Most CUI problems on civilian contracts are not sophisticated breaches. They are a file emailed without a banner marking, a legacy "FOUO" stamp nobody decontrolled, or a shared drive that anyone in the company can open.
Marking and handling is the part of CUI that is already expected of you today, and it does not depend on any rule that is still pending. That distinction matters right now.
In the past week, the Department of War suspended CMMC Phase 2 requirements while the FAR Council kept moving on government-wide CUI rules. Reasonable people read that news and conclude the whole subject is on hold. It is not. CMMC is a defense program. The obligation to protect controlled unclassified information comes from a different place, applies across the executive branch, and is unchanged by a Department of War pause.
What Governs CUI on a Civilian Contract Today?
Three things, and it helps to keep them separate.
- 1
The executive branch CUI program
Established under Executive Order 13556 and implemented by the National Archives at 32 CFR Part 2002. It tells agencies how to designate, mark, safeguard, share and decontrol CUI, and to flow those handling requirements to non-federal partners through agreements and contracts. The categories of CUI are published in the NARA CUI Registry.
- 2
Your contract
This is the operative document. Civilian agencies impose CUI terms through agency supplements, special contract requirements, statements of work and security attachments rather than one uniform government-wide clause. GSA published an FAQ in July 2026 on its own Part 540 provision and clause, and it is explicit that CMMC is the Department of War's program for certifying defense contractor networks. If you sell through a GSA vehicle, read your specific solicitation and task orders rather than assuming.
- 3
FAR 52.204-21
Basic Safeguarding of Covered Contractor Information Systems is final, in force, and broadly applicable. It covers Federal Contract Information, a lower tier than CUI, and sets fifteen basic safeguarding requirements. If a contract contains CUI, 52.204-21 is a floor, not a ceiling.
Is the FAR CUI Rule a Requirement Yet?
No. The FAR CUI rule remains a proposed rule.
It would create a standardized government-wide approach to identifying CUI in solicitations, applying NIST SP 800-171 to contractor systems that process CUI, and reporting CUI incidents on a short timeline. As published in proposed form the reporting window is eight hours, which is aggressive by any standard, but proposed text changes between publication and a final rule with some regularity.
Treat it as a planning document, not a compliance obligation. Nothing in it is enforceable against you until a final rule is issued and the clause appears in your contract. What is worth noting is the direction of travel: the FAR Council is moving forward on CUI while the defense-side certification program pauses, which suggests the civilian side is where the next round of change lands.
What Does Correct CUI Marking Look Like?
The mechanics are more mundane than people expect. NARA's CUI Marking Handbook is the reference, and the basics are these.
- 1
The banner marking
Every page of a CUI document carries a banner at the top center. At minimum it reads CUI. For CUI Specified, where a law or regulation imposes specific handling controls, the banner adds the category separated by double forward slashes, for example CUI//SP-CTI. Any limited dissemination control comes last, for example CUI//SP-CTI//FED ONLY.
- 2
The designation indicator
Somewhere on the first page, usually a block in the lower left, the document identifies who controlled it and under what authority. A typical block includes a Controlled by line naming the agency and office, the CUI category, any limited dissemination control, and a point of contact.
- 3
Portion markings
These are paragraph-level markings such as (CUI). They are optional under the CUI program unless the designating agency requires them. Do not add them on your own initiative if the agency has not asked.
- 4
Legacy markings
FOUO, Sensitive But Unclassified and Law Enforcement Sensitive are legacy designations. Do not create new documents with them. If you receive legacy-marked material, protect it and ask the agency how it should be handled, because you cannot remark or decontrol it yourself.
One point contractors get wrong constantly: you generally do not designate CUI. The government does. Your job is to mark what you create under the contract according to the agency's guidance, and to carry markings forward when you incorporate agency material into your own deliverables.
How Should CUI Be Stored, Sent and Destroyed?
Handling is where the day-to-day risk sits.
