· Compliance · 8 min read
CUI Marking Requirements Under 32 CFR Part 2002
32 CFR Part 2002 directs agencies and authorized holders to use CUI Registry markings, apply clear banners with required category and dissemination indicators, and end legacy labels that the rule does not permit.

Federal policy sets the CUI playbook. 32 CFR Part 2002 requires agencies and authorized holders to mark CUI using the markings in the CUI Registry, and to apply those markings in a consistent manner that readers can see. Contractors handle CUI under government contracts, so your program needs to follow the same rule when you create, receive, or transmit that information.
32 CFR Part 2002 requirements
32 CFR Part 2002 designates the CUI Registry as the government source for CUI categories, subcategories, and authorized markings. The rule authorizes the markings listed in the Registry to designate unclassified information that a law, regulation, or government-wide policy protects. The rule directs agencies and authorized holders to stop legacy markings that the program does not permit and to replace them with the authorized CUI markings.
The rule requires a banner marking on CUI. The banner appears in a place the reader can see, such as the top of the page for documents. The regulation also addresses transmittal materials, portion markings, and the use of limited dissemination controls. Agencies may issue policy that adds placement details or narrows some choices that the federal rule allows.
The Registry and the rule work together. The Registry provides the authorized categories, subcategories, limited dissemination controls, and portion marking scheme. The rule makes those items binding for agencies and authorized holders.
CUI banner, category, and portion markings
Designators place a CUI banner that can include up to three elements. The CUI control marking sits first and may be either the word “CONTROLLED” or the acronym “CUI.” Agency policy may direct one form. The banner may also include the category or subcategory marking when the Registry lists it as required or permitted for the information type. If the Registry lists a limited dissemination control, the banner includes that as well.
Many CUI Basic situations accept a banner that reads “CUI” with no category text. CUI Specified situations require the applicable category or subcategory marking. Specified categories also bring any required limited dissemination controls from the Registry into the banner. The Registry page for the category tells you what to add.
Authorized holders who designate CUI can use portion markings if the CUI Executive Agent has approved the scheme and listed it in the Registry. If your agency customer or contract requires portion markings for CUI, then you apply the approved abbreviations in the portions you author, and you keep the banner on the page. If the contract does not require portion markings, you still place the banner so the reader sees the CUI status at a glance.
Designators also add a designation indicator, when required by the agency policy that implements the federal rule. That indicator identifies the office that applied the marking and gives contact information for questions about the designation or decontrol.
CUI Registry control of marking choices
The CUI Registry serves as the government-wide repository for marking guidance, categories, and controls. The Registry identifies each category as Basic or Specified. The Registry also lists any required or permitted category markings and the set of limited dissemination controls that go with the category. The Registry pages include definitions and references to the source authority for that information type.
The Registry listing controls your banner content. You pick the control marking, “CUI” or “CONTROLLED,” based on agency policy. You add the category or subcategory marking when the Registry indicates that requirement for Specified, or when the listing permits it. You add any limited dissemination control codes that the listing requires. You do not invent local codes or terms for CUI. The rule restricts markings to those in the Registry.
Agencies may add format and placement instructions, but they still point you to the Registry for category and control codes. The federal rule and the Registry take precedence for the content of the marking.
If you need program scoping context, mark CUI at the point of creation and intake. Clear markings help you set and defend the CUI boundary during CMMC preparation. Our post on CMMC scoping and the CUI boundary explains the boundary mechanics that follow from this.
Transmittal documents and legacy markings
The rule covers transmittal documents that carry CUI. If you send CUI with a transmittal letter or an email, you mark the transmittal document on its face with a CUI banner. You also add a notice that the enclosure or attachment contains CUI. If you design the transmittal to become uncontrolled when you remove the enclosure, you note that as well. You still mark the enclosure itself with the CUI banner and any required category and limited dissemination text from the Registry.
Agencies and authorized holders must stop legacy labels that the CUI program does not permit. You will see contracts or archives that still carry historical terms. Treat those files as candidates for re-marking under 32 CFR Part 2002. Coordinate with the contracting officer or the agency program office before you alter government records, and document any direction you receive.
