Buyer Resources · CUI & Data Handling

Is My Drawing CUI? How to Read a Print's Markings and Decide What It Requires

Author: C&W Engineering Team
Reading time: 12 min
Audience: Buyers · Engineers · Suppliers receiving defense drawings
The question shows up with almost every defense RFQ: a drawing arrives, the title block has a stamp or two, the PO has a page of clauses, and someone has to decide whether this print is Controlled Unclassified Information. Get it wrong one way and you have shipped controlled technical data through ordinary email to a plating vendor; get it wrong the other way and you are paying secure-handling premiums on a commercial bracket. No clearance is needed to answer it. You need to read three things: the print, the purchase order, and the end use. This guide walks through them in that order, with a five-question test, the markings to look for, what to do with an unmarked print, and what a "yes" actually obliges you and your supplier to do.
Before we start
This article is a practical orientation, not legal advice. CUI designation, marking, and decontrol decisions on real programs belong with the designating agency, your prime's data custodian, or export counsel. When in doubt, the safe default is to handle a document as CUI until the owner says otherwise.

01The Short Answer (and Why "Unmarked" Is Not "Uncontrolled")

A drawing is CUI when a federal law, regulation, or government-wide policy requires it to be protected and it reached you through a federal contract or from the government itself. In defense manufacturing that almost always means one of two CUI categories: Controlled Technical Information (CTI), technical data with military or space application, and Export Controlled information, data whose release is limited by ITAR or the EAR. A single print is frequently both.[1][2]

The mistake most shops make is treating the marking as the trigger. It is not. The trigger is the contract and the nature of the information. DFARS 252.204-7012 obliges a contractor to safeguard "covered defense information" that is provided by or on behalf of DoD, or developed under the contract, whether or not the file arrived with a banner on it. Government offices are required to mark what they release; when a marking is missing, the information does not become free, it becomes a question you have to ask.[3]

The one-sentence rule
If the print is marked, it is CUI. If the print is unmarked but the PO carries DFARS 252.204-7012 or the part goes on a military or space end item, treat it as CUI and ask the sender to confirm. Only a commercial drawing outside any federal contract is safely "no."

02What Makes Information CUI: Three Ingredients

The CUI program (Executive Order 13556, implemented at 32 CFR Part 2002 and, for DoD, by DoDI 5200.48) replaced dozens of agency labels such as FOUO and SBU with one system and one registry. Under it, information is CUI when three things are true at once:[1][4]

IngredientWhat it means for a drawingWhere you check
1. A law or policy requires protectionFor technical data the usual authorities are DoDI 5230.24 (distribution statements on technical documents), the ITAR and EAR (export control), and DFARS 252.204-7012 (safeguarding covered defense information).The PO's clause list; the distribution statement or export warning on the print.
2. It falls in a Registry categoryThe NARA CUI Registry lists the categories. Manufacturing meets two: Controlled Technical Information (CUI//SP-CTI) and Export Controlled (CUI//SP-EXPT). Both are "specified" categories with their own handling rules.The category marking in the banner or the designation block.
3. It is not publicAnything approved for public release (Distribution Statement A), published standards, and catalog data are not CUI, whatever else is printed near them.Distribution Statement A; a public-release stamp; the document is a published spec.

Two consequences follow. First, CUI is a government designation: your own commercial drawings do not become CUI because your title block template says so, and a customer's proprietary print is protected by your NDA, not by 32 CFR 2002. Second, CUI can spread to what you create from it, and the boundary is the contract, not the file type. Deliverables you produce under the contract that carry the controlled data forward, such as the first-article inspection package, the CMM report, or a marked-up copy of the drawing, are treated as CUI: DFARS 7012 covers information developed in performance of the contract, and those files reproduce the drawing's characteristics. Your own process know-how is a different matter. The CNC program, fixture designs, and setup sheets are the shop's intellectual property and are not CUI by default. They may be CUI where the contract designates contractor-developed data, or where the file embeds the controlled data itself (a program that carries the part geometry from a CTI model is hard to call anything else). When it matters, ask the prime's data custodian or the contracting officer; do not let a template decide it.[3]

03Read the Print: Markings That Say "Yes"

Marked CUI is the easy case. Look in four places: the top and bottom borders, the title block, the notes column, and, for a model, the file's properties or a notes feature. Any of the following means the document is controlled:[4][5]

