Skip to main content

CMMC Pause: What DoW & Primes Still Require

background

Who Is Responsible for Protecting CUI?

  • cui
  • Who Is Responsible for Protecting CUI?

You've received a document from a government program manager. It's clearly sensitive, but it's not marked, and you're not sure whether it's your job to mark it, the government's job, or something you're both responsible for. 

This is one of the most common points of confusion for defense contractors handling CUI, and getting it wrong, in either direction, creates real risk.

Recommended reading

What is Controlled Unclassified Information (CUI)?

Read More

Who is responsible for protecting CUI?

Responsibility for protecting CUI isn't held by a single person. It's layered, starting at the federal level and extending down to every individual who creates, receives, or handles CUI.

  • The CUI Executive Agent. Per Executive Order 13556, the National Archives (NARA), through its Information Security Oversight Office (ISOO), oversees the government-wide CUI Program and sets the baseline rules everyone else follows. For defense contractors specifically, the Department of Defense implements those rules through DoD Instruction 5200.48, which establishes the DoD CUI Program and is the more directly relevant authority for most DoD contracts.
  • Federal agencies and their Senior Agency Officials (SAOs). Each agency designates a Senior Agency Official responsible for implementing the CUI Program within that agency, including issuing agency-specific policy and, in some cases, marking waivers.
  • Authorized holders. This is the term that matters most for you as a contractor. 32 CFR Part 2002, defines an authorized holder as any individual, agency, organization, or group permitted to designate or handle CUI. Once your contract incorporates CUI requirements, typically through clauses like DFARS 252.204-7012, you become an authorized holder and the responsibility to protect that information is binding.

CUI program requirements don't automatically apply to contractors by law; they apply when incorporated into a contract or agreement. 

Who is responsible for applying CUI markings and dissemination instructions?

Under DoD Instruction 5200.48, Section 3.6.a, the authorized holder of a document or material is responsible for determining, at the time of creation, whether the information falls into a CUI category. If it does, that same authorized holder is responsible for applying the appropriate CUI markings and dissemination instructions.

If you create a document, report, or piece of technical data under a DoD contract, the responsibility to determine whether it's CUI and apply the correct marking sits with you, the creator, not with the government.

That said, this responsibility works differently depending on where the information originated:

  • If the government originates the CUI and shares it with you, the originating agency is responsible for the CUI designation and marking. Your responsibility as the contractor is to preserve those existing markings and handle the information accordingly.
  • If you create new or derivative CUI under your contract, you can only do so if your contract explicitly grants you designation authority. Without it, you're not authorized to designate or mark information as CUI, even if you believe it qualifies. If your contract does grant that authority, you're responsible for identifying and marking it correctly at the time of creation, whether that's an engineering analysis built on CUI drawings, a report summarizing CUI test data, or any other document that incorporates CUI source material.

Building a strong CUI program within your organization

Getting the responsibility framework right on paper is one thing. Incorporating these habits will strengthen your CUI program so it works when it counts.

Understand your contract requirements 

Your marking and safeguarding obligations are defined by your contract, not by the CUI Registry alone. According to NARA's official CUI FAQ, contractors should not follow CUI program requirements or apply markings unless directed to do so in a contract or agreement. Start by reading every clause carefully, particularly DFARS 252.204-7012 if it’s present, and map what it actually requires your organization to do.

Under the proposed FAR Overhaul (FAR Case 2026-001), this contract-based direction would be formalized through a new Standard Form (SF XXX), which contracting officers would be required to complete for every contract involving CUI, specifying which categories apply and what safeguarding requirements are in scope. If finalized, this would give contractors a clearer, standardized picture of their obligations upfront rather than relying on clause interpretation.

If you think you're handling unmarked CUI, raise it

If you receive information that seems to qualify as CUI but hasn't been marked, direct questions to the originator of the information or your government contracting activity. Under the proposed FAR Overhaul, contractors would be explicitly required to safeguard any unmarked or mismarked CUI they discover until the contracting officer makes a determination as to its status — but would not be required to mark or identify it themselves unless the SF XXX specifically directs them to.

Preserve CUI markings you receive 

Under 32 CFR 2002 and the NARA FAQ, CUI must be safeguarded in accordance with your contract, whether it was created by you or shared from the government. If a document arrives already marked as CUI, that marking carries forward through every copy and derivative, unless it's been formally decontrolled. Stripping or ignoring a CUI marking on a document you forward, save to a new location, or incorporate into another document is a mishandling failure.

Train your team to recognize CUI

DoD contractors are required to complete CUI training annually. The official training is available free through the Defense Counterintelligence and Security Agency (DCSA) Center for Development of Security Excellence (CDSE). The course covers how to identify, mark, safeguard, decontrol, and destroy CUI, and provides a completion certificate. 

Contractors can also build their own supplemental training program around the same guidelines, but the CDSE course is the baseline. Training your engineers, proposal writers, and program staff to recognize CUI, not just look for the banner, is what turns a policy into safe handling practices.

Why mishandling CUI has real consequences for your business

Misclassifying or failing to mark CUI isn't just a paperwork issue. Under 32 CFR 2002 Subpart H (Sections 2002.46 through 2002.48), the formal sanctions framework for CUI mishandling establishes that agencies are responsible for investigating reported violations and applying administrative remedies. 

Those remedies include:

  • Loss of access to CUI. This is the most immediate business consequence for a contractor. If an agency determines your organization can't be trusted with CUI, they can revoke access. For a defense contractor, losing CUI access doesn't just affect one contract; it can make you ineligible to perform work across the programs that depend on it.
  • Mandatory retraining. Often applied alongside other sanctions, particularly in negligence cases where mishandling was unintentional but systemic.
  • Disciplinary action for individuals. For contractor employees, the contracting agency can direct the contractor to take adverse personnel action against the individuals involved.
  • Referral to the Department of Justice. Where criminal statutes may have been violated, 32 CFR 2002 Subpart H explicitly contemplates referral to the DOJ. This isn't a hypothetical escalation path; it's a formal provision of the sanctions framework, and it applies in cases involving deliberate or gross mishandling of CUI.

Understanding what your contract requires, and building processes to meet those requirements consistently, is the most direct way to protect your business. 

FAQs

Does handling only paper CUI exempt me from CMMC requirements?

Not entirely. Organizations that exclusively handle hard-copy CUI are not required to complete a third-party C3PAO assessment, according to Cyber AB FAQ C-Q11. However, a compliance obligation under NIST SP 800-171 and DoD Instruction 5200.48 still applies. More importantly, the exemption ends the moment CUI enters a digital system: scanning, photographing, uploading, or emailing physical CUI documents brings your information systems into CMMC assessment scope.

Loading...