Controlled Technical Information in Manufacturing: What CTI Is and How to Protect It on the Shop Floor A controlled drawing leaves engineering. It lands on a machine-side workstation, gets copied to a USB drive for a backup, prints out as a paper packet for the second shift, and syncs to a shared folder nobody remembers creating. None of this happens maliciously. It happens because production needs the file fast, and nobody stopped to ask whether it required protection in the first place.

This is the everyday reality on shop floors supporting military or space programs. Controlled Technical Information, or CTI, is a specific category of Controlled Unclassified Information that applies to manufacturers working under defense or space contracts. But here's the catch: not every technical file tied to a defense job is automatically CTI.

This article covers how to determine whether shop-floor information qualifies as CTI, where it tends to hide in day-to-day operations, and how to protect it without grinding production to a halt.

Key Takeaways

  • CTI is technical data with military or space application under access, use, or dissemination controls—verify against the current contract.
  • Shop-floor CTI lives in CAD files, CNC programs, process sheets, test records, machine PCs, media, backups, and printouts.
  • Protect it with classification, least-privilege access, secure transfer, version control, training, and incident response.
  • Unclear markings: lock the file down, then confirm with the customer, prime, or contracting officer before sharing.

What Is Controlled Technical Information?

CTI is technical information with a military or space application that is subject to controls on access, use, reproduction, modification, performance, display, release, or dissemination.

According to the NARA CUI Registry, CTI is CUI Specified, marked CUI//SP-CTI, and authorized under DFARS 252.204-7012.

"Technical information" under this definition is broad. It includes:

  • Engineering drawings and associated parts lists
  • Specifications and standards
  • Process sheets and manufacturing instructions
  • Technical reports, test procedures, and technical orders
  • Data sets, models, and studies
  • Computer software, including source and executable code

The Two-Part Test

Before labeling anything CTI, run it through two questions:

  1. Does it have a military or space application? If the information relates to designing, building, testing, or maintaining a defense or space article, this box gets checked.
  2. Is it subject to a controlling authority? A law, regulation, contract clause, distribution statement, or government-wide policy has to actually impose access or dissemination restrictions.

Both conditions must be true. A part might be destined for a fighter jet, but if the drawing describes an off-the-shelf bracket with no restrictions attached, it likely isn't CTI.

CTI vs. CUI Basic and CUI Specified

CUI Basic applies when the authorizing law or policy doesn't spell out specific handling rules. CUI Specified applies when it does, and CTI falls into this second bucket. CTI therefore carries handling requirements beyond CUI Basic, including the distribution-statement requirement discussed below.

CTI Is Not the Same as ITAR

Handling category and export regime are separate questions, and mixing them up creates real compliance gaps. ITAR is an export-control regime under the Arms Export Control Act, governing the export of defense articles and technical data. CTI is a CUI handling category.

A single document might trigger both:

  • ITAR because it describes a defense article covered by the U.S. Munitions List
  • CTI because it also meets the CUI definition under a DoD contract

Treat these as separate determinations. A file cleared for CTI purposes isn't automatically cleared for export, and vice versa.

CTI versus ITAR handling category and export regime comparison

When in doubt, base classification on the source, the contract, the content, and the applicable authority. Don't rely on a single label someone applied three revisions ago.

Where CTI Appears on a Manufacturing Shop Floor

CTI doesn't stay put in engineering's document management system. It moves — and every stop along the way is a place it can leak, get copied, or get forgotten.

Common CTI-Bearing Files

  • CAD/CAM files and drawing packages
  • CNC programs and tool lists
  • Setup sheets and controlled work instructions
  • Inspection plans and test results
  • Process parameters and machine configuration files
  • Technical change notices

The Locations Everyone Forgets

The obvious spots are engineering workstations and shared drives. The overlooked ones cause the real problems:

  • Email attachments sitting in a machinist's inbox
  • Local downloads on a laptop nobody re-images
  • Printed binders left at the machine overnight
  • USB drives passed between programmers
  • Machine-side PCs running years-old operating systems
  • Personal cloud sync folders
  • Backup systems that never get purged
  • Archived folders from completed programs

Picture this: an engineer releases one controlled drawing. It gets emailed to a supervisor, printed for the floor, saved to a shared drive, copied to a USB stick for the CNC programmer, and backed up nightly. That's five copies from one file. Each one needs tracking until it's returned, destroyed, or formally decontrolled.

Copy control gets harder when the data starts on your floor. Manufacturing or test data your team generates under a defense contract may also need review if it relates to a military or space application. Not everything you create in-house is automatically CTI, but assuming it never is can be just as risky as over-classifying everything.

How to Determine Whether Shop-Floor Information Is CTI

Start with paperwork, not guesswork. Review the statement of work, data requirements list, handling clauses, and any prime-contractor instructions. Look for distribution statements and CUI markings already applied to the file.

Three-step CTI classification evidence review process diagram

A Repeatable Classification Checklist

Ask these four questions for any file in question:

  1. What article, system, or program does this information relate to?
  2. Does it have a military or space application?
  3. Is it required to design, build, test, operate, or maintain that item?
  4. Is access, use, or dissemination restricted by a controlling authority?

Understanding Distribution Statements

Per DoDI 5230.24, distribution statements supplement — not replace — CUI markings on DoD technical information:

Statement Meaning
A Approved for public release; unclassified, unrestricted
B U.S. Government agencies only
C U.S. Government agencies and their contractors
D DoD and DoD contractors only
E DoD Components only
F Distribution as directed by controlling DoD office

Statements B through F can apply to classified information too, so a distribution statement alone doesn't confirm CTI status. Confirm current DoD marking guidance rather than treating an unmarked file as automatically safe to share.

