What Counts as CUI for DoD Contractors? A Machine Shop's Guide to Identifying Controlled Data

Introduction

A drawing lands in your inbox. It looks like every other DXF file you've machined from for years. But this one supports a Navy contract, and somewhere in its title block or the email thread attached to it, there may be handling requirements you're expected to follow.

Many shops assume that if a job comes from a defense customer, everything tied to it must be Controlled Unclassified Information (CUI). That assumption is wrong, and it cuts both ways: some shops over-restrict harmless files, while others miss real obligations hiding in inspection reports, CNC programs, or supplier emails.

CUI status depends on the subject matter, the originating contract or authority, the markings, and the applicable handling rules, not simply on who the customer is.

This guide walks through a practical method for spotting likely CUI on the shop floor. You will see how to tell it apart from related categories like ITAR or proprietary data, and when to escalate before a file gets copied, emailed, or loaded onto a machine controller.

Key Takeaways

  • Safeguarding applies only under specific laws, regulations, or policies—not automatically from a defense connection.
  • Drawings, CNC programs, and inspection records may qualify only when a contract or authority identifies them as protected.
  • Basic and Specified CUI carry different controls; check the NARA CUI Registry and your contract.
  • Trace each file from its source through users, systems, suppliers, and disposal.
  • Treat CUI as separate from classified, FCI, ITAR, export control, and proprietary determinations.

What Is CUI and Why Does It Matter to a Machine Shop?

Controlled Unclassified Information is unclassified information the government has determined needs protection from unauthorized access, use, or disclosure because a law, regulation, or government-wide policy requires it. Under 32 CFR Part 2002, CUI excludes anything classified under Executive Order 13526. It also excludes a contractor's own information that never came from, or was never created for, a federal agency. That last point matters. "Unclassified" doesn't mean "public" or "unrestricted." A file can carry zero classification markings and still require controlled handling. Conversely, a file connected to a DoD program isn't automatically CUI just because of who's paying the invoice.

How CUI Reaches Your Shop

Most machine shops encounter CUI through:

  • Contract clauses and data-item descriptions
  • Government-furnished technical data
  • Statements of work with flow-down terms
  • Markings, banners, or distribution statements on drawings
  • Direct instructions from a prime contractor The National Archives and Records Administration (NARA) maintains the official CUI Registry, listing approved categories, markings, and handling rules. Always check current Registry entries and contract language rather than relying on secondhand summaries, since categories and requirements can change.

Where the Risk Actually Lives

For a machining operation, CUI risk shows up in ordinary places:

  • An unattended shop-floor terminal displaying a customer print
  • A USB drive used to move a CAM file between workstations
  • A backup that retains an old revision after a contract ends
  • A subcontractor with broader access than the job requires CUI rules can touch every stage of the information lifecycle—from receiving and programming through machining, inspection, storage, transmission, and secure destruction.

Seven-stage CUI information lifecycle for machine shop files

Common Types and Examples of CUI-Related Data

A file format never determines CUI status on its own. A PDF, a CAD model, a spreadsheet, or a CNC program becomes CUI only when its content, source, and governing authority say so. Two structural categories—CUI Basic and CUI Specified—determine how tightly that data must be handled.

CUI Basic

CUI Basic applies when the authorizing law or policy doesn't set specific handling instructions beyond the baseline controls in the CUI framework. Machine-shop examples that may fall here, when properly identified by the contract, include:

  • Technical drawings and process specifications
  • Manufacturing instructions
  • Inspection documentation
  • Engineering correspondence Don't treat CUI Basic as low-priority. Per the requirements your contract references, it still requires:
  • Defined access controls
  • Approved transmission methods
  • Proper storage and correct marking
  • Incident reporting
  • Secure destruction

CUI Specified

CUI Specified applies when the underlying authority imposes additional controls beyond the baseline—such as restrictions on who may receive the information or how it must be transmitted. The clearest manufacturing example is Controlled Technical Information (CTI). NARA describes CTI as technical information with military or space application that is subject to controls on access, reproduction, or dissemination. Registry examples include:

  • Engineering drawings and specifications
  • Process sheets and technical data packages
  • Executable or source code CTI carries the CUI//SP-CTI banner and typically requires a DoD Distribution Statement (B through F). Don't infer CUI Specified requirements from a customer's industry or a project's nickname. Identify the actual authority named in your contract or Registry entry.

CUI Basic versus CUI Specified manufacturing data comparison

Data That Requires a Case-by-Case Call

Plenty of shop-floor data sits in a gray zone until you check the source:

  • 2D drawings, 3D CAD models, and bills of material
  • Tolerances, material specs, and tooling instructions
  • CNC programs, post-processor files, and DNC transfer logs
  • Inspection results, nonconformance reports, and test data
  • Shop-floor photographs and screenshots Emails, meeting notes, purchase-order attachments, and exported files can carry controlled content forward even without an obvious CUI label on them. By contrast, a generic capability sheet, a public product brochure, or a process note you developed independently isn't automatically CUI. Context and contract instructions still need checking before you file it as unrestricted.