MarkingWhat it looks likeWhat it tells you
CUI bannerCUI or CONTROLLED centered at the top and bottom of every page. Often with the category: CUI//SP-CTI, CUI//SP-EXPT, or both: CUI//SP-CTI/SP-EXPT.The document is CUI. "SP-" means a specified category with its own handling rules beyond the basic ones.
Designation indicatorA small block, usually near the title block or on the first page: Controlled by: the office · Category: CTI · Distribution/Dissemination Control: the statement · POC: name and contact.Who designated it and whom to ask. The POC is where an unmarked-copy or decontrol question goes.
Distribution statement B–F"DISTRIBUTION STATEMENT D. Distribution authorized to the Department of Defense and U.S. DoD contractors only; reason; date. Other requests shall be referred to..."Technical data under DoDI 5230.24. Anything B through F is controlled; A is public. See the distribution-statement ladder.
Export-control warning"WARNING: This document contains technical data whose export is restricted by the Arms Export Control Act (22 U.S.C. 2751 et seq.) or the Export Administration Act..." or simply ITAR CONTROLLED / ECCN 9E610.Export-controlled. Under a federal contract this is also CUI (EXPT). Either way, U.S.-person access limits apply.
Legacy markingsFOUO, FOR OFFICIAL USE ONLY, SBU, "Export Controlled" without a category.No longer authorized markings, still common on older drawings. Treat as CUI until the owner re-marks or decontrols the document.
Anatomy of a marked print
Where the four markings usually sit on a DoD or prime-contractor drawing. Real prints vary; the banner is the one that must appear on every page, and the designation indicator is the one that names the office to call.
CUI//SP-CTI/SP-EXPT ① banner, top and bottom of every page
Notes column
1. MATERIAL: 7050-T7451 PER AMS 4050.
2. UT INSPECT PER AMS-STD-2154 CLASS A.
3. FAI PER AS9102 ON FIRST LOT.
WARNING: This document contains technical data whose export is restricted by the Arms Export Control Act (22 U.S.C. 2751 et seq.). Violations are subject to severe criminal penalties. ② export-control warning
DISTRIBUTION STATEMENT D. Distribution authorized to the Department of Defense and U.S. DoD contractors only; critical technology; 2024-03-01. Other requests shall be referred to the controlling office. ③ distribution statement
Controlled by: USAF AFLCMC/XYZ
Category: CTI, EXPT
Distribution/Dissemination Control: DISTRIBUTION STATEMENT D
POC: J. Smith, (xxx) xxx-xxxx
④ designation indicator
DWG NO
1234567-01
REV
C
CAGE
12345
SHEET
1 OF 3
CUI//SP-CTI/SP-EXPT

Two details trip people up. A 3D model carries the same status as the drawing it came from, banner or not; if the STEP file has no notes feature, the marking travels in the transmittal and the file name. And a screenshot, photo, or excerpt of a marked drawing is still CUI: cropping the banner off does not decontrol what is inside it.

04The Five-Question Test

Work down the list and stop at the first "yes." The first question is about the print, the second about the paperwork, the third about the end use, and the fourth separates export control from CUI, which overlap but are not the same thing.[3][5]

Is this drawing CUI?
Stop at the first "yes." Questions one and two settle it; question three is the common gray zone, where the right move is to ask the sender and handle the file as CUI in the meantime.
1. CUI banner, Distribution B–F, or an export warning anywhere on the print? yes It is CUI Handle under NIST SP 800-171 from the moment it arrives. Preserve the markings on every copy and derivative. no 2. DFARS 252.204-7012 (or 7019/7020/ 7021) on the PO or the prime contract? yes Treat it as CUI The clause, not the stamp, creates the duty. Ask the customer for the marking and distribution statement. no 3. Military or space end item, and the data came from DoD or a defense prime? yes Probably CTI: confirm before quoting Government data must be marked; ask the sender to confirm its status in writing. Handle as CUI meanwhile. no 4. Export-controlled (USML category or ECCN) but outside any federal contract? yes Export-controlled, not CUI ITAR or the EAR still limit who may see it (U.S. persons, licenses), but 800-171 is not contractually triggered. no 5. None of the above: not CUI. Commercial or proprietary data. Protect it under your NDA and ordinary IT hygiene. Distribution Statement A material and published standards are public.

05Common Cases, Decided

The same handful of situations account for nearly every RFQ we see. Here is how the test resolves them.

