CMMC is vast and complex, but when you drill down to the heart of it, it's all about one thing: properly securing CUI.
And yet that, in and of itself, is a problem.
All CUI needs to be marked, which means if you receive CUI from your agency or prime, it needs to be properly marked. And it means if you produce CUI, you need to mark it properly yourself.
How do you know what is and isn't CUI, and how do you mark it properly? What happens if you get it wrong?
All of this is possibly one of the most confusing aspects of CMMC, which is really saying something given how complex the rest of the framework is. We'll do our best to help you navigate CUI marking here today, but if you have any further questions, don't hesitate to reach out to ask.
BLUF - Bottom Line Up Front
CMMC centers on proper protection of CUI. All CUI must carry clear marks and a first page designation block with controller, category, distribution rule, and a contact. Two types exist: Basic and Specified; Specified need extra controls and an agency tag (CUI//SP-xxx). Email, files, and devices need clear marks. Overmark and undermark create scope, cost, and legal risk. Origin agency can remove control for some CUI.
What is CUI?
CUI is Controlled, Unclassified Information. It's information that needs to be secured against leaks or intrusion, because it could have some negative repercussions if an adversary got hold of it. The legal definition, as described by NIST, can be found here.

There are 125 different categories of information that can be considered CUI. These range from water assessment data to bank secrecy information to national park system resources to nuclear propulsion information, and much more.
CUI comes in two forms: Basic and Specified. Basic is for information that needs to be controlled to a baseline level as outlined in things like CMMC, or more specifically, NIST SP 800-171.
Specified is a little trickier. CUI Specified is any sort of CUI that is a bit more sensitive and a bit more important than normal, basic CUI, but which isn't quite sensitive enough to warrant being fully classified. Each different category of Specified CUI has a designated agency in charge of it, and that agency can put added security controls on top of that CUI. This means certain kinds of CUI have stricter labeling rules and stricter handling rules than your basic, everyday CUI.
We go into a lot more detail on this subject here, so check out that post for further resources if you need it.
Why Does CUI Need Marking?
CUI needs marking so the people and systems that handle it know how to handle it properly.
Broadly speaking, you will have a different way of handling each type of information you need to handle. Simple, non-controlled information can be handled according to your normal company policies and procedures. FCI can be handled according to secure procedures at a Level 1 or other low-level security tier. CUI Basic needs to be handled at the CMMC Level 2 degree of security or higher. CUI Specified needs to be handled through systems that achieve higher levels of security according to the specifics of the type of CUI.
If you're handed a piece of information, some kind of document or schematic, which system do you put it through to get it to its destination?
That's where marking comes in. If there's no marking, it's not controlled information. If there is marking, it's handled according to its marking.

This is why marking is so important; without it, you'd have no way of knowing how sensitive a given document is and how to handle it, which could lead to sending very sensitive information through unsecured public systems, risking a data loss.
How CUI is Marked
Marking CUI is simple.

First, you start with the document you know needs to be marked. This will generally be something you've created, since if it was given to you, it should be marked already by whichever agency or contractor made it.
Then, you check the rules. Cross-reference the document and its CUI type with the National Archives ISOO CUI Registry, 32 CFR Part 2002, DoD Instruction 5200.48, DFARS 252.204-7012, NIST SP 800-171 R2, NIST SP 800-172, and, if it's CUI Specified, the guidance of the agency responsible for it.
You know, easy stuff.
Here's the thing: this is the simplified version. Marking CUI changed a lot with 2010's Executive Order 13556. Prior to that EO, there were over 100 different marks, including everything from For Official Use Only to Sensitive but Unclassified to Law Enforcement Sensitive to a whole array of agency-specific classifications.
It's enough to make you appreciate just having to mark CUI Basic or CUI Specified.
Okay, enough beating around the bush.
Step 1: Check for Specifics
The first thing you need to do is understand what category your information falls into.

This is a little easier than it sounds. You should know more or less what industry you're working in (if you aren't working with National Parks, you probably aren't dealing with National Parks information, you know?) and you can then cross-reference that with the DoD CUI Registry.
This will help you determine if the information is controlled under specific requirements, or if it's CUI Basic.
Step 2: Understand Marking Requirements
All CUI documents need to be marked with a banner and a footer. These go at the top and bottom of every page of any CUI document.

