CUI on page one: what 32 CFR 2002 and DoDI 5200.48 ask of an engineering report

The government-wide rule asks for the same banner on every page and a designation indicator on the first. DoD practice prints plain CUI at top and bottom and moves the codes and a point of contact into a five-line block.

A report that holds controlled unclassified information must carry two marks. The banner tells every reader that the document holds CUI, and the designation indicator says who designated it.1

Portion marks are a third, optional layer. Where each mark goes, and what it holds, differs between the government-wide rule in 32 CFR 2002 and DoD practice under DoDI 5200.48.

This post shows how an engineering team marks its reports, and it is not legal advice. Your contract and your security office pick the category and the controls, and the rules below put them on the page.

The banner: one line, the same on every page

32 CFR 2002.20 lets a banner hold up to three elements.1 The control marking is mandatory and reads CONTROLLED or CUI. Category markings are mandatory for CUI Specified, and limited dissemination control markings are the third.1

The banner covers the whole document and reads the same on every page that holds CUI.1 NARA’s marking handbook puts it at the top of each page and calls a copy at the bottom an optional best practice.2 Double slashes separate the groups, and a Specified category takes an SP- prefix.2

The registry lists Export Controlled with the category marking EXPT.3 Some of its authorities are Specified, with the banner CUI//SP-EXPT, and some are Basic, with the banner CUI or the alternative CUI//EXPT.4 FEDCON, Federal Employees and Contractors Only, is one of the registry’s limited dissemination controls.5

So a government-wide banner for export-controlled data under a Specified authority, limited by FEDCON, reads CUI//SP-EXPT//FEDCON. Any warning or distribution statement that an authority requires still goes on the document, but never inside the banner.1 Only the designating agency may apply a limited dissemination control, and other holders need its approval.5

Retire any report template that still prints FOUO. The part makes legacy markings void and bars any marking that is not in the part or the registry.1 DoD’s instruction calls FOUO the old marking and says a CUI banner needs no U in front, as U//FOUO did.6

The designation indicator: who controls it

Every document with CUI must say who designated it. At minimum that means the designator’s agency, shown by letterhead or by a “Controlled by” line.1 It must be easy to find, and it may appear on the first page or cover alone.1

NARA’s handbook asks you to name a point of contact, branch or division where you can, with contact details.2 DoDI 5200.48 turns this into a fixed block of five lines on the first page or cover:6

DoDI 5200.48, Figure 2CUI Designation Indicator for All Documents and Materialtext
Controlled by: [Name of DoD Component] (Only if not on letterhead)
Controlled by: [Name of Office]
CUI Category: (List category or categories of CUI)
Distribution/Dissemination Control:
POC: [Phone or email address]

Line one names the DoD Component that determined the information is CUI, and letterhead can stand in for it. Line two names the office that made the determination, and line three lists every CUI category in the document.6

Line four holds the distribution statement or the dissemination controls. Line five holds a phone number or office mailbox for the originating Component or the authorized holder.6 DoD’s marking training aid accepts organizational email, and says contractors may create and mark CUI and appear as the point of contact.7

Portion marks: optional until you start

In a fully unclassified document, portion marking is optional: 32 CFR permits and encourages it but does not demand it.12 Once you start, you mark every portion, and portions without CUI get (U).12

Two cases make portion marks mandatory. When CUI shares a document with classified information, every CUI portion must be marked.1 An agency head can also require portion marks on all CUI that the agency creates.2

DoD follows the same pattern: if portion marks are selected, CUI portions get (CUI) and unclassified portions must get (U).6 In a classified DoD document, the CUI portions must be marked.6 The training aid adds one rule: never portion mark the designation indicator.7

What DoD practice changes

  • The banner is a generic “CUI” at the top and bottom of each page.6 The training aid rules out UNCLASSIFIED in front of it and any category after it, so no SP- prefix appears.7
  • Basic and Specified CUI need no distinction during DoD’s phased implementation of the program.6
  • The codes move into the block: the category on line three, and the control or distribution statement on line four.67
  • Technical information keeps a distribution statement. The instruction uses limited dissemination controls for new CUI, but export-controlled technical information and other scientific, technical and engineering information still take distribution statements.6 Export-controlled information also needs an export control warning.6
  • Table 2 of the instruction lines FEDCON up with Distribution Statement C.6 The training aid spells a distribution statement out on page one and puts its letter in the block.7
  • Public release of a CUI report, including posting on a public website, needs a prepublication and security policy review first.6
  • The contract states the protective measures and dissemination controls for CUI that a contractor generates.6

The example, line by line

This is INC-0142 from the Foxborne example dataset, a telemetry gap on a Q4 quad. It is an example, not a field report. The example’s administrator set one marking, and every report carries it.

