Jackie Ramsey July 15, 2026 0

A mistake in handling Controlled Unclassified Information (CUI) can expose sensitive government data, create significant audit gaps, and confuse employees who need clear handling instructions. Under the Cybersecurity Maturity Model Certification (CMMC) framework, a practical CMMC CUI marking template provides your team with one repeatable method for identifying, labeling, storing, sharing, and retiring sensitive information.

I recommend treating CUI marking as a core component of daily operations, rather than a document control task that only appears before an assessment. Your procedure should connect contract requirements, employee behavior, Microsoft 365 settings, endpoint controls, and evidence collection.

The template below gives small and midsize defense contractors a workable starting point for CMMC Level 2 preparation.

Key Takeaways

  • CMMC Level 2 requires the protection of Controlled Unclassified Information (CUI) in systems that process, store, or transmit it, based on the 110 requirements found in NIST SP 800-171 Rev. 2.
  • CMMC does not create new CUI categories, and it is important to remember that not every document requires unclassified information markings.
  • Your organization must validate marking requirements with the contracting officer, legal counsel, or designated security authority.
  • A written marking procedure should cover electronic files, printed records, emails, removable media, and exports from business systems.
  • These markings only work when access control, endpoint security, staff training, and cloud management support the same rules for CMMC Level 2 compliance.

Why CUI Marking Matters for CMMC Level 2

Controlled Unclassified Information is information the government creates or possesses, or that an organization creates or possesses for or on behalf of the government, that requires safeguarding or dissemination controls under applicable law, regulation, or government-wide policy. It is not classified information. Still, it requires disciplined protection.

NARA manages the federal CUI program, and its CUI Registry identifies approved categories and subcategories. Contractors should never invent their own category labels simply because a file seems sensitive.

For CMMC Level 2, this procedure is vital for members of the Defense Industrial Base handling DoD contracts, as the key issue is whether your environment protects sensitive data according to framework requirements. A marking procedure supports several areas of compliance, including access control, media protection, system and communications protection, awareness training, and audit accountability.

Markings tell employees what they are handling. They also reduce guesswork when files move between project teams, cloud repositories, email systems, printers, conference rooms, and subcontractors.

A marking is a handling signal, not a security control by itself. The system must still restrict access, record activity, and protect CUI during storage and transmission.

I often see contractors make one of two costly errors. The first is marking every internal file as CUI. The second is leaving CUI unmarked because the file came from a trusted source or sits inside a protected Microsoft 365 tenant.

Neither approach is reliable. Over-marking dilutes the meaning of CUI and can create needless handling burdens. Under-marking leaves staff without direction and creates inconsistent evidence during a CMMC assessment.

The DoD CMMC Program ties Level 2 requirements to protecting Federal Contract Information and CUI in the contractor environment, specifically by aligning these practices with NIST 800-171. Your contract, statement of work, data received from the government, and written direction from the contracting officer should guide your scope decisions.

Determine What Requires a CUI Marking

Before using a template, identify the source and authority for the information. A contractor cannot decide that a document is CUI based only on business sensitivity, competitive value, or discomfort with disclosure. Instead, requirements for identifying CUI are typically dictated by DFARS 252.204-7012 or specific data handling requirements found within your DoD contracts.

For each data type, I recommend documenting four facts:

Review questionWhat to documentExample evidence
Where did the information come from?Government source, contract task, prime contractor, or internal creationAward document, email, portal record
What authority applies?Law, regulation, policy, or contract clauseContract clause, CUI category reference
Is it CUI or another data type?CUI category, FCI, proprietary data, PII, or public informationData inventory entry
Who approved the determination?Security authority, program manager, legal counsel, or contracting officerReview ticket or approval record

The NARA CUI Program overview explains that agencies determine whether information qualifies as CUI under applicable authorities. A defense contractor should follow the direction attached to the information and raise questions when markings, contract language, or data flow are unclear.

