GovOps360
GovOps360 GovOps360

FOUO Meaning, CUI and SCIF: What Contractors Must Actually Do

clock Sep 08,2026
pen By Alaa Negeda
Cover graphic for the FOUO meaning, CUI and SCIF guide, showing a struck-through FOUO stamp marked void since 14 November 2016 becoming a CUI banner marking with banner, portion and designation indicator elements.

FOUO Meaning: What It Was, and Whether It Is Still Used

FOUO meaning, in one line: For Official Use Only was the marking the government put on unclassified information that still needed protection, and it has been retired. Controlled Unclassified Information, or CUI, replaced it.

That matters more than a naming change usually does, because an old FOUO stamp on a document you hold today is not a protection marking at all. The regulation says so directly, and almost nobody quotes the line.

This guide covers what FOUO was and what replaced it, what CUI actually is, which regulations reach a contractor and which do not, how a CUI document is marked, how it has to be stored and sent, and the separate question of when a SCIF is genuinely required. Most contractors never need one, and this article says so plainly rather than selling the idea.

FOUO stands for For Official Use Only. It was a control marking applied to unclassified government information that was still withheld from public release, most often material exempt from disclosure under the Freedom of Information Act. It was never a classification level, and it never carried the legal weight of Confidential, Secret or Top Secret.

It is no longer in use. When the National Archives and Records Administration published the CUI final rule in 2016, it stated the position without hedging: the CUI Program markings “will replace other designations, such as SBU, FOUO, and OUO, and any agency-specific labels for CUI, which will all be discontinued.”

The Department of Defense closed its own chapter on 6 March 2020, when DoD Instruction 5200.48 was issued and canceled DoD Manual 5200.01, Volume 4, the manual that had governed FOUO. DoDI 5200.48 also removed the old banner convention, noting that there is no requirement to add the “U” for unclassified as was required with the old U//FOUO marking.

So the answer to “is FOUO still used” is no, twice over: not government-wide, and not in DoD. What you will still encounter is old paper and old PDFs that carry the stamp, which is a different problem, handled in the next section but one.

What Is CUI?

Controlled Unclassified Information is unclassified information that law, regulation or government-wide policy requires to be safeguarded or subjected to dissemination controls. It is the single government-wide category that replaced the patchwork of agency labels FOUO belonged to.

It splits in two, and the split decides how much rulebook you have to read.

  • CUI Basic is, per 32 CFR 2002.4, “the subset of CUI for which the authorizing law, regulation, or Government-wide policy does not set out specific handling or dissemination controls.” The baseline in the regulation applies and nothing more.
  • CUI Specified is “the subset of CUI in which the authorizing law, regulation, or Government-wide policy contains specific handling controls that it requires or permits agencies to use that differ from those for CUI Basic.” Here you have to go read the underlying authority, because it says something extra.

Which categories exist is not a matter of opinion. NARA maintains the CUI Registry, and a category only counts as CUI if it is listed there with the law or policy that authorizes it. If someone tells you information is CUI and cannot name the category, that is a question worth asking out loud.

One more point that changes how you read your obligations. Only the government designates CUI. The CUI glossary defines the designating agency as “the executive branch agency that designates or approves the designation of a specific item of information as CUI.” A contractor is an authorized holder. You mark, protect and pass on what the contract tells you to; you do not get to promote your own work product into the CUI system.

What Is a SCIF?

A SCIF is a Sensitive Compartmented Information Facility: an accredited area where Sensitive Compartmented Information can be processed, stored, used or discussed. It is a physical space with construction, acoustic and technical security requirements, not a software setting and not a policy.

The governing document is Intelligence Community Directive 705, signed by the Director of National Intelligence on 26 May 2010, with the build requirements in the IC Technical Specifications for ICD/ICS 705. ICD 705 requires that all IC SCIFs “comply with uniform IC physical and technical security requirements,” and that “All SCIFs shall be accredited prior to being used for the processing, storage, use, or discussion of SCI.”

Two consequences follow immediately. A room is not a SCIF because it is windowless and locked; it is a SCIF when an Accrediting Official has accredited it. And accreditation is a government act, so a company cannot decide on its own to have one.

SCIF and CUI are frequently discussed together and are not on the same ladder at all. CUI is unclassified. SCI sits above Secret. Mixing them up is the single most common confusion in this topic, which is why they get separate sections here.

CUI vs FOUO: What Changed and When?

