What CUI is (and isn't)
CUI is information the federal government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that requires safeguarding or dissemination controls pursuant to law, regulation, or government-wide policy. NARA maintains the authoritative CUI Registry of categories.
CUI is not: classified information (that's Confidential/Secret/Top Secret), generic proprietary data, FOUO under the legacy program, or commercial data without a federal nexus. The mistake of treating everything sensitive as CUI inflates scope and cost.
The mandatory banner marking
The CUI banner must appear at the top of every page of a CUI document. The minimum is:
CUI
Banner with category and dissemination control:
CUI//SP-CTI//NOFORN
Structure: CUI followed by //, the category (e.g. SP-CTI for Specified-Controlled Technical Information), another //, and any dissemination controls (e.g. NOFORN = no foreign nationals). Categories come from the CUI Registry; dissemination controls come from the limited approved list.
Portion marking (paragraph-level)
Each paragraph, table, figure, or other discrete portion of a CUI document should carry a portion mark identifying its CUI status. Format: (CUI) at the start of the portion, or (U) for unclassified portions in a mixed document.
Portion marking is recommended for any CUI document but becomes mandatory when CUI is mixed with non-CUI content in the same document — without it, the entire document is presumed CUI.
Dissemination controls you'll actually see
- NOFORN — Not Releasable to Foreign Nationals.
- FED ONLY — Federal employees only.
- FEDCON — Federal employees and contractors only.
- NOCON — Not Releasable to Contractors.
- REL TO USA, [country] — Releasable to specified countries.
- DL ONLY — Display only (limits printing/forwarding).
How CUI marking maps to CMMC objectives
Marking touches at least three NIST 800-171A objective families: 3.1 Access Control (limit CUI based on markings), 3.8 Media Protection (mark CUI media), and 3.13 System and Communications Protection (mark electronic CUI in transit). Your assessor will sample documents and emails to verify marking compliance. A program that processes CUI but can't show consistently marked artifacts is going to lose objectives across all three families. The evidence collection guide covers what to capture.
Common marking failures
- Banner only at first page. CUI requires marking on every page.
- Email subject without banner. Emails carrying CUI need a banner line in the body, not just the subject.
- Inconsistent category codes. Use the NARA registry codes verbatim. Made-up category strings will be cited.
- Mixed documents without portion marks. Without portion marks, the whole document is CUI and your scope expands accordingly.
- No CUI training for staff. The 3.2 Awareness and Training family requires annual CUI handling training — a marking error often traces back to missing training records.