Ambiguous Cases Worth Knowing

  • A generic cutting-tool datasheet probably isn't CTI. The same datasheet embedded in a defense-program document showing controlled tooling parameters might be.
  • A standard machine manual is likely public. A program-specific machine configuration or process qualification record tied to that same machine may be controlled.
  • A CNC program can be CTI when it embodies restricted technical information for a defense or space part. That status depends on the program and its governing contract, not the file extension.

If a File Shows Up Unmarked

Treat the file as controlled until you get a clear determination:

  • Restrict access immediately
  • Don't forward it or upload it anywhere
  • Preserve the original source and context
  • Request clarification from the originator or contracting authority
  • Document the interim decision, source, related contract, who has access, and who owns reassessment

If a determination touches ITAR, EAR, classified information, or conflicting customer instructions, escalate to export-control or legal counsel. This isn't a call a machinist or IT administrator should make alone.

How to Protect CTI Without Slowing Production

Protection doesn't mean locking every machine behind a badge reader and grinding throughput to zero. It means building a controlled, traceable path for the file, one that's easier to follow than the workarounds people invent when security gets in the way.

Define the Boundary and Apply Least Privilege

Map every system that stores, processes, or transmits CTI:

  • Engineering workstations, file servers, and email
  • CAD/PLM systems and DNC servers
  • Machine-side computers and inspection stations
  • Backups, printers, and removable media

Then apply role-based access:

  • Give machinists access only to the programs and instructions needed for their assigned job
  • Separate engineering approval, production release, and execution privileges
  • Remove access immediately when someone changes roles or leaves the company

Control File Movement and Versions

Ad hoc email and personal cloud storage are how controlled files end up outside the boundary. Use authenticated, logged network paths instead — and make version control a security function, not just a quality one.

  • Require engineering sign-off before any file reaches production
  • Clearly flag the active revision and quarantine anything superseded
  • Prevent operators from grabbing an old file off a local folder by mistake

This is where CNC/DNC communication systems earn their keep. Controlled distribution tools that manage file status, permissions, and audit trails push the current approved file to production automatically, instead of relying on someone to remember which USB drive has the latest revision.

Controlink Systems LLC has built shop-floor automation and DNC communication tools since 1998 to connect engineering systems with machine controls in a tracked, repeatable way. That infrastructure supports these controls instead of forcing teams to work around them.

Physical Media and Baseline Safeguards

Printed drawings and removable media need the same discipline as digital files:

  • Store printed drawings in designated bins or cabinets, not left at the machine overnight
  • Track approved USB devices and encrypt them where feasible
  • Sanitize or destroy media according to documented procedures

Layer in baseline technical safeguards aligned with contract obligations and NIST SP 800-171 Rev. 3:

  • Unique accounts and multi-factor authentication where feasible
  • Endpoint protection, patching, and network segmentation
  • Audit logging across systems that handle CTI

Train everyone who touches this data — machinists, programmers, quality staff, and temps — on what to do if a file is misdelivered, copied without authorization, or lost. If exposure is suspected, preserve evidence and follow your reporting obligations.

A Practical CTI Protection Workflow for the Shop Floor

Five steps turn scattered good intentions into something repeatable.

  1. Inventory. Identify every CTI source, file type, system, machine, and archive. Map the flow from receipt through production, inspection, delivery, and eventual return or destruction.
  2. Classify and mark. Record the source marking and governing authority. Apply only markings your organization is authorized to use, and add internal handling labels where needed.
  3. Approve and release. Require engineering authorization before any file reaches the floor. Tie revision control to DNC distribution so operators always get the current approved version, not a manually copied one.
  4. Monitor and review. Audit access, transfers, removable media, and print activity. Reconcile your inventory against actual shop-floor practice periodically.
  5. Retain, return, or destroy. Follow contract instructions for completed work. Preserve required records, securely destroy unnecessary copies, and document the action.

Five-step CTI protection workflow from inventory through secure destruction

The practical goal is one traceable path that protects CTI while keeping production moving. When that path is easier than any workaround, employees follow it.

Frequently Asked Questions

How do I know if I have CUI?

CUI status comes from applicable law, regulation, contract terms, or customer instructions, not simply because information feels technical or sensitive. Review your source documents and ask the contracting authority when uncertain.

Is CUI the same as ITAR?

No. CUI is an information-handling designation, while ITAR is an export-control regime. A single document can fall under both and require overlapping controls.

What are the two types of CUI?

CUI Basic and CUI Specified. Specified CUI carries additional handling requirements set by its governing authority. CTI falls under CUI Specified, so verify current registry terminology before applying markings.

Are CNC programs and CAD files always CTI?

No. Determine whether the file relates to a military or space application and is subject to actual access or dissemination controls. Check the contract and any markings before assuming either way.

Where should CTI be stored on a manufacturing shop floor?

Only on approved, access-controlled, monitored systems within your documented security boundary, including machine-side computers, DNC servers, workstations, backups, and approved removable media.

What should a manufacturer do if CTI is sent without proper markings?

Restrict access and distribution immediately, preserve the file and its delivery context, and notify the originator or contracting authority for guidance. Follow your incident process if unauthorized access may have occurred.