· Compliance  · 8 min read

CUI Decontrol and Sanitization: Records Retention for the DIB

CUI status does not change how long you keep records; decontrol and sanitization handle markings and media while contracts and schedules drive retention.

CUI status does not change how long you keep records; decontrol and sanitization handle markings and media while contracts and schedules drive retention.

CUI status does not change records retention timelines. Agency records schedules and contract clauses set them, and you follow those periods regardless of markings.

Federal definitions and scope

The National Archives and Records Administration runs the executive branch Controlled Unclassified Information (CUI) program. NARA defines CUI as unclassified information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to safeguard or control for dissemination, excluding classified information. The CUI program sets a standard for designating, marking, safeguarding, disseminating, decontrolling, and disposing of such information across agencies.

32 CFR Part 2002 directs agencies on CUI practices and extends to organizations that handle, possess, use, share, or receive CUI on behalf of an agency. That frame covers DIB contractors as authorized holders under their contracts. NARA’s implementation recommendations instruct agencies to configure systems that store, process, or transmit CUI for a Moderate Confidentiality impact value consistent with 32 CFR 2002.14. Contractors align with that expectation when they design and operate enclaves for Federal CUI.

NARA’s CUI FAQ states in plain terms that records retention issues and timeframes do not change because a record carries CUI markings. Your records officer bases retention on the applicable records schedule and your contract.

Decontrol triggers and marking removal

Authorized holders decontrol CUI when the information no longer requires safeguarding or dissemination controls under 32 CFR Part 2002 and the CUI Registry. NARA’s decontrol guidance lists two paths. An agency can act to decontrol. Automatic triggers can also lift controls, for example a public release, a statutory release, an end of need to control, or a date or event that the agency specified in markings or policy.

You do not use decontrol to cover an unauthorized disclosure. NARA calls that out and expects agencies and holders to treat incidents through proper reporting and remediation channels.

After decontrol, you remove or strike CUI markings before reuse, release, donation, or transfer, and you follow agency policy on placement. That step avoids confusion for downstream users. If the contract transfers records to NARA, the agency decontrols when feasible or indicates ongoing status. The Archivist of the United States can decontrol CUI in records transferred to NARA. Contractors should coordinate decontrol questions with the contracting officer or agency CUI officer.

Media sanitization requirements under NARA and NIST

NARA policy and training tie media sanitization to NIST guidance. NARA’s CUI policy guidance references NIST SP 800-88, Guidelines for Media Sanitization. NARA training material instructs holders to render CUI unreadable, indecipherable, and irrecoverable when they destroy it, including electronic forms. Acceptable methods draw from NIST SP 800-53 controls, NIST SP 800-88 methods, methods approved for classified information, or methods required by law, regulation, or Government-wide policy.

You select a sanitization method that fits the media type and threat model. You document the method, the media identifier, and the person who executed and verified the action. You preserve that record per your internal records policy and any contract clause that sets a period for evidence of destruction.

CMMC guidance, which interprets NIST SP 800-171 for assessments, adds practical pointers for holders. The Level 2 Assessment Guide instructs you to store system media that contains CUI in a secure location and to restrict access to authorized users with accountability procedures. For non-digital media, the guide describes removal of CUI from documents, redaction of sections or words in a manner equivalent in effect to removal, or destruction, and expects you to choose a method that achieves the same protective outcome as removal.

CMMC Level 2 and NIST SP 800-171 media protection

The NIST SP 800-171 control set and CMMC Level 2 practices govern how you protect CUI on systems and media. Two practices drive decontrol and sanitization work:

  • MP.L2-3.8.3. Sanitize or destroy information system media that contains CUI before disposal or release for reuse.
  • MA.L2-3.7.3. Ensure equipment removed for off-site maintenance is sanitized of any CUI.

The CMMC Level 2 Assessment Guide explains these expectations and provides assessment criteria for evidence. The Scoping Guide defines CUI assets as assets that process, store, or transmit CUI. Those assets sit in scope for assessment and must meet applicable practices. You build procedures that ensure sanitization before you send devices for maintenance or reuse systems in a different role.

Keep your boundary tight so you know where these practices apply. If you still map the boundary, review our guidance on CMMC scoping and the CUI boundary. Align your evidence with your NIST SP 800-171 System Security Plan. Document decontrol triggers and media sanitization methods in the SSP and related records. For structure, see our post on System Security Plans for NIST SP 800-171.

