Last reviewed: June 29, 2026
Markings are a signal, not the whole system
CUI markings, contract legends, distribution statements, export-control warnings, proprietary notices, privacy labels, and agency handling instructions are important. They tell authorized holders that information has handling rules. But government-contracting teams know that real-world data does not always arrive perfectly labeled.
A contractor may receive unmarked technical data, misdirected agency emails, draft procurement information, personal information in attachments, export-sensitive drawings, system vulnerability details, internal government deliberations, source-selection information, or proprietary subcontractor data. Waiting for a perfect label can create risk.
The better approach is to use markings as one input in a broader intake and escalation process.
Why contractors cannot rely only on labels
Contractors should not rely only on markings because:
- information may be CUI even if it was not marked correctly;
- agency personnel may use legacy or inconsistent markings;
- contract attachments may impose handling duties independent of a banner marking;
- privacy, export-control, procurement-integrity, or proprietary restrictions may apply without a CUI label;
- information created by the contractor during performance may become protected even before the agency marks it;
- subcontractors may strip or alter legends during file transfer;
- cloud tools and AI tools may remove context; and
- incident response often requires fast decisions before classification is fully resolved.
This does not mean contractors should invent CUI categories or override the agency. It means they should protect questionable information conservatively and ask for clarification when necessary.
Contract clauses and agency instructions
Contract terms can impose safeguarding obligations even when markings are imperfect. Contractors should review FAR and DFARS clauses, agency supplements, statements of work, DD Forms, CDRLs, security attachments, data rights clauses, privacy clauses, IT requirements, and customer instructions.
If the contract says certain data must be stored only in an approved environment, encrypted in transit, restricted to U.S. persons, reported if compromised, or returned at closeout, the contractor should follow that term even if each file is not individually labeled.
Sensitive categories that may require escalation
Contractors should train personnel to escalate information that appears to involve:
- CUI or potential CUI;
- FCI;
- export-controlled technical data;
- personally identifiable information;
- protected health information;
- education records;
- financial or tax information;
- law-enforcement or investigative information;
- source-selection or procurement-sensitive information;
- proprietary contractor or subcontractor information;
- vulnerability, exploit, or system-security information;
- classified spill indicators;
- agency deliberative or predecisional materials; and
- contract performance information that could create operational security concerns.
Safeguarding expectations even when information is not marked CUI
Not every sensitive document is CUI. But information may still require safeguarding under contract terms, privacy law, export-control law, procurement rules, trade-secret duties, NDAs, agency policy, or responsible business practice.
For example, a contractor may receive unmarked pricing data from a teammate, resumes with personal information, a draft agency acquisition plan, a vulnerability report, or proprietary vendor architecture diagrams. Even if the information is not CUI, unrestricted sharing or storage in unapproved tools may be inappropriate.
Practical intake and escalation workflow
A workable workflow should be simple enough for program teams to use:
- Identify the source. Government, prime, subcontractor, vendor, employee, public website, incident-response collection, or third party.
- Check visible markings. CUI banner, distribution statement, export marking, proprietary legend, privacy label, contract number, agency instruction, or classification marking.
- Review contract context. Does the contract involve CUI, FCI, export-controlled data, PII, agency records, system access, or special handling?
- Assess content sensitivity. Does the information reveal technical designs, vulnerabilities, personal data, procurement strategy, operational details, or nonpublic government information?
- Apply temporary safeguards. Store in an approved restricted location, limit access, avoid public tools, and prevent external sharing while status is resolved.
- Escalate. Ask the contract manager, security lead, privacy lead, export-control lead, counsel, prime, or contracting officer as appropriate.
- Document the decision. Record how the information was classified, where it may be stored, who may access it, and whether flowdowns or notices are needed.
When to ask the government
Contractors should ask the contracting officer, contracting officer's representative, security office, or agency data owner for clarification when:
- documents appear to contain CUI but are unmarked;
- markings conflict with contract terms;
- data categories are unclear;
- subcontractors need access and flowdown scope is uncertain;
- cloud, AI, offshore, or external support use is proposed;
- information may be export-controlled;
- a possible classified spill occurred; or
- the contractor cannot determine whether a reporting obligation exists after an incident.
Questions should be specific. Instead of asking “Is this sensitive?” ask: “Does this attachment contain CUI, export-controlled technical data, Privacy Act records, or other information requiring safeguarding or dissemination controls under the contract? If so, what markings and handling requirements should apply?”
Do not overmark, but do not underprotect
Overmarking can create cost, confusion, and unnecessary barriers to performance. Underprotecting can create breach, contract, enforcement, and mission risk. The right balance is disciplined intake, conservative temporary handling, timely clarification, and documented decisions.
Educational content only. This page provides general legal information for educational purposes. It does not constitute legal advice and does not create an attorney-client relationship. Contractors should consult qualified legal counsel for contract-specific information-handling obligations.