The situationVerdictWhy
A prime forwards a government drawing marked Distribution Statement D.CUIQuestion 1. CTI by definition; the distribution statement is the marking.
A prime sends its own drawing for a military aircraft bracket. No banner, but the PO cites DFARS 252.204-7012.Treat as CUIQuestion 2. The clause makes it covered defense information. Ask the prime to mark it; keep handling it as CUI whether or not they do.
A drawing for a food-processing conveyor part, under an NDA, no government contract anywhere in the chain.Not CUIQuestion 5. Proprietary, protected by the NDA. Handle it well, but 800-171 is not triggered.
A catalog fastener to a public standard (NAS, AN, MS) for a military customer.Not CUIPublished standards are public. A commercial-item drawing does not become CTI because the buyer is DoD.
The CNC program and setup sheet you wrote from a CUI drawing.DependsShop IP by default, not CUI. It may be CUI if the contract designates contractor-developed data or the program embeds the controlled geometry. Your FAI package and CMM data, which reproduce the drawing's characteristics, are the derivatives to treat as CUI.
A drawing with an ITAR warning from a commercial customer building a product for export, no federal contract.Export-controlled, not CUIQuestion 4. ITAR's U.S.-person and licensing rules apply in full; the CUI program does not, because no federal contract flows it.
An old drawing stamped FOUO, nothing else.Treat as CUIFOUO is a retired marking that meant "controlled." Ask the owner to re-mark or decontrol; until then it is controlled.
A marked CUI drawing that the buyer emailed to you in the clear.CUIHow it arrived does not change what it is. Store it correctly on receipt and give the sender a secure channel for next time.
A sketch with the note "for a Navy program" and no other information.AskQuestion 3. Handle as CUI while you wait for a written answer. Do not forward it to a sub-vendor in the meantime.
A MIL-SPEC or AMS specification you bought from the publisher.Not CUIPublished standards are public documents, even when they govern controlled parts. The drawing that invokes them may still be CUI.

06Unmarked but Suspicious: What to Do

The gray zone is a print with no markings that plainly belongs to a military program: a landing-gear fitting, a missile canister bracket, a housing whose title block names a defense prime. The people who created it were required to mark it if it is CUI, so its arrival unmarked means one of three things: it is genuinely uncontrolled, the marking was dropped somewhere in the chain, or the sender does not know. You do not have to guess. Do four things:[3][4]

1
Handle it as CUI now
Put it in the controlled environment on receipt. Downgrading later costs nothing; upgrading after it sat in a shared inbox for a week is an incident.
2
Ask in writing
"Please confirm the CUI status and distribution statement for drawing 1234567 rev C, and whether DFARS 252.204-7012 applies to this order." Keep the reply with the job.
3
Hold the flow-down
Do not send it to heat treat, plating, or a second-op shop until the answer comes back. If it is CUI, those vendors need to be 7012-compliant and the marking must travel with it.
4
Quote the handling
If the answer is "yes," the job carries secure-handling cost: controlled storage, restricted personnel, vetted sub-tiers, and NSA-standard destruction at the end. Price it, do not absorb it.
Why the safe default is safe
Nothing in the CUI rules penalizes a contractor for protecting information that turns out to be uncontrolled. Everything in them penalizes the reverse. That asymmetry is the whole argument for "handle it as CUI until told otherwise," and it is the posture C&W applies to any unmarked print that looks like defense work.

07What a "Yes" Obliges: Storing, Sending, Sharing, Destroying

Once a drawing is CUI, four sets of rules attach to it. The first is the one everybody has heard of; the other three are where most real-world slips happen.[3][6][7]

Storing: the NIST SP 800-171 environment

CUI may live only on systems that meet NIST SP 800-171: access limited to authorized users, multi-factor authentication, encryption, logging, and the rest of the 110 requirements that CMMC Level 2 verifies. In practice that rules out personal phones, consumer cloud drives, unencrypted USB sticks, and the front-office PC that also runs the accounting package unless it is inside the assessed boundary. Paper counts too: prints on the floor stay in controlled areas, go face-down or into a locked cabinet at the end of the shift, and are not photographed by visitors.

Sending: encrypted, never a public upload

CUI moves only over channels that protect it in transit, which for DFARS 7012 means FIPS-validated encryption. Plain email is out. So is a public web-upload form, however convenient, because the shop cannot control where that file lands. C&W accepts controlled technical data only through a U.S.-hosted secure channel we set up with the customer; the ITAR page explains how to start one. If a buyer emails a marked print anyway, the shop's obligation is to store it correctly on receipt and steer the next transmission to the secure channel.

Sharing: people and sub-tiers

Access is limited to people who need it for the job. When the data is also export-controlled, which describes most CTI, those people must be U.S. persons unless a license says otherwise, and that includes the plating vendor's estimator who receives the drawing to quote a finish. Sub-tier suppliers who touch the data must themselves meet DFARS 7012, the marking must travel with the file, and they need the same secure channel. A shop that sends a controlled print to an unvetted finisher has just made that finisher's inbox part of the incident.