The change was ordered by Executive Order 13556, signed on 4 November 2010. The order is unusually direct about why. It describes the pre-2010 state of affairs as an “inefficient, confusing patchwork” that “has resulted in inconsistent marking and safeguarding of documents, led to unclear or unnecessarily restrictive dissemination policies, and created impediments to authorized information sharing.” FOUO was one label inside that patchwork. NARA was named Executive Agent.

The implementing regulation followed six years later: the CUI final rule at 81 FR 63324, published 14 September 2016, effective 14 November 2016, codified at 32 CFR Part 2002.

Here is the line that decides what you do with the FOUO-stamped document in front of you. 32 CFR 2002.20(a)(2) states that “If legacy markings remain on information, the legacy markings are void and no longer indicate that the information is protected or that it is or qualifies as CUI.”

Read that carefully, because it cuts both ways and both cuts catch people out.

  • A FOUO stamp does not make information CUI. The marking is void. Whether the information qualifies as CUI depends on the CUI Registry category behind it, not the ink on the page.
  • A void marking is not a release authorization either. Information can still be exempt from disclosure, still be someone else’s to release, and still be covered by your contract. “The marking is void” is not the same sentence as “this is public.”

The practical move when a legacy document turns up is to ask the designating agency what it is under the current system, and to keep protecting it while you wait. Nothing in the regulation asks you to guess.

Is CUI Classified Information?

No. CUI is unclassified by definition. It requires safeguarding or dissemination controls under a law, regulation or government-wide policy, and that is a different mechanism entirely from the Executive Order system that produces Confidential, Secret and Top Secret.

The practical differences matter more than the theory. CUI does not require a security clearance to access. It does not require classified storage. And mishandling it is a contractual and regulatory problem rather than a matter of criminal classification law. None of which makes it optional: the safeguarding requirements in your contract are real obligations with real consequences.

FOUO meaning timeline showing Executive Order 13556 in November 2010, the CUI rule taking effect in November 2016 and DoD Instruction 5200.48 in March 2020, with a FOUO-stamped document crossing the November 2016 gate and emerging with the stamp struck through as void.

Which Regulations Govern CUI for Contractors?

This is where most explanations go wrong, because they list regulations without saying which ones actually bind a company. Start with the one that does not.

32 CFR Part 2002 applies to executive branch agencies, not directly to you. The final rule says so and then explains how it reaches you anyway: the rule “applies only to executive branch agencies, but,” in written agreements involving CUI, “agencies must include provisions that require the non-executive branch entity to handle the CUI in accordance with this rule.” Your obligation arrives through your contract, not through the regulation itself. That is why two contracts at the same company can carry genuinely different CUI requirements.

On the Defense side the mechanism is concrete and named. DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, does the work:

  • It defines what is covered. “Covered defense information” is unclassified controlled technical information or other information described in the CUI Registry that requires safeguarding, and that is either marked and provided to you by DoD, or collected, developed, received, transmitted, used or stored by you in performing the contract.
  • It sets the security standard. The clause requires the contractor to implement NIST SP 800-171. Note the revision question: DoD Class Deviation 2024-O0013, issued 2 May 2024, directs contracting officers to use a deviated version of the clause tied to Revision 2. Read the clause in your own contract rather than assuming the newest revision applies.
  • It sets a reporting clock. Cyber incidents must be reported rapidly to DoD at the DIBNet portal, and the clause defines rapidly as within 72 hours of discovery.
  • It flows down. Paragraph (m) requires the clause to be included in subcontracts involving covered defense information “without alteration, except to identify the parties.” The obligation reaches suppliers who have no direct relationship with DoD, which is covered in more depth in our FAR vs DFARS guide.

Sitting on top of that, the Cybersecurity Maturity Model Certification program is now in acquisition. The DFARS final rule under case 2019-D041 was published 10 September 2025 and took effect 10 November 2025, adding DFARS 252.204-7025 as a solicitation provision and putting 252.204-7021 into contracts. It applies to commercial products and services other than awards solely for commercially available off-the-shelf items, and it flows down to subcontractors that will process, store or transmit federal contract information or CUI.

Is There a FAR CUI Clause Yet?

Not as of September 2026, and that single fact explains a lot of the confusion in the market.

A government-wide FAR rule was proposed on 15 January 2025 under FAR Case 2017-016, with a provision, two clauses and a standard form for communicating CUI requirements. Its preamble is candid about the gap: “Currently laws, Federal regulations, and Government-wide policies already mandate these protections, but there is not a standard way these requirements are identified and shared with contractors.” It also warns that without a uniform approach, agencies “will continue to employ ad hoc, agency-specific policies.”

