compli.ai
From the blog

Who Is Responsible for Protecting CUI? (And Who Can Decontrol It)

Everyone who lawfully handles CUI is responsible for protecting it, but only the designating agency can decontrol it. Here are the roles per 32 CFR 2002 and DoDI 5200.48 — for quiz-takers and contractors alike.

Short answer: Every authorized holder is responsible for protecting CUI — that means any individual or organization that lawfully possesses or has access to Controlled Unclassified Information, including federal employees, contractors, and their subcontractors. Protecting CUI is not one office's job; it travels with the information to whoever is holding it. Decontrol is different. Only the designating agency (the federal agency that originally marked the information as CUI), or a specific official that agency has authorized in its own policy, can decontrol it. A contractor cannot decide on its own that CUI is no longer CUI. Those two rules, that everyone protects and only the originator decontrols, are the whole answer, and the rest of this post explains the roles behind them.

If you are studying for a Department of War (DoW) CUI training quiz, the two lines above are what you need. If you are a contractor trying to understand your actual obligations, keep reading: the "authorized holder" duty is the one that lands on your company, and it comes with specific safeguarding requirements under DFARS and NIST SP 800-171.

The short version, in one table

QuestionAnswerAuthority
Who is responsible for protecting CUI?Every authorized holder — anyone who lawfully possesses or accesses it (agencies, contractors, subcontractors, employees)32 CFR 2002; DoDI 5200.48
Who is responsible for marking CUI?The person who designates the information as CUI — generally the originating agency/office (the designator)32 CFR 2002.20
Who can decontrol CUI?The designating agency, or an official that agency authorizes in its CUI policy; the Archivist for records at NARA32 CFR 2002.18
Who is the government-wide Executive Agent for the CUI Program?NARA (through its Information Security Oversight Office, ISOO)32 CFR 2002
What is DoW's implementing instruction?DoDI 5200.48DoDI 5200.48

What "protecting CUI" actually means, and who does it

CUI is unclassified information that the government requires to be safeguarded or subject to dissemination controls under law, regulation, or government-wide policy. The government-wide rule that established the program is 32 CFR Part 2002, effective November 14, 2016, with NARA serving as the Executive Agent through its Information Security Oversight Office (ISOO). Inside DoW, the implementing instruction is DoDI 5200.48, originally issued March 6, 2020, which sets DoW policy for marking, handling, decontrolling, and destroying CUI.

The key concept for responsibility is the authorized holder. An authorized holder is any individual, agency, organization, or group of users that is permitted to designate or handle CUI in accordance with the program. The rule assigns the protection duty broadly and deliberately: if you are lawfully holding CUI, you are responsible for protecting it. That is why the correct answer to "who is responsible for protecting CUI" is not "the CISO" or "the contracting officer" or "the originating agency" — it is everyone who handles it.

For a defense contractor, "protecting CUI" is not an abstraction. It means implementing the safeguarding controls in NIST SP 800-171 (currently Revision 2 for DoW contracts) on the systems that process, store, or transmit CUI, per the contract clause DFARS 252.204-7012. It also means the downstream obligations that come with that clause: maintaining a System Security Plan, reporting cyber incidents within 72 hours to the Department, and flowing the requirement down to subcontractors who will also handle the CUI. So the "authorized holder" responsibility, for contractors, translates directly into an 800-171 implementation program. We cover that implementation in depth in our NIST 800-171 compliance guide.

The roles that sit underneath "everyone"

"Everyone protects" is the right headline, but a few specific roles carry named responsibilities:

  • The designator (originating agency/office). Decides that a piece of information is CUI in the first place, applies the correct CUI banner marking, category markings where required, and a designation indicator identifying the originating agency. Marking responsibility sits with whoever designates the information — per 32 CFR 2002.20.
  • The authorized holder (which includes contractors). Protects the CUI in their possession, applies the required safeguarding and dissemination controls, and re-marks or challenges markings as appropriate. This is the responsibility that lands on your company.
  • The designating agency. The federal agency that designated the information. It sets the safeguarding and dissemination rules for its CUI and, importantly, holds decontrol authority. In DoW, the agency component that created the information plays this role.
  • NARA / ISOO (Executive Agent). Runs the program government-wide, maintains the CUI Registry of categories at archives.gov/cui, and issues implementing guidance.

CUI Basic vs. CUI Specified — why the "how" changes

Not all CUI is protected the same way, and this trips up contractors who assume a single handling standard.

  • CUI Basic is the default. It is handled per the uniform controls in 32 CFR 2002 and the CUI Program. The underlying law, regulation, or policy that made it CUI does not prescribe specific handling — so the standard baseline applies.
  • CUI Specified is CUI where the underlying authority does prescribe particular safeguarding or dissemination controls beyond the Basic baseline. When information is CUI Specified, those specific controls govern, and they can be more restrictive.

The responsibility to protect does not change between the two — every authorized holder still protects both. What changes is which controls apply. If you want a decision-tree approach to figuring out what in your environment is CUI and which flavor it is, see our companion guide on what counts as CUI.

Who can decontrol CUI — and who cannot

This is the second half of the question, and it is where searchers most often get the wrong answer.