Bannertop of every pageCUICUI only: no category, no UNCLASSIFIEDDesignation indicatorfirst page or coverControlled byHarrow Field RoboticsControlled byReliability EngineeringCUI categoryEXPTDisseminationFEDCONPOC[email protected]DoD contract: the DoD ComponentFive lines, first page or coverEXPT on DoD work: distribution statementIncident reportINC-0142Telemetry gap after perception.servicewas killedVehicleUAS-04, Q4 recon quadRunR-0931, Route Iron reconReport bodyno portion marks1 Finding2 Sequence3 EvidenceNo portion marks. Optional in anunclassified report.Bannerbottom of every pageCUISame line as the top banner
Page one of INC-0142 from the Foxborne example dataset. The banner and block follow DoD practice, except lines 1 and 4, which a DoD contract would set differently.
  1. Banner: CUI at the top and bottom and nothing else, which matches DoD practice as written.67
  2. Placement: the block sits under the top banner. The instruction asks only for the first page or cover, while the training aid draws the block at the bottom of page one.67
  3. Line one, Harrow Field Robotics: the company itself. The instruction wants the DoD Component here, and DCSA’s job aid fills the line with the Government Contracting Activity.68
  4. Line two, Reliability Engineering: the office that created the report, which is what DoD’s marking aids ask for.78
  5. Line three, EXPT: the registry marking for Export Controlled.3
  6. Line four, FEDCON: a valid registry control, printed under the label Dissemination.5 For export-controlled technical information, a DoD program puts a distribution statement letter on this line instead.67
  7. Line five, an office mailbox: allowed as written.67
  8. Portion marks: none, which an unclassified report allows.16

Lines two, three and five stand as written. Lines one and four come from the contract, so read them off it before the first report goes out.

Sending the report

An email that carries a CUI report as an attachment serves as a transmittal document.7 It needs a CUI marking on its face and an instruction such as “When enclosure is removed, this document is Uncontrolled Unclassified Information.”1

DoD’s training aid does not require the designation indicator on such an email, but keeps “CUI” as its first and last lines.7 It also tells DoD users to encrypt any email that contains CUI whenever that is technically feasible.7

What the marking tells a reviewer

A marking is a statement about handling, made by whoever designated the report. The banner does not make information CUI: the law, regulation or government-wide policy behind the category does.1 Marking information that does not qualify counts as misuse.1

What the evidence shows

  • The report holds CUI in the Export Controlled category, EXPT.
  • Who to ask about it: Reliability Engineering, through an office mailbox.
  • The dissemination limit the designator chose: FEDCON, federal employees and contractors only.

What it does not

  • Whether the content qualifies as CUI. That rests on the authority behind the category, not on the banner.
  • Which export authority applies, Basic or Specified. A DoD banner never shows it.
  • Whether a given reader may receive the report. The marking states the limit, and access control enforces it.

Sources

  1. 132 CFR Part 2002, Controlled Unclassified Information, §§ 2002.4 and 2002.20eCFR, current to September 24, 2026. Accessed September 26, 2026.
  2. 2Marking Controlled Unclassified Information, version 1.1 (CUI Marking Handbook)NARA, Information Security Oversight Office. Accessed September 26, 2026.
  3. 3CUI Registry: CUI MarkingsNARA. Accessed September 26, 2026.
  4. 4CUI Registry: Export ControlledNARA. Accessed September 26, 2026.
  5. 5CUI Registry: Limited Dissemination ControlsNARA. Accessed September 26, 2026.
  6. 6DoDI 5200.48, Controlled Unclassified Information (CUI), March 6, 2020, paragraphs 3.3, 3.4, 4.3 and 5.3Department of Defense, Internet Archive copy of the esd.whs.mil PDF. Accessed September 26, 2026.
  7. 7Controlled Unclassified Information Markings, training aid, December 2024OUSD(I&S), DoD CUI Program, Internet Archive copy. Accessed September 26, 2026.
  8. 8CUI Marking Job Aid, October 2021Defense Counterintelligence and Security Agency, Internet Archive copy. Accessed September 26, 2026.

More field notes

Time and clocksBoot time, wall time, arrival time: one incident, three clocksA PX4 flight log counts from boot, the companion journal keeps wall time and the ground station logs arrival. Give each an explicit error bound, and you know which events you can put in order and which you cannot.Companion computersReading an OOM kill in a journalctl exportThe kernel’s out-of-memory report names the thread that asked, the process it killed and every page it counted. systemd then records the unit’s result, and two settings decide what happens next.Companion computersWhen BindsTo= takes your MAVLink router down with itA dependency in the unit graph can silence telemetry with no radio fault at all. Here is how to spot one in the journal, and how to prove it on the bench before anyone swaps a radio.

A pilot on your own data

Bring your hardest incident.

Send one failure you have already investigated. We rebuild it on your data, beside your current tools, and show where the evidence agrees with your conclusion and where it doesn’t.

  1. 1
    Send one incidentA failure you have already investigated, with the flight log and whatever companion or ground evidence you kept.
  2. 2
    We reconstruct itBeside your current tools, on your data, with every claim traced to its source.
  3. 3
    Compare the answersWhere the evidence agrees with your conclusion, where it does not, and what it cannot decide.