If you're a defense contractor handling Controlled Unclassified Information (CUI), your compliance obligations don't come from a single source. They come from a layered set of regulations, each playing a distinct role. Most contractors know DFARS 252.204-7012 because it shows up in their contracts. Fewer know where it comes from, what it actually requires, or how it connects to CMMC and the broader regulatory framework behind it.
For defense contractors, three regulatory frameworks are the most important to know: 32 CFR Part 2002, DFARS 252.204-7012, and CMMC. A fourth is on the way: a proposed FAR rule would extend standardized CUI requirements across all federal contracts, which we’ll cover below.
What DoD instruction implements the DoD CUI Program?
DoD Instruction 5200.48, "Controlled Unclassified Information (CUI)," is the DoD instruction that implements the DoD CUI Program.
Issued on March 6, 2020 by the Under Secretary of Defense for Intelligence and Security, it establishes policy, assigns responsibilities, and prescribes procedures for CUI throughout the Department of Defense and its contractor community, in accordance with Executive Order 13556 and 32 CFR Part 2002.
The regulatory frameworks around CUI
CUI compliance for defense contractors sits across three interconnected regulatory layers. Each builds on the one below it, and each plays a distinct role: one establishes the government-wide framework, one implements it for DoD specifically, and one makes it contractually enforceable.
Understanding how they connect tells you not just what you're required to do, but why, and where the obligation actually comes from.

32 CFR Part 2002: The government-wide foundation
32 CFR Part 2002 is the federal regulation that established the CUI Program across the entire executive branch. Published by NARA as the implementing regulation for Executive Order 13556, it defines what CUI is, who qualifies as an authorized holder, how CUI must be marked and safeguarded, and what decontrol and sanctions look like.
For federal contractors, 32 CFR Part 2002 sets the baseline. It defines the terms and the overall framework. But it doesn't, by itself, impose binding requirements. As the NARA FAQ makes clear, CUI program requirements don't automatically apply to non-federal entities; they apply when incorporated into a contract or agreement.
DoDI 5200.48: The DoD implementation
DoDI 5200.48 takes 32 CFR Part 2002's framework and implements it for the DoD enterprise. It covers DoD-specific marking requirements, the DoD CUI Registry, and procedures for responding to CUI misuse. It's the primary governance document for how the DoD operationalizes the CUI Program, and it applies to DoD components, military services, defense agencies, and the contractors working under DoD contracts.
DoDI 5200.48 also establishes the DoD's mandatory CUI training requirement. Per the instruction and the DCSA CUI Training Reference Guide, DoD contractors are required to complete CUI training annually. The official training (course IF141.16) is available through the Center for Development of Security Excellence (CDSE) and covers identifying, marking, safeguarding, decontrolling, and destroying CUI.
Contractors may also develop their own training program based on the same guidelines, but the CDSE course fulfills the requirement when directed by a Government Contracting Activity.
DFARS 252.204-7012: The contractual mechanism
DFARS 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting," is the contract clause that makes CUI obligations legally enforceable for defense contractors. When this clause appears in your contract, it means you're bound by specific cybersecurity and safeguarding requirements, regardless of whether you have a direct relationship with the DoD or are operating as a subcontractor.
Its core requirements include:
- Implementing the security controls in NIST SP 800-171 (currently Revision 2) on any system that processes, stores, or transmits Covered Defense Information (CDI)
- Reporting cyber incidents to the DoD within 72 hours of discovery
- Using cloud service providers that meet FedRAMP Moderate or equivalent standards
- Submitting malicious software to the DoD Cyber Crime Center (DC3) if discovered during a cyber incident investigation (As of June 6, 2025, DoD cyber incidents are no longer reported via DIBNet, which has been shut down; reporting now goes through the DC3/DCISE portal at icf.dcise.cert.org)
- Flowing the clause down to subcontractors whose work involves CDI
DFARS 252.204-7012 has been a required clause in DoD contracts involving CDI since 2016 and applies across a defense supply chain that, per the DoD, includes roughly 337,000 prime contractors and subcontractors.
