to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

Is the information in front of you CUI?

At most 3 questions about one specific set of information. It ends in a determination or in the exact question to put to your contracting officer.

Read this first

Whether information is CUI is the government's decision, made by the agency that designates it and, in theory, marked on the document. This worksheet does not make that decision for you. It prepares the question: it sorts the information you are holding by where it came from, what it is marked, and what your contract says, so that you either know what to do next or know exactly what to ask. Where the answer points at one registry category, it names it and its marking.

Over-protecting is recoverable. Under-protecting is not.

Go deeper

The questions, in order

Q1 Where did this information come from?

Think about the specific folder, drawing, or thread, not your business in general.

Origin decides everything downstream. Information you generated for yourself is not federal information no matter how sensitive it feels.

Q2 Is it marked: CUI, FOUO, Distribution B through F, ITAR, or similar?

Look at headers, footers, cover sheets, drawing title blocks, and the transmittal email.

32 CFR 2002 places the duty to identify and mark CUI on the agency that designates it.

Q3 What does the marking say?

Read the banner at the top of the page or the drawing title block. A Specified category appears as CUI//SP- and a code; a plain CUI banner means a Basic category.

32 CFR 2002.20(b): the banner is the word CUI, then // and SP- plus the category marking for CUI Specified, then // and any limited dissemination control such as NOFORN.

Q4 Is this information the contract requires you to produce or protect?

Deliverables, test data, drawings, and process information developed under the contract usually are. Your own invoices and staffing notes usually are not.

DFARS 252.204-7012 covers covered defense information, which includes information collected, developed, received, transmitted, used, or stored in support of contract performance.

Q5 Is it technical information about a military or space item?

Drawings, specifications, process descriptions, test results, source code, or manuals relating to a defense article.

DFARS 252.204-7012(a) defines controlled technical information by reference to DoD Instruction 5230.24 distribution statements B through F.

Q6 Does any part of it contain information the government gave you or that you produced for a contract?

Mixed files are common. A pricing spreadsheet with a government drawing pasted in is not purely internal.

Commingling is the most frequent scoping error. One CUI element pulls the whole container into scope unless you separate it.

Q7 Was it cleared for public release by the government?

Published on a government site or approved through a public-release review counts. Something you found on a supplier's website does not.

DFARS 252.204-7012(a) excludes information lawfully and publicly available without restriction.

Q8 Does your contract include DFARS 252.204-7012?

Search the contract PDF for “7012”. It is normally in Section I.

The clause is the mechanism that imposes 800-171 on you. Without it, the obligation is not contractual.

The outcomes

  • Treat this as CUI. This has the marks of covered defense information. Your obligation is to protect it under all 110 requirements of NIST SP 800-171 Rev. 2 and to report cyber incidents affecting it to DoD within 72 hours.
  • Separate it, then treat the CUI part as CUI. Mixed containers pull everything around them into scope. The cheapest fix is almost always separation, not expanding your boundary to cover the whole company.
  • This looks like FCI, not CUI. Federal contract information is information provided by or generated for the government under a contract that is not intended for public release. It is in scope, but for the basic safeguarding requirements of FAR 52.204-21 rather than all 110.
  • Not federal information. Out of scope. Your own business information is yours to protect as you see fit. Nothing in CMMC or 800-171 reaches it, though it may still be your most valuable data.
  • This one goes to your contracting officer. You have reached the point where the answer is not yours to give. Unmarked information you suspect is CUI is a question for the person who issued the contract, and their written answer is the record that protects you.