That rule was then folded into the wider FAR rewrite. A proposed rule under FAR Case 2026-001 published on 23 June 2026 carries the CUI material forward, with the comment period closing on 23 July 2026. It is still a proposed rule.

So the honest current picture is: DoD contractors have a hard clause, everyone else has agency-specific terms, and the government-wide clause is coming but is not here. Until it lands, the only reliable answer to “what are my CUI obligations” is the text of the contract in front of you.

How Do You Mark a CUI Document?

Three elements, and they do different jobs. Getting one right and skipping the others is the most common marking failure there is.

  1. The banner marking, at the top of the page. The control marking itself is mandatory and is either the word CONTROLLED or the acronym CUI. Category and dissemination elements are appended after double slashes, so a CUI Basic banner can be as short as CUI, while a Specified document with a dissemination control looks like CUI//SP-CATEGORY//DISSEM. DoDI 5200.48 requires DoD documents to carry CUI in both the banner and the footer.
  2. Portion markings, on the individual parts. These are the parenthetical markings that tell a reader which paragraph is the controlled one: (CUI) for a controlled portion and (U) for an uncontrolled one. NARA encourages portion marking to support information sharing; DoDI 5200.48 states that if portion markings are used, all subjects, titles and portions known to contain CUI are marked.
  3. The designation indicator, on the first page or cover. 32 CFR 2002.20(d) requires every document containing CUI to carry an indicator of who designated it, including the designating agency at a minimum. The DoD form of this is a block naming the controlling component and office, the CUI category, any distribution or dissemination control, and a point of contact.

The banner tells a reader the document is controlled. The portion markings tell them which sentences to be careful with. The designation indicator tells them who to ask. A document with only the first has answered the easiest of the three questions.

One restriction that catches contractors specifically. Limited dissemination controls such as NOFORN are not yours to apply. The CUI Registry is explicit that only the designating agency may apply them, and that an authorized holder may apply them only with the designating agency’s approval. Adding one to be safe is not a cautious act, it is an unauthorized one.

Anatomy of a correctly marked CUI document page showing the CUI banner marking at the top and repeated in the footer, one paragraph portion marked CUI and one marked U, and the designation indicator block, with three numbered callouts explaining what each element tells a reader.

How Do You Store and Transmit CUI?

The government-wide baseline is less dramatic than most people expect, and the DoD overlay is where the real engineering requirement lives.

For physical handling, 32 CFR 2002.14(c) requires an authorized holder to keep CUI under direct control or protect it with at least one physical barrier, and to reasonably ensure that the holder or the barrier protects it from unauthorized access or observation when outside a controlled environment. A locked drawer and a habit of not leaving printouts on a shared desk is closer to the standard than a vault is.

For systems, 32 CFR 2002.14(h) points at the standard by name: NIST SP 800-171 “defines the requirements necessary to protect CUI Basic on non-Federal information systems in accordance with the requirements of this part.” That is the bridge between the CUI regulation and the security controls your IT team actually implements.

For transmission, there is no blanket government-wide encryption mandate in the regulation, which surprises people. What the regulation does is require dissemination systems to meet at least the moderate confidentiality impact level under the FIPS and NIST SP 800-53 framework. DoDI 5200.48 permits electronic transmission via approved secure communications systems or systems using other protective measures such as public key infrastructure or transport layer security, and separately prohibits DoD personnel from using personal email accounts or non-DoD systems for official business involving CUI, other than approved or authorized contractor systems.

If your work is DoD covered defense information, the cloud question has a specific answer. DFARS 252.204-7012 requires that where the contractor intends to use an external cloud service provider to store, process or transmit covered defense information, the provider must meet security requirements “equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline.” Equivalent to is doing real work in that sentence, and it is the clause to quote when a vendor tells you their product is secure without saying what it is measured against.

When Is a SCIF Actually Required?

Almost never, for almost everyone. A SCIF is required when Sensitive Compartmented Information will be processed, stored, used or discussed, and only then. It is not a CUI requirement, it is not a NIST SP 800-171 requirement, and it is not a general requirement for classified work.