For example, a technical data package received through a DoD portal may already carry a CUI banner. That banner should remain intact when your team downloads, stores, prints, or shares the package.

However, an internally created meeting agenda may not require CUI marking simply because it relates to a defense contract. Review whether the agenda includes Controlled Technical Information, export controlled data, protected procurement data, or another category tied to a valid authority.

A good data inventory helps separate business records from CUI. Include locations such as SharePoint sites, Teams channels, OneDrive folders, file servers, engineering applications, ticketing systems, encrypted laptops, backups, and removable media.

CMMC CUI Marking Procedure Template

The following CUI marking procedure template is designed for adaptation by a small business. Replace bracketed fields with your organization’s information, then have the procedure reviewed by the appropriate internal and external authorities.

Document Control

FieldTemplate entry
Procedure titleCUI Marking and Handling Procedure
Company[Company Name]
Procedure owner[System Owner or Security Manager]
Approved by[Executive Name and Title]
Version[Version Number]
Effective date[Effective Date]
Review date[Review Date]
Related policiesAccess Control Policy, Media Protection Policy, Incident Response Plan, Security Awareness Training Policy
Applicable systems[System Names, Microsoft 365 Tenant, File Server, Engineering Platform, Ticketing System]

Purpose and Scope

Purpose: [Company Name] marks and handles Controlled Unclassified Information according to applicable contract requirements, government direction, the NARA CUI Program, DoD requirements, and internal security policies. This procedure establishes consistent methods for identifying, marking, storing, transmitting, printing, and destroying CUI.

Scope: This procedure applies to all employees, temporary staff, executives, subcontractors, consultants, managed service providers, and third parties who access CUI in [Company Name] systems or facilities.

Out of scope: Information that is public, internal-only, proprietary, Federal Contract Information, or personally identifiable information does not become CUI unless an authorized government source, contract requirement, applicable authority, or designated security authority identifies it as CUI.

Roles and Responsibilities

RoleResponsibility
[Executive Sponsor]Provides resources and approves policy direction
[System Owner]Maintains technical controls for systems that process CUI
[Security Manager]Maintains this procedure, training records, and review evidence
[Program Manager]Identifies contract data flows and escalates marking questions
[Data Owner]Confirms source, category, and authorized handling requirements
[All Authorized Users]Apply approved markings and report suspected errors
[IT Provider or Business Technology Partner]Configures approved security controls and supports evidence collection

Approved CUI Markings

[Company Name] uses only markings authorized by the information source, contract, applicable law, regulation, or policy. Personnel must preserve government-provided CUI banner markings, portion marking entries, distribution statements, and dissemination controls.

When determining the format, personnel must identify if the data is CUI Basic or CUI Specified. Regardless of the classification, the documentation may also require a Designation Indicator block to identify the authority for the designation. Unless the source or contract requires another format, follow these standards:

  • Place CUI in the header and footer of each page.
  • Use the authorized CUI category or limited dissemination control when provided.
  • Retain source markings on government-furnished information.
  • Mark files exported to PDF, printed copies, and scanned copies before distribution.
  • Apply the approved naming convention when a file name needs a handling indicator, such as [CUI] ProjectName-TechnicalData.pdf.

Employees must not add a CUI label merely because information is confidential. They must refer questionable items to [Security Manager], [Program Manager], or [Designated Security Authority].

Electronic File Marking Procedure

  1. Confirm that the file contains CUI and record the source or contract reference in [Data Inventory Location].
  2. Review the original file for CUI banner markings, CUI category markings, dissemination controls, export-control notices, or distribution statements.
  3. Preserve all original markings when editing, converting, or exporting the file.
  4. Apply the approved header and footer when the file requires contractor-applied CUI marking.
  5. Store the file only in an approved location listed in [Authorized CUI Repository List].
  6. Limit access to authorized users with a documented business need.
  7. Share the file through approved encrypted methods, such as [Approved Email Encryption Method] or [Approved Secure File Sharing Platform].
  8. Record material marking errors or suspected unauthorized disclosures under the incident response process.