If you track NIST SP 800-171 self-assessment results in SPRS, failure to meet MP.L2-3.8.3 or MA.L2-3.7.3 affects your score. We explain the scoring method in SPRS scoring for NIST SP 800-171. The scoring process does not set a records retention period, but it does expect documented methods and outcomes that an assessor can review.

Records retention strategy for defense contractors

You face two distinct questions. First, does the information require CUI controls. Second, how long do you keep the record based on its series. NARA’s FAQ separates these questions and states that CUI status does not drive the retention period. Your records manager and counsel anchor decisions in the agency schedule and contract language.

Build a durable approach that ties CUI handling to your records program.

  • Identify the records series that contain CUI under your contracts, then map each series to the controlling schedule or clause.
  • Name the roles that approve decontrol for each series, then publish the method and authority that the role will cite.

Documentation matters for both decontrol and sanitization events.

  • Record the decontrol trigger, the authority used, the date, and the person who removed or struck markings.
  • Log each sanitization action with the media identifier, the method used under NIST SP 800-88 or an approved method, the date, and the person who executed and verified the step.

Drive operational steps through procedure and training.

  • Update markings before you reuse, release, or donate information that left CUI status, then furnish the updated copy to the recipient.
  • Sanitize or destroy media when the schedule and contract permit disposition and your security team has cleared the method for that media type.

Tie decontrol and sanitization to your security boundary.

  • Keep CUI on systems engineered for Moderate Confidentiality, then decontrol the content before you transfer it to systems that do not carry that impact level.
  • When you send equipment off-site, sanitize CUI from the equipment in line with MA.L2-3.7.3, then record the action.

Address cross-cutting policy questions up front.

  • Who inside your firm can authorize decontrol for a given contract, and which agency official must agree.
  • How your contract treats records transfer to NARA and whether the agency expects decontrol before transfer.

Retain evidence that you followed the schedule and the contract. NARA does not set a period for such logs. Review the contract, the statement of work, and agency policy for any retention duty on destruction certificates, sanitization logs, or decontrol records. Keep those records alongside program documentation so an assessor or contracting officer can examine them during audits or performance reviews.

CUI controls may end at decontrol, but other duties can remain. Agency IT policy can require care for unclassified information that no longer carries CUI status. You should route such information into your standard unclassified handling processes and preserve the record per the schedule that already applies to that series.

Contract and DFARS alignment

DFARS 252.204-7012 drives adoption of NIST SP 800-171 controls across the DIB and sets incident reporting and other duties for covered defense information. Your decontrol and sanitization procedures should not conflict with these obligations. If your team reviews -7012 in detail, start with our overview of DFARS 252.204-7012 requirements. Confirm any records retention periods that the contract states for incident reports, media handling attestations, or destruction evidence, and fold those periods into your records program.

Action plan for program owners

You can move on this work without waiting for a contract event.

  • Inventory record series that include CUI, then confirm the controlling schedule and contract clause for each series with your records officer.
  • Publish a short decontrol and sanitization procedure for each media type in scope, then train admins and program staff who create, store, or dispose of CUI.

Coordination with the agency CUI officer and contracting officer helps you avoid rework. Use that venue to agree on decontrol triggers, marking changes, and any expectations for destruction evidence. The CUI Registry, the CMMC Level 2 Assessment Guide, and agency schedules give you the references you need for those discussions.

Sources

CUI Registry (National Archives and Records Administration)
CUI program overview and 32 CFR Part 2002 scope (National Archives and Records Administration)
CUI glossary and decontrol definition (National Archives and Records Administration)
Decontrolling CUI guidance (National Archives and Records Administration)
CUI FAQs on retention and marking removal (National Archives and Records Administration)
CUI policy guidance referencing NIST SP 800-88 (National Archives and Records Administration)
CUI implementation recommendations (National Archives and Records Administration)
CMMC Level 2 Assessment Guide (Department of Defense Chief Information Officer)
CMMC Level 2 Scoping Guide (Department of Defense Chief Information Officer)

Want a structured starting point?

Our 27-question CMMC technical readiness self-survey covers tenant, identity, endpoint, data protection, audit logging, documentation, and the 72-hour DFARS reporting plan. The score is produced in your browser from your answers alone. Nothing is verified or stored.

Back to Blog

Related Posts

View All Posts »
CUI Marking Requirements Under 32 CFR Part 2002

CUI Marking Requirements Under 32 CFR Part 2002

32 CFR Part 2002 directs agencies and authorized holders to use CUI Registry markings, apply clear banners with required category and dissemination indicators, and end legacy labels that the rule does not permit.