The escalation is worth setting out plainly, because vendors and well-meaning advisers routinely skip several rungs:

  • CUI on your own systems means NIST SP 800-171, and for DoD work a CMMC level in the contract. No facility clearance is implied.
  • Classified information brings in a facility clearance and approved storage under the National Industrial Security Program. This is already a large step and it is not a SCIF.
  • Sensitive Compartmented Information is what brings ICD 705 into play, and only SCI does.

If your contract does not put SCI in your hands, you do not need a SCIF, and any conversation that jumps from “we handle CUI” to “we should look at a SCIF” has skipped two rungs and a facility clearance.

When SCI genuinely is in scope, the sequence is government-led. The IC Technical Specifications require that a Construction Security Plan be developed and approved by the Accrediting Official before a construction contract is awarded, and that the AO review and approve the design concept, the CSP and the final design before construction starts. You do not build first and seek accreditation afterwards, and you do not proceed without a sponsor.

What Does a SCIF Cost, and How Long Does Accreditation Take?

There is no published official figure for either, and we are not going to invent one. ICD 705 and the IC Technical Specifications set security requirements; they contain no cost or schedule data. Any article quoting a per-square-foot price or a number of months without naming a source is estimating from vendor marketing.

What can be said honestly is what drives both. Cost concentrates in construction to the technical specification, accredited installation, and the alarm, access control and acoustic work that a normal fit-out does not include. Schedule is governed by the approval sequence rather than by the build: the CSP and design approvals come first, and the AO sets that pace. If you need a number, the only reliable one comes from your sponsoring agency and a contractor who has built to the specification for that AO.

Stepped diagram showing three rising tiers of information custody: federal contract information and CUI requiring NIST SP 800-171 and a CMMC level, classified information requiring a facility clearance and approved storage, and Sensitive Compartmented Information requiring a SCIF accredited under ICD 705, with a marker showing that most contractors stop at the first step.

The Most Common CUI Marking Mistakes

Every one of these is common, and every one of them has a specific line of authority behind the correction.

Common CUI handling and marking mistakes, what the rules actually require instead, and the authority for each correction.
The mistakeWhat is actually requiredWhere it says so
Treating an old FOUO stamp as a live protection markingA legacy marking is void and does not indicate the information is protected or qualifies as CUI32 CFR 2002.20(a)(2)
Treating a void marking as permission to releaseThe marking being void says nothing about whether the information may be disclosed; ask the designating agency32 CFR 2002.20(a)(2), read with the contract
Designating your own work product as CUIOnly the designating agency designates CUI; a contractor is an authorized holderCUI glossary, designating agency and authorized holder
Adding NOFORN or another dissemination control yourselfOnly the designating agency may apply limited dissemination controls; a holder needs its approvalCUI Registry, Limited Dissemination Controls
Banner marking only, with no designation indicatorEvery document containing CUI must indicate who designated it, agency at a minimum32 CFR 2002.20(d); DoDI 5200.48
Carrying the old U//FOUO banner style into DoD documentsDoD documents carry CUI in the banner and footer, and the U is not addedDoDI 5200.48, section 3.4
Assuming CUI access requires a security clearanceCUI is unclassified; access does not turn on a clearanceEO 13556 and 32 CFR Part 2002
Accepting that a cloud tool is secure without a benchmarkFor DoD covered defense information the provider must meet requirements equivalent to the FedRAMP Moderate baselineDFARS 252.204-7012(b)(2)(ii)(D)

If you take one habit from this table, take the third and fourth rows. Over-marking feels safe and is the mistake with the least defensible paper trail, because there is no authority anywhere that lets a contractor invent a control.

What CUI Handling Requires of Your Bid and Capture Systems

Start by separating two things that get merged in almost every vendor conversation: the information you hold that is CUI, and the information you hold that merely feels sensitive.

Much of what sits in a capture pipeline is not CUI at all. Public solicitation notices, your own teaming discussions, your own pricing build-up and your own past performance narratives are your information. What can be CUI is the material the government hands you: a marked attachment, technical data, or information the contract identifies. The discipline is not to protect everything equally, it is to know which of your systems are in scope and to keep in-scope material out of the ones that are not.

That gives four questions worth answering before a solicitation arrives rather than after:

  • Which of your contracts carry a CUI safeguarding clause, and which specific clause is it?
  • Which systems are permitted to hold that material, and who decided?
  • Which subcontracts received the flow-down, and does that still match the current contract after every modification?
  • Who is the designating agency contact for each marked document you hold, so a legacy or ambiguous marking can be resolved rather than guessed?