Printed Records and Physical Media

Personnel must place printed CUI in controlled work areas when not in use. Staff must not leave CUI on shared printers, conference-room tables, unlocked desks, or vehicles. For physical protection, it is recommended to use an SF 901 coversheet to shield the content of sensitive documents.

Printed copies require the approved CUI marking on each page when applicable. Employees should collect output immediately from printers and use locked disposal bins or approved cross-cut shredding for destruction.

Removable media containing CUI must carry an external label that identifies the media as CUI and includes any required handling limitations. [Company Name] only permits encrypted removable media approved by [System Owner].

Email, Collaboration, and External Sharing

Email messages that contain CUI in the body or attachment must use approved encryption and include the required CUI indication where applicable. Users must verify recipient addresses before sending information outside [Company Name], particularly if the data includes export controlled restrictions or limited dissemination controls.

Microsoft Teams and SharePoint can support controlled collaboration, but permission settings require active administration. For an Office 365 migration involving CUI, I recommend documenting tenant type, authentication requirements, conditional access policies, external sharing restrictions, retention settings, and approved repositories before moving any records.

For organizations that need a compliant government cloud environment, Microsoft 365 GCC High may be part of a broader secure cloud architecture. The tenant alone does not create compliance. Configuration, user behavior, documentation, and evidence all matter.

Connect Markings to Technical Security Controls

A CUI marking procedure has limited value if users can download Controlled Unclassified Information to unmanaged devices or forward files to personal email. CMMC Level 2 requires a working security program, not a polished policy binder.

NIST 800-171 includes requirements for controlling data flow, limiting access to authorized users, protecting covered defense information during transmission, sanitizing media, and monitoring system activity. The NIST SP 800-171 Rev. 2 publication remains the core reference for CMMC Level 2 alignment.

Your technical environment should support the procedure through controls such as multifactor authentication, least-privilege access, endpoint encryption, audit logging, secure backups, email protection, and approved data repositories. These controls reduce the chance that a correctly marked file becomes an uncontrolled file.

Endpoint Security and Device Hardening deserve close attention. A CUI file can lose protection when a user saves it to an unmanaged laptop, copies it to unencrypted USB storage, or prints it at an uncontrolled location. Managed devices should have full-disk encryption, supported operating systems, patch management, malware protection, restricted local administrator rights, screen locks, and centralized logging.

For many contractors, Cloud Infrastructure has replaced the local file server as the main CUI storage location. That shift demands careful Cloud Management, especially when handling Controlled Technical Information. Review identity settings, guest access, sharing links, mobile-device controls, retention rules, backup coverage, and administrator privileges.

Build Training and Evidence Into Daily Work

Employees need more than a one-time slide deck. They need instructions that match the tools and situations they face during normal work.

I recommend training new users before granting CUI access. Annual training should reinforce how to recognize CUI, preserve source markings, use approved storage locations, verify recipients, secure printed material, and report a possible disclosure.

Include short scenarios based on actual work. An engineering employee may receive a marked technical drawing from a prime contractor. A project manager may need to upload a CUI deliverable to a customer portal. A finance employee may receive a contract-related file that contains no CUI at all. These cases help staff distinguish between sensitive business information and controlled information, while also ensuring they understand how to address legacy markings that may appear on older documents and cause confusion.

Maintain evidence that the process works. Useful records are essential for demonstrating compliance during your C3PAO assessment. These records include:

  • CUI data inventory entries and system boundary diagrams
  • Marking approvals and documented exception decisions
  • Training completion records and training materials
  • Access reviews for CUI repositories
  • Sample marked files, screenshots, and printer handling records
  • Incident tickets involving mislabeling, lost media, or unauthorized sharing

A CMMC assessor may ask how a user knows what to do with a received CUI file. Your answer should include the procedure, the training record, the technical control, and a live demonstration in the system.