How to Determine Whether a Machine-Shop File Is CUI

Treat this as a repeatable sequence, not a one-time judgment call.

  1. Identify the origin. Record who supplied or created the file, which contract or program it supports, and whether it was generated from government-provided technical data.
  2. Review the authoritative paperwork. Check the contract, task order, statement of work, and any DFARS clauses or flow-down terms. Contract language changes between awards, so verify current wording rather than assuming last year's terms still apply.
  3. Inspect markings and metadata. Look for CUI banners, category codes, distribution statements, export-control notices, revision histories, and instructions embedded in drawing title blocks.
  4. Map the data to a Registry category. Compare it against the NARA CUI Registry and the authority named in your contract, distinguishing CUI from FCI, ITAR, EAR, and ordinary proprietary information.
  5. Trace where it travels. Follow the file across CAD/CAM workstations, DNC servers, CNC controllers, inspection equipment, cloud storage, email, portable media, and eventual disposal.
  6. Document and escalate. Keep a data inventory with the source of each determination. When markings, contract language, and actual use don't line up, ask the responsible government or prime-contractor contact rather than guessing.

One documented failure mode: DCSA's May 2025 CUI FAQ notes that technical documents carrying Distribution Statement D sometimes arrive without a CUI//SP-CTI banner. The information is still CUI and still requires safeguarding, regardless of whether the banner is present.

Six-step machine-shop CUI determination process flow

Systems can support this process, but they can't make the legal determination for you. CNC/DNC and shop-floor automation software can enforce version control, distribute only engineering-approved files to controllers, and log who accessed what and when.

Controlink Systems has built DNC transfer utilities and process-monitoring tools for machine shops since 1998. Those systems can push the correct file revision to a control automatically instead of relying on a machinist grabbing whatever's on a USB stick. That kind of traceability supports a CUI handling program, but it doesn't substitute for reviewing the contract and markings first.

What to Check Before Finalising a CUI Determination

What to Check Before Finalizing a CUI Determination

Before you lock in a CUI determination, run through these checks:

  • Information type and authority: Confirm the specific CUI category, marking authority, and contract requirement before you restrict access on every DoD-related file.
  • Unmarked and derivative files: Trace inherited data, screenshots from controlled drawings, revised prints, and copies pulled from an original controlled source.
  • Overlapping regimes: Keep CUI separate from ITAR, EAR, FCI, and proprietary status. One file can fall under more than one regime, and each may need its own controls.
  • Subcontractors and temporary staff: Verify need-to-know, flow-down obligations, remote access permissions, and approved transmission paths before granting supplier portal access.
  • Production system controls: Match authentication, least-privilege access, logging, patching, removable-media rules, and secure disposal to the actual requirement—not merely to the fact that a system exists.

Assign an owner and a review date to every determination. Contract modifications, revised drawings, new suppliers, or updated regulations should all trigger a fresh look rather than a one-and-done filing.

Conclusion

CUI identification is a contract- and authority-driven process. You apply controls only where a law, regulation, or government-wide policy requires protection, not to every file that touches a defense program.

The practical workflow stays consistent:

  • Identify the source
  • Read the contract and markings
  • Check the applicable CUI category against the NARA Registry
  • Map where the data travels
  • Escalate when something doesn't add up

Disciplined revision control, tight access management, and controlled movement of production files won't answer every legal question on their own. But they reduce the odds of an old drawing surfacing on the wrong workstation, or a machinist running a superseded CNC program because nobody tracked which version was current.

For a shop juggling multiple defense contracts alongside commercial work, that operational discipline makes the rest of the compliance picture manageable.

Frequently Asked Questions

What is considered DoD CUI?

DoD CUI is unclassified information that requires safeguarding or dissemination controls under law, regulation, policy, or contract. In manufacturing, that often includes marked engineering drawings and technical data packages; always verify the governing authority.

What is not considered CUI?

Information is not automatically CUI just because it relates to the DoD, is proprietary, or is technical. Publicly released data and information without a governing CUI authority typically fall outside CUI.

Are CNC files considered CUI?

CNC programs require a case-by-case review based on their source, content, contract terms, and any markings or governing authority attached to them. File format alone never decides the answer.

Is CUI the same as ITAR-controlled information?

No. CUI is a safeguarding and dissemination status; ITAR is an export-control classification for defense articles. A file can fall under one, both, or neither, so check each requirement separately.

Does every DoD contractor have to handle CUI?

Not necessarily. Obligations depend on the information you receive, create, or handle and the contract clauses that apply. CUI handling is separate from broader federal cybersecurity requirements that may still apply.

How can a machine shop identify CUI in its files?

Review the source, contract, markings, and distribution statements, then check the NARA CUI Registry. Trace data flow, document your decision, and ask the prime or contracting officer when anything is unclear.