Destroying and reporting

At the end of the job, CUI is returned or destroyed so that it is unreadable, indecipherable, and irrecoverable, the standard set in 32 CFR 2002.14, using a method approved for classified material. That last part surprises people: an ordinary office cross-cut shredder does not qualify. For paper, DoD points to shredders on the NSA/CSS Evaluated Products List, which cut to particles no larger than 1 mm × 5 mm under NSA/CSS Specification 02-01, the same size required for classified paper up to Top Secret, or to pulping, pulverizing, or disintegration equipment on that list. A typical office cross-cut machine leaves pieces around 4 × 40 mm and misses the standard by a wide margin. For drives, USB media, and any controller or backup that holds CUI (the drawing, the model, an inspection package, or a program that embeds controlled geometry), the references are NIST SP 800-88 (purge or destroy, never a quick format) and NSA/CSS Policy Manual 9-12 for the specific method; solid-state media cannot be degaussed, so physical destruction on listed equipment is usually the answer. If in-house equipment does not meet the standard, use a destruction vendor that certifies to it and keep the certificate of destruction with the job record. C&W handles this in-house: controlled paper is destroyed on site in a high-security, NSA/CSS-approved shredder, so CUI never leaves the building to be shredded. If a suspected compromise happens, DFARS 7012 requires reporting it to DoD within 72 hours through the DoD Cyber Crime Center (DC3), which now runs the defense industrial base incident-reporting portal that DIBNet used to, and which still requires a DoD-approved medium-assurance certificate to file. Compliant shops obtain that certificate before they need it.

08What Is Not CUI (and the Cost of Over-Marking)

The other failure mode is quieter and more expensive: marking everything. A drawing is not CUI when it is your company's own commercial design, a customer's proprietary print outside any federal contract, a published standard, anything approved for public release, or plain business information such as pricing and delivery. Those deserve normal confidentiality, not the CUI machinery.[1]

Over-marking has real costs. It pushes secure-handling premiums onto parts that do not need them, it dilutes the markings that matter so that people stop reading them, and it is technically a mis-marking: only the designating agency, or a contractor acting under a contract that directs it, may apply a CUI marking. A title-block template that stamps every drawing "CUI" is not compliance; it is noise. The test in section 04 is deliberately narrow so that a "yes" means something.

09A Buyer's Checklist

If you are sending drawings to a supplier, the fastest way to get correct handling is to make the answer obvious before the file leaves your system. Put these in the RFQ or the PO:

State the status
"This drawing is CUI//SP-CTI, Distribution Statement D" or "This drawing is not CUI and is not export-controlled." One sentence saves a week of email.
Include the clauses
If DFARS 252.204-7012 applies, put it on the PO along with 7019/7020 (NIST assessment) and, where required, 7021 (CMMC). Suppliers price against the clause list.
Name the jurisdiction
USML category or ECCN, or "EAR99," so the shop knows whether U.S.-person restrictions apply. Do not stamp "ITAR" defensively on a part that is not.
Send it securely
Use the supplier's secure channel or your own encrypted transfer. Never a public upload form, and never a plain email attachment, even for the quote.
Check the supplier
Ask for their SPRS score or CMMC status, DDTC registration if USML, and JCP DD-2345 if you will send DoD-origin data. C&W's are on the certifications page.
Say what happens after
Return or destroy at job end, whether contractor-developed files (programs, fixtures, inspection data) count as CUI under this contract, and what the supplier may retain for repeat orders. Silence here becomes a question at the next audit.
1CUI program: Executive Order 13556; 32 CFR Part 2002 (Controlled Unclassified Information); NARA CUI Registry, categories "Controlled Technical Information" and "Export Controlled."
2Export control: ITAR, 22 CFR Parts 120–130 (technical data at § 120.33); EAR, 15 CFR Parts 730–774.
3Contract clause: DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (definitions of "covered defense information" and "controlled technical information"; 72-hour reporting); DFARS 252.204-7019/-7020 (NIST SP 800-171 assessments) and -7021 (CMMC).
4DoD implementation: DoDI 5200.48, Controlled Unclassified Information (marking, designation indicator, legacy FOUO); DoDI 5230.24, Distribution Statements on DoD Technical Information.
5Marking: DoD CUI Program marking guidance (banner, category markings CUI//SP-CTI and CUI//SP-EXPT, designation indicator); DoDD 5230.25 export-control warning notice.
6Safeguarding: NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations; CMMC, 32 CFR Part 170.
7Destruction and reporting: 32 CFR 2002.14(f)(3) (CUI destruction: NIST SP 800-88 and NSA/CSS PM 9-12, or any method approved for classified information); NSA/CSS Specification 02-01 and the NSA/CSS Evaluated Products List for high-security cross-cut paper shredders (1 mm × 5 mm); NSA/CSS Policy Manual 9-12, Storage Device Sanitization; NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization; DoDI 5200.48 (DoD CUI destruction); DoD Cyber Crime Center (DC3) / DCISE cyber incident reporting portal (successor to DIBNet).

Have a controlled drawing to quote?

C&W holds a current CMMC Level 2 self-assessment in SPRS, is ITAR-registered and JCP-certified, and accepts CUI only through a U.S.-hosted secure channel. Ask us for one before you send the file.