to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

DoD Critical Infrastructure Security Information DCRIT

A CUI category in the Defense grouping of NARA's registry, CUI Basic, marked CUI.

For a defense contractor

Foxx Cyber's note, not NARA's

Marked DCRIT. Vulnerability and protective-measure information about defence installations and infrastructure.

NARA's description

CUI Registry · DoD Critical Infrastructure Security Information

Information that, if disclosed, would reveal vulnerabilities in the DoD critical infrastructure and, if exploited, would likely result in the significant disruption, destruction, or damage of or to DoD operations, property, or facilities, including information regarding the securing and safeguarding of explosives, hazardous chemicals, or pipelines, related to critical infrastructure or protected systems owned or operated on behalf of the DoD, including vulnerability assessments prepared by or on behalf of the DoD, explosives safety information (including storage and handling), and other site-specific information on or relating to installation security.

Verbatim from the registry entry, which NARA last reviewed on May 8, 2025. Fetched 2026-09-08.

Markings

Category marking
DCRIT
Banner marking
CUI
Alternative banner, Basic
CUI//DCRIT

A banner reads CUI for Basic categories and CUI//SP-DCRIT for Specified ones, followed by any limited dissemination control such as NOFORN. How the marking rule works, verbatim from 32 CFR 2002.20.

Authorities

The law, regulation or Government-wide policy that makes this information CUI, and whether it does so as a Basic or a Specified authority.

Safeguarding or dissemination authorityBasic or SpecifiedBannerSanctions
10 USC 130eBasicCUI

Source: https://www.archives.gov/cui/registry/category-detail/dod-critical-infrastructure-security-information.