside and outside the agency) can contact a designated agency representative for instructions when they receive unmarked or improperly marked information the agency designated as CUI". You are one of the holders outside the agency. The mechanism exists for you. Use it, and keep the reply.

    Legacy markings. 2002.4(cc) defines legacy material as unclassified information an agency marked as restricted "prior to the CUI Program", and 2002.20(a)(1)(i) obliges agencies and authorized holders to "Discontinue all use of legacy or other markings not permitted by this part or included in the CUI Registry." The NARA FAQ adds: "Once agencies implement the CUI program, legacy markings such as FOUO or SBU will no longer be used. In some cases, what was previously marked as FOUO would align and be marked as CUI." The handbook is equally direct: "All legacy information is not automatically CUI. Agencies must examine and determine what legacy information qualifies as CUI and mark it accordingly." So a file server full of documents stamped FOUO is neither automatically in scope nor automatically out. It is a list of items whose status the originating agency has to confirm, and the handbook's re-use process (identify the information, check whether its type is listed in the Registry, and if so mark the new document as CUI) is the procedure to run when any of it is incorporated into new work.

    Information you believe is mis-designated. That is the 2002.50 challenge described above. Protect it at its current marking while you ask.

    The common thread is that none of these cases is resolved by an internal meeting. The NARA FAQ sentence bears repeating because it is the whole policy: "Questions regarding the status of information (marked or unmarked) should be directed back to the government contracting activity." An engineer's opinion that an unmarked drawing is "obviously not CUI" is not a determination, and neither is a consultant's opinion that it obviously is.

    Step four: trace it into the systems that process, store or transmit it

    Steps one to three tell you what CUI you hold. Step four tells you where, and it is where the CMMC scope is actually set. 32 CFR 170.19 defines CUI Assets at Level 2 as "Assets that process, store, or transmit CUI", and NIST SP 800-171 applies its requirements, in the words of the Revision 2 abstract, "to all components of nonfederal systems and organizations that process, store, and/or transmit CUI, or that provide protection for such components". (CSRC records Revision 2 as withdrawn on May 14, 2024 and superseded by Revision 3; which revision CMMC pins, and why, is covered in is CMMC Level 2 the same as NIST 800-171.) Three verbs: process, store, transmit. Run each one against the estate.

    Start from an entry point, not from a system list. Take one CUI item you identified in steps one to three and follow it: the mailbox it arrived in, the folder it was saved to, the CAD or PLM system it was opened in, the quoting tool it was summarised into, the supplier portal it was uploaded to, the printer it was sent to, the backup job that copied the folder, the ticketing system where someone attached it to ask a question. Each hop is a system that processes, stores or transmits CUI and each is a candidate CUI Asset. Then do it for a second item from a different contract, because the paths differ.

    Then run the search the other way, across the categories of place where CUI tends to sit unnoticed. Shared mailboxes and distribution lists. Sync folders on laptops and phones. Engineering file shares with fifteen years of history. Removable media in desk drawers, which the marking handbook expects to be labelled and most companies have never labelled. Multi-function printers with internal storage. Collaboration tools where a screenshot of a drawing was pasted into a chat. Supplier portals where you upload what you receive. Each of these is a question with a yes or no answer, and the honest way to get the answer is to look, not to ask the owner whether they think CUI is there.

    The asset categories that sort what you find (CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets and Out-of-Scope Assets) and the enclave decision they lead to are owned by CMMC enclave or full scope. The providers that turn up in the trace, and what each owes you, are owned by does your MSP need CMMC. This step produces their input: a list of every asset that touched CUI, with the path that put it there.

    Step five: write it down in the three documents the rule names

    The regulation is specific about where the answer lives. 170.19 requires in-scope assets to be documented in the asset inventory, in the network diagram of the CMMC Assessment Scope, and, as to their treatment, in the system security plan. An identification exercise that ends in an email thread has not ended.

    Per contract, record the clause set, the CUI identification language or its absence, the categories the contracting officer confirmed, and the date of the confirmation. Per CUI item type, record the marking as received and any correction obtained. Per asset, record which items it processes, stores or transmits and which category it therefore falls into. Then draw the diagram from the asset list, not the other way round.