Decontrol means removing the CUI status from information that no longer requires protection. Under 32 CFR 2002.18, agencies should decontrol CUI as soon as practicable once it no longer needs safeguarding or dissemination controls — unless doing so would conflict with the governing law, regulation, or government-wide policy.

The authority to decontrol belongs to the designating agency. Specifically:

  • The designating agency decontrols its own CUI. It may authorize specific personnel to do so through its own CUI policies — but that authorization has to come from the agency that designated the information.
  • Automatic decontrol can occur on a pre-determined date or event, or when the law, regulation, or policy that required control no longer applies, or when the agency releases the information to the public.
  • An authorized holder may request decontrol from the designating agency — but requesting is not the same as deciding. The holder cannot unilaterally strip the CUI status; the designating agency makes the call.
  • The Archivist of the United States may decontrol records that have been transferred to the National Archives, absent a specific agreement otherwise with the designating agency.

For DoW specifically, DoDI 5200.48 ties decontrol to the Department's process, and public-release review generally precedes decontrol — you do not decontrol first and figure out releasability later. Decontrol also does not automatically authorize public release; a separate releasability determination applies.

The line contractors need to remember: You protect CUI as an authorized holder, but you do not get to decontrol it. If you think a piece of CUI no longer needs protection, the path is to go back to the designating agency (usually via your contracting channel), not to remove the markings yourself.

Where CMMC fits

The reason all of this matters commercially is that protecting CUI is exactly what the Cybersecurity Maturity Model Certification (CMMC) program is built to verify. CMMC Level 2 maps 1:1 to the 110 requirements of NIST SP 800-171 Rev 2, the safeguarding controls that operationalize your "authorized holder" duty. If your contracts involve CUI, expect a CMMC Level 2 requirement, and the same control set that protects CUI is what an assessor will check. The Department has suspended CMMC Phase 2, the third-party assessment requirement that was scheduled to begin November 10, 2026, while it reviews the program. Phase 1 remains in effect: contracts can still require CMMC Level 1 and Level 2 self-assessments with affirmations in SPRS, and DFARS 252.204-7012 still requires all 110 NIST SP 800-171 Rev 2 security requirements. See our CMMC compliance overview for how the levels and assessment types work, and where the CUI scoping decisions drive your assessment boundary.

How Compli.ai handles the CUI responsibility problem

The hard part of protecting CUI is proving it across an assessment. Authorized-holder responsibility turns into a paperwork problem fast: which systems are in scope, which of the 110 controls are met, what evidence backs each one, and where the CUI boundary sits.

Compli.ai was built by compliance practitioners for exactly this, and it runs inside a SharePoint site in your own Microsoft 365 tenant, so the records of your CUI program stay inside the boundary you already defend. It keeps an inventory of the CUI you hold and how it reaches you, carries all 110 NIST SP 800-171 requirements with their SSP implementation statements, manages POA&Ms under the federal eligibility rules, computes a live SPRS score, and ties evidence to the 320 assessment objectives in NIST SP 800-171A. Instead of tracking your CUI-protection obligations in a spreadsheet, you track them against the assessment objectives an assessor will actually test.

For contractors ready to move from "we know we are responsible" to "we can prove it," book a demo to see how the artifacts come together.

FAQ

Who is responsible for protecting CUI?

Every authorized holder is responsible for protecting CUI — any individual or organization that lawfully possesses or accesses it, including federal agencies, contractors, subcontractors, and their employees. Protection responsibility travels with the information to whoever is holding it, not to a single designated office.

Who can decontrol CUI?

Only the designating agency (the federal agency that originally designated the information as CUI) can decontrol it, or an official that agency has specifically authorized in its CUI policy. Decontrol may also happen automatically on a pre-determined date or event. An authorized holder can request decontrol but cannot decide it unilaterally.

What DoD instruction implements the DoD CUI Program?

DoD Instruction (DoDI) 5200.48, "Controlled Unclassified Information (CUI)," implements the DoD CUI Program. It was originally issued March 6, 2020, and establishes DoW policy for marking, handling, decontrolling, and destroying CUI. It implements the government-wide rule at 32 CFR Part 2002.

Who is responsible for applying CUI markings and dissemination instructions?

The individual or office that designates the information as CUI is responsible for applying the correct markings and dissemination instructions — generally the originating agency or office (the designator). Markings include the CUI banner marking, any required category markings, a designation indicator identifying the originating agency, and any limited-dissemination controls.

Is a contractor an authorized holder of CUI?

Yes. A contractor that lawfully receives CUI under a contract is an authorized holder and is responsible for protecting it, typically by implementing NIST SP 800-171 controls on systems that handle the CUI, as required by DFARS 252.204-7012. The obligation flows down to subcontractors who will also handle the CUI.

What is the difference between CUI Basic and CUI Specified for protection?

Both must be protected by every authorized holder — the difference is which controls apply. CUI Basic follows the uniform 32 CFR 2002 baseline. CUI Specified follows the specific safeguarding or dissemination controls prescribed by the underlying law, regulation, or policy, which can be more restrictive than the Basic baseline.

Compli.ai is the tenant-resident CMMC and NIST SP 800-171 compliance platform for defense contractors that handle CUI. Program records stay in each customer's own Microsoft 365 tenant. Book a demo.