Is My Drawing CUI? How to Read a Print's Markings and Decide What It Requires
- 01The Short Answer (and Why "Unmarked" Is Not "Uncontrolled")
- 02What Makes Information CUI: Three Ingredients
- 03Read the Print: Markings That Say "Yes"
- 04The Five-Question Test
- 05Common Cases, Decided
- 06Unmarked but Suspicious: What to Do
- 07What a "Yes" Obliges: Storing, Sending, Sharing, Destroying
- 08What Is Not CUI (and the Cost of Over-Marking)
- 09A Buyer's Checklist
01The Short Answer (and Why "Unmarked" Is Not "Uncontrolled")
A drawing is CUI when a federal law, regulation, or government-wide policy requires it to be protected and it reached you through a federal contract or from the government itself. In defense manufacturing that almost always means one of two CUI categories: Controlled Technical Information (CTI), technical data with military or space application, and Export Controlled information, data whose release is limited by ITAR or the EAR. A single print is frequently both.[1][2]
The mistake most shops make is treating the marking as the trigger. It is not. The trigger is the contract and the nature of the information. DFARS 252.204-7012 obliges a contractor to safeguard "covered defense information" that is provided by or on behalf of DoD, or developed under the contract, whether or not the file arrived with a banner on it. Government offices are required to mark what they release; when a marking is missing, the information does not become free, it becomes a question you have to ask.[3]
02What Makes Information CUI: Three Ingredients
The CUI program (Executive Order 13556, implemented at 32 CFR Part 2002 and, for DoD, by DoDI 5200.48) replaced dozens of agency labels such as FOUO and SBU with one system and one registry. Under it, information is CUI when three things are true at once:[1][4]
| Ingredient | What it means for a drawing | Where you check |
|---|---|---|
| 1. A law or policy requires protection | For technical data the usual authorities are DoDI 5230.24 (distribution statements on technical documents), the ITAR and EAR (export control), and DFARS 252.204-7012 (safeguarding covered defense information). | The PO's clause list; the distribution statement or export warning on the print. |
| 2. It falls in a Registry category | The NARA CUI Registry lists the categories. Manufacturing meets two: Controlled Technical Information (CUI//SP-CTI) and Export Controlled (CUI//SP-EXPT). Both are "specified" categories with their own handling rules. | The category marking in the banner or the designation block. |
| 3. It is not public | Anything approved for public release (Distribution Statement A), published standards, and catalog data are not CUI, whatever else is printed near them. | Distribution Statement A; a public-release stamp; the document is a published spec. |
Two consequences follow. First, CUI is a government designation: your own commercial drawings do not become CUI because your title block template says so, and a customer's proprietary print is protected by your NDA, not by 32 CFR 2002. Second, CUI can spread to what you create from it, and the boundary is the contract, not the file type. Deliverables you produce under the contract that carry the controlled data forward, such as the first-article inspection package, the CMM report, or a marked-up copy of the drawing, are treated as CUI: DFARS 7012 covers information developed in performance of the contract, and those files reproduce the drawing's characteristics. Your own process know-how is a different matter. The CNC program, fixture designs, and setup sheets are the shop's intellectual property and are not CUI by default. They may be CUI where the contract designates contractor-developed data, or where the file embeds the controlled data itself (a program that carries the part geometry from a CTI model is hard to call anything else). When it matters, ask the prime's data custodian or the contracting officer; do not let a template decide it.[3]
03Read the Print: Markings That Say "Yes"
Marked CUI is the easy case. Look in four places: the top and bottom borders, the title block, the notes column, and, for a model, the file's properties or a notes feature. Any of the following means the document is controlled:[4][5]
| Marking | What it looks like | What it tells you |
|---|---|---|
| CUI banner | CUI or CONTROLLED centered at the top and bottom of every page. Often with the category: CUI//SP-CTI, CUI//SP-EXPT, or both: CUI//SP-CTI/SP-EXPT. | The document is CUI. "SP-" means a specified category with its own handling rules beyond the basic ones. |
| Designation indicator | A small block, usually near the title block or on the first page: Controlled by: the office · Category: CTI · Distribution/Dissemination Control: the statement · POC: name and contact. | Who designated it and whom to ask. The POC is where an unmarked-copy or decontrol question goes. |
| Distribution statement B–F | "DISTRIBUTION STATEMENT D. Distribution authorized to the Department of Defense and U.S. DoD contractors only; reason; date. Other requests shall be referred to..." | Technical data under DoDI 5230.24. Anything B through F is controlled; A is public. See the distribution-statement ladder. |
| Export-control warning | "WARNING: This document contains technical data whose export is restricted by the Arms Export Control Act (22 U.S.C. 2751 et seq.) or the Export Administration Act..." or simply ITAR CONTROLLED / ECCN 9E610. | Export-controlled. Under a federal contract this is also CUI (EXPT). Either way, U.S.-person access limits apply. |
| Legacy markings | FOUO, FOR OFFICIAL USE ONLY, SBU, "Export Controlled" without a category. | No longer authorized markings, still common on older drawings. Treat as CUI until the owner re-marks or decontrols the document. |
1234567-01
C
12345
1 OF 3
Two details trip people up. A 3D model carries the same status as the drawing it came from, banner or not; if the STEP file has no notes feature, the marking travels in the transmittal and the file name. And a screenshot, photo, or excerpt of a marked drawing is still CUI: cropping the banner off does not decontrol what is inside it.
