← Back to Field notes
WINROVE / Compliance

CUI Handling Training: What Your New Hires Need to Know

CUI violations can cost government contractors their contracts and clearances. This guide covers everything your new hires need to know about handling Controlled Unclassified Information.

March 7, 2026 · Winrove Team

Cover illustration for CUI Handling Training: What Your New Hires Need to Know

Why CUI Training Is Critical From Day One

Controlled Unclassified Information (CUI) is the category of information that doesn't reach the threshold for classification as Confidential, Secret, or Top Secret: but still requires protection because its unauthorized disclosure could harm national security, public safety, or individual privacy. Government contractors handle enormous volumes of CUI: technical specifications, contract data, personally identifiable information (PII), law enforcement sensitive information, and dozens of other categories.

CUI violations are a significant source of contract performance issues, DCSA compliance findings, and: in serious cases: criminal liability. The challenge is that CUI is everywhere in a government contracting environment, and many employees handle it without realizing they're doing so. Effective new hire training closes this gap before the first day of productive work.

What Is CUI? The Basics Your New Hires Must Understand

The CUI Registry

CUI isn't defined by a single regulation: it's defined by the CUI Registry maintained by the National Archives (NARA). The Registry contains over 20 CUI categories and 100+ subcategories. The categories your new hires will most likely encounter in government contracting:

  • Controlled Technical Information (CTI): Technical documents, drawings, specifications, and data with military or space applications
  • Privacy/PII: Information about individuals including names, SSNs, financial data, medical information
  • Export Controlled: Information subject to EAR or ITAR restrictions
  • Law Enforcement Sensitive (LES): Information from law enforcement agencies that could compromise investigations
  • Procurement and Acquisition: Source selection information, contractor bid information, pre-award acquisition data
  • Intelligence: Information produced by or about intelligence activities

CUI Basic vs. CUI Specified

Two handling regimes exist under the CUI program:

  • CUI Basic: The default handling requirements: mark it, protect it with safeguards equivalent to NIST 800-171, and control access on a need-to-know basis
  • CUI Specified: Additional or different handling requirements set by the authorizing law, regulation, or government-wide policy. Examples: personally identifiable information (many specific legal requirements), HIPAA-protected health information, or export controlled technical data with ITAR restrictions

New hires need to understand which categories of CUI they'll encounter in their specific role and whether those categories have specified requirements beyond the baseline.

CUI Marking: What It Looks Like and What It Means

Required Markings

Documents containing CUI must be marked at the time of creation. A properly marked CUI document includes:

  • Banner marking: "CUI" at the top and bottom of each page
  • Designation indicator: The specific CUI category (e.g., "CUI//CTI" or "CUI//PRVCY")
  • Limited dissemination controls (if applicable): "NOFORN" (no foreign nationals), "FED ONLY" (federal employees only), etc.
  • Agency identifier and point of contact for classified documents that also contain CUI

Portion Markings

Within a document, individual portions (paragraphs, sections) that contain CUI should be marked "(CUI)" at the beginning of the portion. This enables reviewers to identify which portions require protection if the document needs to be shared with someone who doesn't have need-to-know for all the CUI within it.

What New Hires Often Get Wrong

Three common CUI marking failures to address in training:

  • Not marking at creation: Many employees think CUI marking is someone else's job. Everyone who creates a document containing CUI is responsible for marking it.
  • Over-marking: Marking information as CUI that doesn't meet the definition creates unnecessary burden and desensitizes people to the markings.
  • Under-marking: Not marking information that should be marked CUI because the employee doesn't recognize it as CUI. This is the more common and more dangerous failure.