- 1
Access
CUI is shared on the basis of a lawful government purpose. There is no clearance and no formal need-to-know process, which means the discipline has to come from you. If everyone in your company can open the folder, you have not restricted access.
- 2
Storage
Keep it in a controlled environment: named folders with restricted permissions, not a general company drive and not a personal cloud account. Physical documents go in a locked container or a controlled area when not under someone's direct control.
- 3
Transmission
Encrypt in transit. Agencies commonly expect FIPS-validated cryptography and many will say so in the contract. Do not post CUI to a public-facing website, an unsecured file transfer service or an unreviewed collaboration tool. Send it inside an encrypted channel and label the message so the recipient knows what they are receiving.
- 4
Destruction
Destroy so that reconstruction is not reasonably possible. Shred paper. Sanitize media rather than simply deleting files.
- 5
Decontrol
Only the designating agency decontrols CUI. If you think a document no longer needs protection, that is a question for the contracting officer, not a decision for you.
Is There a Civilian Certification I Need to Get?
No. There is no civilian equivalent of CMMC, and no certification body issues a CUI credential for civilian agency work. Anyone offering to certify you on the civilian side is describing something that does not exist.
What civilian agencies rely on today is the contract itself, your representations, and the government's ability to audit and enforce. Where NIST SP 800-171 is invoked in a civilian contract it typically arrives through the contract terms and is verified by self-assessment and by the agency, not by a third-party assessor. That is a lower ceremonial bar and a real legal one, because misstating your posture in a proposal is False Claims Act exposure regardless of which agency you are selling to.
What Should We Do in the Next 90 Days?
Start with an inventory question rather than a technology question. Do we receive or create CUI at all, on which contracts, and where does it live?
- 1
Confirm your contract terms in writing
Read the actual security language in your awards rather than working from memory.
- 2
Map the systems and people that touch CUI
Identify where controlled information actually lives and who can reach it.
- 3
Fix the marking practice
Apply correct banner markings and designation indicators on the documents you produce.
- 4
Restrict access
Lock down the folders that hold CUI so access follows lawful government purpose, not a company-wide default.
- 5
Turn on encryption in transit
Then read your contract's incident reporting language and make sure someone knows what number to call and how fast.
None of that requires the proposed FAR rule to be final. All of it makes the eventual final rule a smaller lift.
Frequently Asked Questions
Does the CMMC pause mean civilian contractors can stop worrying about CUI?
No. CMMC is a Department of War certification program. Civilian agency CUI obligations come from Executive Order 13556, 32 CFR Part 2002 and the terms of your individual contract, none of which are affected by a defense-side pause. If anything, the FAR Council has kept moving on government-wide CUI rules during the same period.
Do I have to mark documents as CUI myself?
You mark what you create under a contract according to the agency's guidance, and you carry forward markings on agency material you incorporate. Designating information as CUI in the first place is an agency function, not a contractor function. If it is unclear whether a deliverable contains CUI, ask the contracting officer in writing.
What is the difference between CUI Basic and CUI Specified?
CUI Basic is protected under the general standards of the CUI program and its banner marking is simply CUI. CUI Specified is covered by a law, regulation or government-wide policy that imposes particular handling controls, and its banner includes the category marking. The NARA CUI Registry identifies which categories are Specified.
Is the FAR CUI rule in effect?
No. It remains a proposed rule. Until a final rule is issued and the resulting clause appears in your contract, its terms, including the proposed eight hour incident reporting window, are not enforceable against you.
Can I still use FOUO markings?
No new documents should be created with FOUO or other legacy markings. If you receive legacy-marked material from an agency, protect it and ask the agency how it should be handled. You cannot remark or decontrol government information on your own.
Is there a certification that proves my company handles CUI correctly on civilian contracts?
There is not. No certification exists on the civilian side. Compliance is established through your contract terms, your own assessment and documentation, and government oversight.
Not certain which of your civilian contracts actually contain CUI terms? Pull the security language from your three largest active awards and run the gap assessment so you know exactly where you stand against NIST SP 800-171.
Run the Gap Assessment