04The Five-Question Test
Work down the list and stop at the first "yes." The first question is about the print, the second about the paperwork, the third about the end use, and the fourth separates export control from CUI, which overlap but are not the same thing.[3][5]
05Common Cases, Decided
The same handful of situations account for nearly every RFQ we see. Here is how the test resolves them.
| The situation | Verdict | Why |
|---|---|---|
| A prime forwards a government drawing marked Distribution Statement D. | CUI | Question 1. CTI by definition; the distribution statement is the marking. |
| A prime sends its own drawing for a military aircraft bracket. No banner, but the PO cites DFARS 252.204-7012. | Treat as CUI | Question 2. The clause makes it covered defense information. Ask the prime to mark it; keep handling it as CUI whether or not they do. |
| A drawing for a food-processing conveyor part, under an NDA, no government contract anywhere in the chain. | Not CUI | Question 5. Proprietary, protected by the NDA. Handle it well, but 800-171 is not triggered. |
| A catalog fastener to a public standard (NAS, AN, MS) for a military customer. | Not CUI | Published standards are public. A commercial-item drawing does not become CTI because the buyer is DoD. |
| The CNC program and setup sheet you wrote from a CUI drawing. | Depends | Shop IP by default, not CUI. It may be CUI if the contract designates contractor-developed data or the program embeds the controlled geometry. Your FAI package and CMM data, which reproduce the drawing's characteristics, are the derivatives to treat as CUI. |
| A drawing with an ITAR warning from a commercial customer building a product for export, no federal contract. | Export-controlled, not CUI | Question 4. ITAR's U.S.-person and licensing rules apply in full; the CUI program does not, because no federal contract flows it. |
| An old drawing stamped FOUO, nothing else. | Treat as CUI | FOUO is a retired marking that meant "controlled." Ask the owner to re-mark or decontrol; until then it is controlled. |
| A marked CUI drawing that the buyer emailed to you in the clear. | CUI | How it arrived does not change what it is. Store it correctly on receipt and give the sender a secure channel for next time. |
| A sketch with the note "for a Navy program" and no other information. | Ask | Question 3. Handle as CUI while you wait for a written answer. Do not forward it to a sub-vendor in the meantime. |
| A MIL-SPEC or AMS specification you bought from the publisher. | Not CUI | Published standards are public documents, even when they govern controlled parts. The drawing that invokes them may still be CUI. |
06Unmarked but Suspicious: What to Do
The gray zone is a print with no markings that plainly belongs to a military program: a landing-gear fitting, a missile canister bracket, a housing whose title block names a defense prime. The people who created it were required to mark it if it is CUI, so its arrival unmarked means one of three things: it is genuinely uncontrolled, the marking was dropped somewhere in the chain, or the sender does not know. You do not have to guess. Do four things:[3][4]
07What a "Yes" Obliges: Storing, Sending, Sharing, Destroying
Once a drawing is CUI, four sets of rules attach to it. The first is the one everybody has heard of; the other three are where most real-world slips happen.[3][6][7]
Storing: the NIST SP 800-171 environment
CUI may live only on systems that meet NIST SP 800-171: access limited to authorized users, multi-factor authentication, encryption, logging, and the rest of the 110 requirements that CMMC Level 2 verifies. In practice that rules out personal phones, consumer cloud drives, unencrypted USB sticks, and the front-office PC that also runs the accounting package unless it is inside the assessed boundary. Paper counts too: prints on the floor stay in controlled areas, go face-down or into a locked cabinet at the end of the shift, and are not photographed by visitors.