This applies to the full document. If you have generated a 100-page PDF with 99 pages of public information, and one table on one page that contains CUI, the entire document must be marked CUI.
The top and bottom of every page should have a large, bold marker saying CUI. Alternatively, you can use CONTROLLED.
Optionally, you can include the category of the CUI for CUI Basic. For example, General Critical Infrastructure Information is CUI Basic, with the abbreviation CRIT. You can mark the document as CUI//CRIT for clarity.
This demonstrates an important detail: the double slash. This is used to apply multiple labels and is essential for CUI Specified.
CUI Specified needs the label for the category of the specified group. For example, Naval Nuclear Propulsion Information is Specified under NNPI, so the mark would be CUI//SP-NNPI.
If more than one category applies, they should all be listed after SP-, and divided by a single slash. Something hypothetical that relates to naval nuclear propulsion and export-controlled information might be marked with both NNPI and EXPT, so it would be CUI//SP-EXPT/NNPI.
For specified CUI, you will also need a line at the bottom of each page outlining the agency or department with control over the information. That information can be found in the CUI registry. This is also where you can reference any documents that outline the specific controls for each type of CUI, if they exist.
Finally, each document needs a CUI Designation Indicator Block on the first page. This only needs to be on that first page, but it does need to exist. This block includes:
- Controlled by: The organization that controls the CUI, which could be a DoD component, a contractor, or whatever other organization created the CUI.
- CUI category: The abbreviation for the category, like NNPI or CRIT.
- Distribution Statement (or Limited Dissemination Control): Some documents will have one of five distribution statement letter indications, A through E. This categorizes how the CUI can be distributed, according to this document. Other CUI will be marked with a Limited Dissemination Control, which can include designations like Federal Employees and Contractors Only (FEDCON) or Display Only. See this document for more information.
- POC: The Point of Contact for the CUI; this is a specific person's name and phone number, who created the document.
A designation block would therefore look like:
Controlled by: OUSD(I&S)/IAP
CUI category: BUDG
Distribution statement: B
POC: John Brown, 703-555-0135
For documents with limited dissemination lists, you will need to create that list for the document as well.
Step 3: Mark the Document
Apply your markings according to what's required for the document you've created.

For longer documents, particularly those where only specific sections are CUI, you can use portion markings for those sections. If you use them, every section that is CUI must be marked, and no sections that are not CUI should be marked. It only works for clarity if it's clear, after all. Note: you do not apply a CUI portion marking to the CUI designation indicator block.
What About Other Forms of CUI?
Certain kinds of information can't just be marked with a header and footer. These have their own requirements.

A common one is email. Emails that include CUI should be marked with a banner at the top, and possibly the label CUI in the subject line. They can also include the designation block in the body of the email.
One issue throughout many defense contractors is just blanket labeling every email, such as by using a template or by adding the information to an email signature. This is inappropriate, for reasons we'll get to in a moment.
You might also encounter things like USB drives that themselves contain CUI. The documents on the drive need to be marked, but also the device itself needs to have a CUI label applied to it.
Who Applies CUI Markings?
CUI is marked by the agency that creates it. Most of the time, this is a federal agency or potentially a prime contractor authorized to create CUI.

Many contractors in the DoD ecosystem may be authorized to handle and process CUI, but not to create it; likewise, many of those that do create CUI are doing it simply through creative derivatives of CUI handed to them.
The Problems with Improper Marking
One of the biggest issues in CMMC right now is the confusion surrounding CUI marking. Many, many contractors end up over-marking (such as with the email example above), which can cause serious issues.

Overmarking, on its face, doesn't seem like a problem. If a document is marked CUI but there's nothing really sensitive in it, does it really matter? Over-securing documents doesn't hurt… does it?
The real problem is in scoping and boundaries.
If you have people in your organization marking every email they send as CUI, then you have a lot of emails that need to be handled according to CUI regulations, and that can be a serious organizational and operational burden. It can also be expensive.
The related issue is in softening security through overfamiliarity. When a lot of otherwise-meaningless documents are marked CUI, people who handle them start to treat it as a meaningless label, and don't take CUI regulations seriously. They might then send real CUI to places they shouldn't, because so much has been given the label that it has lost its meaning.
The flip side is undermarking. If legitimate CUI is not marked properly, it can easily be mishandled, and that mishandling can come with serious consequences.
We're talking about individual responsibility, FCA liability, breach of contract, loss of authorization, and more.
Can CUI Marks be Removed?
In a sense. Not all CUI is CUI forever; some can be decontrolled, such as when the nature of the information changes, or when the controlling laws or agencies change. In these cases, the decontrol process occurs.

Ideally, the decontrol process happens frequently, because the government wants to keep as little information controlled as possible. The larger the library of controlled information, the harder it is to protect.
For the most part, this won't be your job; it'll be the job of the agency that originated the information. Refer to their guidance when you have specific questions.
Ready for More CMMC?
Here at Ignyte, we strive to make complex frameworks like CMMC as understandable and digestible as possible. We built the Ignyte Platform as a way to make compliance itself as simple and easy as possible, and part of that is through education. We're always available to answer questions, and our blog is full of useful information on CMMC and more.

To learn more about how we can help you with all things CMMC, drop us a line. Whether it's a demo for the platform itself, a simple discussion, or a request for a topic you'd like us to cover, we're always receptive.
Max Aulakh is a distinguished Data Security and Compliance leader, recognized for implementing DoD-tested security strategies and compliance measures that protect mission-critical IT operations. His expertise was shaped in the United States Air Force, where he was responsible for the InfoSec and ComSec of network hardware, software, and IT infrastructure across global classified and unclassified networks. He also developed strategic relationships with military units in Turkey, Afghanistan, and Iraq. After his tenure with the USAF, Max played a pivotal role in driving Information Assurance (IA) programs for the U.S. Department of Defense (DoD). As a Senior Consultant for a leading defense contracting firm, he led a team that ensured data centers met Air Force Level Security audits for regulatory requirements like HIPAA, SOX, and FISMA. Currently, as the CEO of Ignyte Assurance Platform, he is at the forefront of cyber assurance and regulatory compliance innovation, catering to defense, healthcare, and manufacturing sectors. Max is also an esteemed speaker, having presented at several conferences on topics including cybersecurity GRC, medical device security, and cybersecurity perspectives in vendor management. You can follow him in LinkedIn here.