Skip to main content

🔔 Notifications Hub: See compliance updates in one place

Controlled Technical Information (CTI)

Controlled Technical Information is a CUI category for technical data with military or space application. Engineering drawings, specifications, performance parameters, test data, source code for weapons systems. CTI is identified by Distribution Statements B through F (per DoD Instruction 5230.24). If your contract involves CTI, you are handling CUI, which means CMMC Level 2 and DFARS 252.204-7012 apply.

What CTI Covers

  • Engineering drawings and CAD files for defense components
  • Technical specifications, performance parameters, test procedures
  • Manufacturing process documentation, quality control data
  • Source code and firmware for weapons platforms or defense systems
  • Research and development data with military application
  • Technical manuals, maintenance procedures, training materials

Distribution Statements B Through F

DoD Instruction 5230.24 defines six distribution statements. Statement A is unlimited public release. Statements B through F are the controlled ones, each narrower than the last:

  • Distribution B: U.S. Government agencies only.
  • Distribution C: U.S. Government agencies and their contractors.
  • Distribution D: DoD and U.S. DoD contractors only.
  • Distribution E: DoD components only.
  • Distribution F: Further distribution only as directed by the controlling DoD office.

How to Tell If You Have CTI

Look for distribution statement markings on the document itself. The marking is usually on the cover sheet or in the document header. If a drawing arrives with 'Distribution Statement D,' that drawing is CTI. The DD Form 254 attached to a contract also identifies controlled information categories.

CTI and CMMC Compliance

CTI is CUI, so contractors handling CTI need CMMC Level 2 certification and the full 110 NIST SP 800-171 practices. A few areas deserve extra attention because of how CTI gets stored and shared: access control (who on the team actually needs the file, based on need-to-know), audit and accountability (who opened the file and when), and media protection (how CAD files get moved between CAD stations, shop floor, and archival storage).