GovOps360 is built for the first, third and fourth of those: the contract record, the clause obligations it carries, and the subcontractor relationships those obligations flow into, held in one place so a modification that changes a safeguarding requirement is visible against the subcontracts it affects. For the second question, the honest answer for any vendor is to read what they publish rather than what they say in a demo. Ours is in the GovOps360 Trust Center, and the right way to use it is to compare what it states against the specific safeguarding requirement written in your contract before any controlled material goes anywhere.

GovFind finds the opportunity. GovOps360 wins it.

See Where GovOps360 Fits Your Pipeline

Bring a pursuit you lost and one you won. We will model both, show you where the platform helps and tell you where another tool on this list is the better fit.

Frequently Asked Questions

1. Is FOUO still used?

No. The 2016 CUI final rule stated that CUI Program markings would replace designations such as SBU, FOUO and OUO, which would all be discontinued, and DoD Instruction 5200.48 canceled the DoD manual that governed FOUO in March 2020. You will still meet the stamp on older documents.

2. Is CUI classified information?

No. CUI is unclassified information that requires safeguarding or dissemination controls under a law, regulation or government-wide policy. It sits entirely outside the Confidential, Secret and Top Secret system, so it does not require classified storage or a clearance to access.

3. Does CUI require a security clearance?

No. Access to CUI is not gated by a clearance. It is gated by whether you are an authorized holder with a lawful government purpose, and by whatever dissemination controls the designating agency applied. Your contract, not your clearance level, is what governs.

4. What is the difference between CUI Basic and CUI Specified?

CUI Basic is the subset whose authorizing law, regulation or policy sets out no specific handling or dissemination controls, so the baseline in 32 CFR Part 2002 applies. CUI Specified is the subset whose authority contains specific controls that differ from that baseline, so you must read the underlying authority.

5. Can a contractor decide that something is CUI?

No. The CUI glossary defines the designating agency as the executive branch agency that designates or approves the designation. A contractor is an authorized holder: you mark and protect what the contract and the designating agency require, and you cannot promote your own material into the system.

6. What does a marking like CUI//SP-CATEGORY//DISSEM mean?

It is a banner marking read left to right. The first element is the control marking, either CUI or CONTROLLED. The second names a Specified category from the CUI Registry. The third is a limited dissemination control. Double slashes separate the elements.

7. Does CUI have to be encrypted in email?

There is no blanket encryption mandate in 32 CFR Part 2002. DoDI 5200.48 permits electronic transmission via approved secure systems or protective measures such as public key infrastructure or transport layer security, and your contract may impose more. Check the clause rather than assuming.

8. Do I need a SCIF to work on a classified contract?

Not usually. A SCIF is required for Sensitive Compartmented Information specifically. Classified work below SCI is handled under a facility clearance with approved storage, which is a different and much more common arrangement than an ICD 705 accredited facility.

Alaa Negeda, author and federal contracting subject matter lead at GovOps360

Alaa Negeda

Senior Solution Architect with 23 years of experience in different Technology sectors. Diligent, forward-thinking, and adaptable to dynamic company, customer, and project needs.

Related Articles

Cover graphic for the FAR vs DFARS guide, showing the FAR as 48 CFR Chapter 1 with clauses numbered 52 and the DFARS as 48 CFR Chapter 2 with clauses numbered 252 stacked above it, with the note that a supplement adds a layer and never removes the one below.
clock Sep 05,2026

FAR vs DFARS: Which Rules Apply to Your Contract and When

FAR vs DFARS explained: what each one governs, how to decode a clause number, which agency supplement applies to you, and what happens when they…
Read the Article
GovOps360 article cover: UEI Number and CAGE Code, showing the SAM.gov registration track from getting the UEI through Core Data where DLA issues the CAGE code, a ten business day validation wait, and an Active record.
clock Sep 02,2026

UEI Number and CAGE Code: The Complete Registration Guide for Contractors

UEI number and CAGE code explained: what each one is, who issues it, the exact SAM.gov sequence, and why registrations get rejected. Start ten days…
Read the Article
GovOps360 article cover: RFI Meaning in Government Contracting, showing an RFI or Sources Sought notice shaping the requirement, which becomes the RFP, with the FAR 15.201(f) gate closing after release.
clock Aug 30,2026

RFI Meaning in Government Contracting: What It Is and How to Respond

RFI meaning in federal procurement: what a Request for Information actually is, why agencies issue one, and how to respond so you shape the eventual…
Read the Article

Create your account