    Two habits keep the record true. Re-run step four when a new contract starts, when a system is added or migrated, and when a prime changes how it sends you data, because the trace is only correct for the estate it was drawn against. And keep the government correspondence with the record: the confirmation of categories, the reply from the 2002.8(c)(12) contact, the outcome of any 2002.50 challenge. Those are the documents that make "we identified our CUI" a statement an assessor can verify rather than a claim they have to take on trust.

    What this procedure does not decide

    It does not decide your level; that follows from the answer and is worked through in what CMMC level do you need. It does not decide whether to build an enclave; the enclave article does, once the trace shows how many people and systems are involved. It does not decide what your managed provider owes you, which is in the MSP article. And it does not decide export-control status: technical data subject to ITAR or EAR is often CUI as well, but the export obligations are a separate regime with their own rules, and the enclave article covers why that can override the scoping arithmetic.

    It also does not apply if you have no federal contract, subcontract or agreement that involves CUI. The NARA FAQ states the boundary: CUI requirements "do not bind the public, except as authorized by a law, regulation, or as incorporated into a contract or agreement." No agreement, no CUI obligation, and a readiness programme built on a prime's mailing list is spending against a hypothesis.

    Where Top Floor fits

    The identification exercise is the first phase of our CMMC engagements, and it is the phase that sets every downstream cost: reading the clause sets, drafting the written questions to contracting officers, training the people who receive data to read a banner, running the trace across the estate, and producing the inventory, diagram and system security plan sections that 170.19 expects. Where a company runs CMMC alongside commercial frameworks, the same trace feeds the other programmes under compliance as a service.

    Two honest limits. We do not designate CUI, and neither does anyone else outside the government; a firm that tells you what is CUI before your contracting officer has is offering an opinion, and you should keep the correspondence that shows whose opinion it was. And if you hold one contract, receive marked drawings from one prime, and can name the three people who open them, you can run this procedure yourself in a week with the handbook open beside you. Buy help when the contract count, the estate, or the number of unmarked cases makes the trace a project.

    How to decide this week

    Pull every active federal contract, subcontract and task order and find the CUI identification language or note its absence. Where absent, send the written question.

    Print page six of the marking handbook and put it next to the people who open inbound files. Ask them to flag every banner they see for one week.

    Pick one flagged item and trace it through every system it touched, from arrival to backup. That single trace usually reveals the shape of the whole problem, and it tells you whether step four is an afternoon or a quarter.

    Frequently asked questions

    Who decides whether something is CUI?

    The designating agency, not the contractor. 32 CFR 2002.4(t) defines designating as a determination by an authorized holder "consistent with this part and the CUI Registry" that an item falls into a CUI category, and 2002.20(a)(4) says the designating agency "applies the appropriate CUI marking when it designates that information as CUI." The National Archives FAQ tells contractors that questions about the status of information, marked or unmarked, "should be directed back to the government contracting activity." If you believe a designation is wrong, 2002.50 lets you challenge it in good faith while continuing to protect the information at its current marking.

    How do I recognise a CUI marking?

    By its anatomy. Every document containing CUI carries a control marking, "CONTROLLED" or "CUI", mandatory under 32 CFR 2002.20(b)(1); the CUI Marking Handbook places it at the top of each page. Category markings follow after a double slash and are mandatory for CUI Specified, which carries an "SP-" prefix; limited dissemination controls such as NOFORN or FEDCON follow after another double slash. Every document must also carry a designation indicator naming at least the designating agency, per 2002.20(d)(1). The handbook adds that one item of CUI anywhere in a document makes the whole document a CUI document.

    What do I do with documents marked FOUO?

    Treat them as unresolved rather than as either in or out of scope. 32 CFR 2002.4(cc) calls pre-programme markings legacy material, 2002.20(a)(1)(i) requires legacy markings to be discontinued, and the marking handbook states that all legacy information is not automatically CUI and that agencies must examine and determine what qualifies. Ask the originating agency, through the contact mechanism 2002.8(c)(12) requires it to provide, and when legacy material is re-used in new work, follow the handbook's process: identify the information, check whether its type is in the CUI Registry, and mark the new document if it is.

    Does CUI I create myself count, or only what the government sends?

    Both. DFARS 252.204-7012 defines covered defense information to include information "Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract", and 32 CFR 2002.4(h) defines CUI to include information "an entity creates or possesses for or on behalf of the Government." A drawing, test result or process sheet you generate from government-furnished technical data can be CUI even though it never arrived marked. The search for CUI therefore has two directions: what came in, and what you made from it.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.