Protecting CUI is a shared effort spanning federal agencies, prime contractors, subcontractors, and every individual who touches it along the way. But shared responsibility only works when everyone knows which part is theirs, and this is where many defense contractors get tripped up. Assumptions about who marks documents, who determines what qualifies as CUI, and when obligations actually apply have real consequences, from failed compliance efforts to False Claims Act exposure.
The answers live in a layered set of regulations that most contractors know only by their clause numbers. Understanding how 32 CFR Part 2002, DoD Instruction 5200.48, and DFARS 252.204-7012 fit together tells you not just what you're required to do, but why, and where the obligation comes from.
This section walks you through the full accountability picture: who is responsible for protecting CUI and applying markings, the regulations that define those duties and make them enforceable, how requirements flow down through the supply chain to subcontractors, and who holds the authority to decontrol CUI when it no longer needs protection.
Whether you're building a compliance program from scratch or pressure-testing one you've inherited, you'll walk away knowing exactly where your responsibilities begin and end, and where the rules are actively changing.