Sending: encrypted, never a public upload
CUI moves only over channels that protect it in transit, which for DFARS 7012 means FIPS-validated encryption. Plain email is out. So is a public web-upload form, however convenient, because the shop cannot control where that file lands. C&W accepts controlled technical data only through a U.S.-hosted secure channel we set up with the customer; the ITAR page explains how to start one. If a buyer emails a marked print anyway, the shop's obligation is to store it correctly on receipt and steer the next transmission to the secure channel.
Sharing: people and sub-tiers
Access is limited to people who need it for the job. When the data is also export-controlled, which describes most CTI, those people must be U.S. persons unless a license says otherwise, and that includes the plating vendor's estimator who receives the drawing to quote a finish. Sub-tier suppliers who touch the data must themselves meet DFARS 7012, the marking must travel with the file, and they need the same secure channel. A shop that sends a controlled print to an unvetted finisher has just made that finisher's inbox part of the incident.
Destroying and reporting
At the end of the job, CUI is returned or destroyed so that it is unreadable, indecipherable, and irrecoverable, the standard set in 32 CFR 2002.14, using a method approved for classified material. That last part surprises people: an ordinary office cross-cut shredder does not qualify. For paper, DoD points to shredders on the NSA/CSS Evaluated Products List, which cut to particles no larger than 1 mm × 5 mm under NSA/CSS Specification 02-01, the same size required for classified paper up to Top Secret, or to pulping, pulverizing, or disintegration equipment on that list. A typical office cross-cut machine leaves pieces around 4 × 40 mm and misses the standard by a wide margin. For drives, USB media, and any controller or backup that holds CUI (the drawing, the model, an inspection package, or a program that embeds controlled geometry), the references are NIST SP 800-88 (purge or destroy, never a quick format) and NSA/CSS Policy Manual 9-12 for the specific method; solid-state media cannot be degaussed, so physical destruction on listed equipment is usually the answer. If in-house equipment does not meet the standard, use a destruction vendor that certifies to it and keep the certificate of destruction with the job record. C&W handles this in-house: controlled paper is destroyed on site in a high-security, NSA/CSS-approved shredder, so CUI never leaves the building to be shredded. If a suspected compromise happens, DFARS 7012 requires reporting it to DoD within 72 hours through the DoD Cyber Crime Center (DC3), which now runs the defense industrial base incident-reporting portal that DIBNet used to, and which still requires a DoD-approved medium-assurance certificate to file. Compliant shops obtain that certificate before they need it.
08What Is Not CUI (and the Cost of Over-Marking)
The other failure mode is quieter and more expensive: marking everything. A drawing is not CUI when it is your company's own commercial design, a customer's proprietary print outside any federal contract, a published standard, anything approved for public release, or plain business information such as pricing and delivery. Those deserve normal confidentiality, not the CUI machinery.[1]
Over-marking has real costs. It pushes secure-handling premiums onto parts that do not need them, it dilutes the markings that matter so that people stop reading them, and it is technically a mis-marking: only the designating agency, or a contractor acting under a contract that directs it, may apply a CUI marking. A title-block template that stamps every drawing "CUI" is not compliance; it is noise. The test in section 04 is deliberately narrow so that a "yes" means something.
09A Buyer's Checklist
If you are sending drawings to a supplier, the fastest way to get correct handling is to make the answer obvious before the file leaves your system. Put these in the RFQ or the PO:
Have a controlled drawing to quote?
C&W holds a current CMMC Level 2 self-assessment in SPRS, is ITAR-registered and JCP-certified, and accepts CUI only through a U.S.-hosted secure channel. Ask us for one before you send the file.