You do not blend legacy labels with CUI. You apply the CUI banner and required elements from the Registry, and you remove unsupported markings during your update. If another holder sends you a file that shows legacy tags, request confirmation of the correct CUI category and dissemination controls, then mark the copy you control per the rule.
DoD-specific CUI marking expectations
The Department of Defense implements the federal rule through DoDI 5200.48 and DoD Manual 5200.01, Volume 2. DoD follows the Registry for categories, subcategories, and limited dissemination controls. DoD adds implementation details that affect format and placement.
DoD documents include a CUI banner with the approved control marking, the category or subcategory for Specified information, and any required limited dissemination controls from the Registry. DoD policy also calls for a designation indicator that identifies the originating activity and a point of contact. The instruction and manual describe placement, cover elements, and page markings in DoD formats.
You should expect DoD contracts to cite the instruction or manual in data item descriptions or CDRLs. You should align your templates with those documents and the Registry. If your Microsoft 365 tenant supports sensitivity labels, you can map label names and footers to the CUI banner and required legends for DoD formats. That mapping ties into data loss prevention and transport rules you set for CUI handling. We outline the Microsoft 365 side in Microsoft Purview CUI and DLP.
DFARS clauses often bring additional safeguarding and incident reporting obligations on systems that process CUI. Marking does not satisfy those clauses, but it sets the boundary that those clauses apply to. If you need a summary of the contract obligations, see DFARS 252.204-7012 requirements.
Practical marking steps for contractors
You can keep your program aligned with the federal rule and agency policy by anchoring your process to two actions.
- Build your category catalog from the CUI Registry, then tie each category to a banner rule that calls out the control marking, the category or subcategory requirement, and any limited dissemination controls the listing requires.
- Train your authors and program staff on portion markings and transmittal rules where your agency customer or contract directs use, and include a designation indicator in your templates where your customer requires it.
Template discipline reduces errors. Your document templates should place the banner where readers can see it and should reserve space for category and limited dissemination text. Your transmittal templates should carry the face marking and the enclosure notice. Your email templates should include a subject line pattern and body legend that match the customer direction and the rule.
Your intake process should enforce re-marking on arrival for legacy labels. Your contract management process should keep the current agency policy, the DoD instruction where applicable, and your mapping from Registry categories to banners. Your records show who designated the file and when you decontrolled it, if the agency policy assigns a decontrol event or date.
Your technology can help with consistency. Sensitivity labels that apply a banner, footer text, and header text can align your content with the Registry and the agency format. Data loss prevention policies that match on those labels can enforce routing and encryption rules. Your users still decide the correct category, but your system keeps the visual and transport behavior in line with the rule.
Key pitfalls to avoid
Two failure patterns cause most marking defects in DIB programs.
- Teams invent local markings that do not appear in the CUI Registry. The rule does not permit that practice. Use Registry codes, category names, and limited dissemination controls.
- Teams mix legacy labels with CUI banners. The rule directs holders to stop legacy terms and replace them with the authorized CUI markings.
You can detect both patterns with a simple review of templates and a sample of outbound files. Check the banner text for Registry alignment and check the presence of required category and limited dissemination text for Specified information. Check transmittal letters for the face mark and enclosure notice.
Clear markings help your SSP writers define system scope and help your engineers set Microsoft 365 controls in the right places. Your assessors will expect to see that linkage between the Registry, your templates, and your content.
Sources
Controlled Unclassified Information (CUI) (National Archives and Records Administration)
32 CFR Part 2002, Controlled Unclassified Information (National Archives and Records Administration)
CUI Registry Category and Marking List (National Archives and Records Administration)
GSA CUI Program Guide, January 31, 2024 (General Services Administration)
CUI Marking Handbook v1.1, December 6, 2016 (National Archives and Records Administration)
Want a structured starting point?
Our 27-question CMMC technical readiness self-survey covers tenant, identity, endpoint, data protection, audit logging, documentation, and the 72-hour DFARS reporting plan. The score is produced in your browser from your answers alone. Nothing is verified or stored.