Fit CUI Marking Into Broader Small Business IT

CMMC work often reveals broader technology issues. A contractor may have inconsistent file sharing, aging laptops, weak identity controls, or backup systems that were never designed for controlled unclassified information. Those gaps affect compliance and everyday operations.

A strong Business Technology Partner can connect CUI handling with Small Business IT, practical Cybersecurity Services, and long-term technology planning. That work may include Infrastructure Optimization, secure collaboration standards, identity management, and documented recovery processes.

For companies modernizing operations, Office 365 Migration planning should identify Controlled Technical Information and CUI before data moves. Similarly, Data Center Technology decisions should account for system boundaries, access logging, encryption, backup protection, and vendor responsibilities.

The same discipline applies outside defense work. Restaurant POS Support and Kitchen Technology Solutions may involve payment systems, employee devices, remote support, and operational data. Those environments do not usually process DoD CUI, yet they still benefit from controlled access, device management, and tested recovery plans.

Innovative IT Solutions should solve a defined business problem. Tailored Technology Services should match the company’s contract obligations, risk tolerance, staff capacity, and growth plans. That is why Technology Consulting and an informed IT Strategy for SMBs matter before adding new cloud tools or expanding remote access.

For a defense contractor, Managed IT for Small Business should include clear ownership of patching, backups, identity administration, endpoint monitoring, incident escalation, and CUI repository management. The goal is practical Business Continuity & Security, supported by documented responsibilities rather than informal assumptions.

Review the Procedure Before an Assessment

Review the CUI marking procedure at least annually and after major contract, system, staffing, or security changes. A new prime contractor, cloud migration, acquisition, incident, or office move can alter how CUI enters and moves through the business.

During each review, compare the written procedure against real behavior. Pull a recent CUI file. Confirm its marking, storage location, access list, audit trail, backup status, transmission method, and disposal path. Then verify that employees can explain their responsibilities.

If a government-provided file lacks markings but appears to contain Controlled Unclassified Information, do not guess. Preserve the file, restrict access while the question is reviewed, and contact the contracting officer, legal counsel, or designated security authority for direction.

The procedure should also align with your System Security Plan, Plan of Action and Milestones, asset inventory, data flow diagrams, incident response plan, and vendor agreements. Conflicting documentation can create unnecessary complications, so ensure your process remains consistent with your system security plan to avoid issues before an assessment.

Frequently Asked Questions

Can I create my own labels for sensitive government documents?

No, you should never invent custom categories. The National Archives and Records Administration (NARA) manages the official CUI Registry, and contractors must follow the categories and subcategories defined by that registry or provided by the contracting officer.

Does all information related to a defense contract require CUI marking?

Not every document is CUI. You must differentiate between routine business records, proprietary information, and Controlled Unclassified Information based on specific contract requirements and authoritative direction from the government.

What should I do if I receive a document that looks like CUI but is not marked?

Do not assume it is standard business data. Secure the file, restrict access to it, and contact your contracting officer, legal counsel, or designated security authority to receive formal guidance on how the information should be handled.

Are CUI markings sufficient to secure sensitive data on their own?

No, markings are handling signals rather than technical security controls. Your organization must still implement robust system protections such as encryption, access control, audit logging, and secure transmission methods to ensure CUI remains protected at rest and in transit.

A Clear Marking Process Supports Stronger CMMC Readiness

A CMMC CUI marking template provides your employees with a shared method for handling sensitive contract data with care. By establishing this consistency, you create vital evidence that your organization understands where data resides and how it remains protected under the Cybersecurity Maturity Model Certification. This structured approach is essential for any business aiming to demonstrate compliance and achieve CMMC Level 2 certification.

The strongest procedure is short enough for employees to use, detailed enough for technical teams to implement, and reviewed whenever business conditions change. Consistent handling of Controlled Unclassified Information protects contract performance, reduces avoidable exposure, and supports credible readiness for your upcoming assessment.


Discover more from Guide to Technology

Subscribe to get the latest posts sent to your email.

Category: 

Leave a Reply