CUI Handling Requirements: The Rules New Hires Must Know

Storage

  • Electronic CUI: Store on systems that meet NIST 800-171 requirements (not personal email, not personal cloud storage like Google Drive or Dropbox used for personal purposes, not unencrypted USB drives)
  • Physical CUI: When not in use, store in locked containers; don't leave CUI documents on desks in open areas or in shared spaces where unauthorized individuals might view them

Transmission

  • Electronic: Use approved government or company systems; encrypt email containing CUI (either end-to-end encryption or secure email gateway); do not use personal email accounts to transmit CUI
  • Physical: Use approved shippers (USPS First Class, UPS, FedEx with tracking); double-wrap packages with inner and outer packaging; do not reveal CUI status on outer packaging

Reproduction

  • Reproduction of CUI is permitted when necessary for authorized work purposes
  • Reproduced copies carry the same markings and protections as originals
  • Be aware of who has access to printers and copy machines: unsecured printers in open areas are a CUI risk

Destruction

  • Paper CUI: Shred using a cross-cut or micro-cut shredder (strip-cut shredders don't provide adequate destruction)
  • Electronic CUI: Use DoD-approved sanitization methods; "delete" is not sufficient: use secure erase tools or physical destruction for drives
  • Never place CUI in regular trash or recycling

Need-to-Know: The Governing Principle

Perhaps the most important concept in CUI handling is need-to-know. Having a clearance: or even a demonstrated reason to access CUI in general: doesn't automatically authorize access to specific CUI. An employee must have both authorization (clearance/suitability) AND a specific need-to-know to access any particular piece of CUI.

New hires need to internalize this question before sharing any CUI: "Does this person need this information to do their specific job?" If the answer isn't clearly yes, don't share it: and check with your supervisor or FSO if you're uncertain.

CUI Incident Reporting: What to Do When Something Goes Wrong

Mistakes happen. The key is catching them early and reporting them properly. New hires must know:

What Constitutes a CUI Incident

  • Sending CUI to an unauthorized recipient
  • CUI accessed or potentially accessed by unauthorized individuals
  • Lost or stolen devices containing CUI
  • CUI discovered in non-approved storage (personal email, unauthorized cloud storage)
  • Improperly marked CUI that has been widely distributed

What to Do

  1. Stop the damage: If the incident is ongoing (email about to be sent, file actively being shared), stop it immediately
  2. Don't try to fix it yourself: Remediation actions can inadvertently destroy evidence or make the situation worse
  3. Report immediately to your supervisor and FSO: within hours, not days
  4. Document everything you know: What was the CUI, how was it compromised, who might have seen it, when did you discover the incident
  5. Cooperate fully with the subsequent inquiry and remediation process

Self-reporting is viewed far more favorably than discovered violations. A contractor who promptly reports a CUI incident demonstrates a functioning security culture. A contractor whose CUI violation is discovered by the government demonstrates a broken one.

Building CUI Training Into Your Onboarding Program

Effective CUI training in onboarding includes:

  • Role-specific content: A technical engineer handling CTI needs different CUI training emphasis than an HR professional handling PII
  • Practical scenarios: "What would you do if..." exercises that apply CUI rules to realistic situations
  • Written acknowledgment: A signed form confirming the employee received and understood CUI training, with specifics of what was covered
  • Annual refresher: CUI training is not a one-time event: annual refreshers and updates when requirements change are required
  • Clear reporting chain: New hires should leave training knowing exactly who to call if they have a CUI question or incident

Investing in thorough CUI training during onboarding protects your contracts, your company's reputation, and your employees' careers. It's one of the highest-value training investments a government contractor can make.

Preserved Field Notes article. Original path /blog/cui-handling-training-what-new-hires-need-to-know/. No unrelated help guide has been substituted.

Related Field notes

Reading a DPAS Priority Rating on a Federal Order: What Contractors Must Know ↗

Wide Area Workflow (WAWF) Invoicing Basics for New Federal Contractors ↗

Provisional Billing Rates and Indirect Rate Structures, Explained Simply ↗

Cost Realism: Surviving the Government Price Analysis ↗

The compliance matrix step most small contractors skip (and how it loses bids) ↗

NAICS Code Selection and Recertification: Avoiding the Small-Business Size-Standard Trap ↗