A few related DFARS clauses round out the picture:
- DFARS 252.204-7008 ("Compliance with Safeguarding Covered Defense Information Controls"): a solicitation provision requiring offerors to represent, before contract award, that they will implement NIST SP 800-171 requirements.
- DFARS 252.204-7020 ("NIST SP 800-171 DoD Assessment Requirements"): requires contractors to conduct a self-assessment of NIST SP 800-171 compliance and submit the score into SPRS.
- DFARS 252.204-7021 ("Cybersecurity Maturity Model Certification Requirements"): the clause through which CMMC requirements are incorporated into specific contracts, specifying the required CMMC level and timeline.
Recommended reading
The FAR CUI Rule: What the June 2026 Proposed Rule Means for Federal Contractors
Read MoreProposed changes under the Revolutionary FAR Overhaul (RFO)
The June 2026 proposed rule under the Revolutionary FAR Overhaul would make several notable changes to how CUI requirements are communicated and enforced across civilian contracts. If finalized, the rule would:
- Introduce a standardized form, SF XXX (CUI Requirements), that contracting officers must complete for every solicitation and contract involving CUI, identifying which CUI categories are involved, where CUI will reside, and what safeguarding and reporting requirements apply
- Replace the current ad-hoc clause approach with two new FAR clauses: FAR 52.240-6 (notice) and FAR 52.240-7 (substantive CUI requirements)
- Standardize CUI incident reporting to 72 hours from discovery across civilian agencies, with non-DoD incidents reported via CISA
- Introduce "Covered Federal Information" as a new defined term for what has been called FCI
The proposed FAR rule would not replace DFARS 252.204-7012 for DoD contractors. The two frameworks would run in parallel. If you hold contracts with civilian agencies alongside your DoD work, these requirements would apply to those contracts directly, making this a fourth compliance layer. The public comments period closed on July 23, 2026, and final rules are expected to take effect in 2026.
How CMMC connects
The Cybersecurity Maturity Model Certification (CMMC) program doesn't replace DFARS 252.204-7012; it builds on it.
DFARS 7012 requires contractors to implement NIST SP 800-171 and self-attest their compliance by submitting a score to the Supplier Performance Risk System (SPRS). CMMC extends it: contractors subject to CMMC Level 2 must complete a self-assessment against the DoD Assessment Methodology, maintain an accurate SPRS score, and affirm continued compliance annually.
Since CMMC requirements are now being written directly into DoD contracts via DFARS 252.204-7021, failing to achieve the required CMMC level can affect your ability to bid on or continue performing DoD work.
Why understanding these regulations matters
Reading through three regulatory frameworks can feel like an abstract exercise. What ties them together for a defense contractor is a simple chain: 32 CFR Part 2002 defines the rules, DoDI 5200.48 tells DoD how to apply them, and DFARS 252.204-7012 is what makes them your legal obligation the moment you sign a contract.
Misunderstanding where that obligation comes from, or assuming CUI requirements apply automatically without a contract clause, creates risk in both directions. Over-scoping your compliance program wastes resources on requirements that aren't triggered yet. Under-scoping it creates real legal exposure.
CUI compliance failures can carry administrative sanctions under 32 CFR Part 2002 Subpart H, including loss of CUI access and adverse personnel action. DFARS non-compliance adds a separate layer of risk: submitting invoices under a contract where cybersecurity compliance has been misrepresented creates False Claims Act exposure, with penalties that can include tripled damages.
Knowing which regulation governs which obligation, and when each one applies, is the foundation of a CUI compliance program that holds up under scrutiny.
FAQs
Which DoD instruction provides the governance for the CUI Program?
DoDI 5200.48 takes the government-wide framework established by NARA/ISOO under 32 CFR Part 2002 and translates it into DoD-specific policy, covering how DoD components and their contractors identify, mark, safeguard, disseminate, and decontrol CUI.