Who Is Responsible for Applying CUI Markings and Dissemination Instructions?
The authorized holder of the information at the time of creation is responsible for applying CUI (Controlled Unclassified Information) markings and dissemination instructions. This person identifies the CUI, applies the correct banner, portion, and dissemination markings, and controls how it is shared.
The answer
The authorized holder of the information at the time of creation is responsible for applying CUI markings and dissemination instructions. This is the exam-correct answer in DoD and federal CUI training.
An authorized holder is anyone who has been given lawful access to CUI and who creates, possesses, or handles it in the course of their work. When that person creates a document containing controlled information, it is their job - at the moment of creation - to:
- Identify that the information qualifies as CUI under an approved category.
- Apply the correct markings (banner marking, portion marks where required, and the CUI designation indicator).
- Add any dissemination or limited-distribution controls that restrict who may receive it.
Marking does not wait for a supervisor or a security office - the responsibility sits with the authorized holder who generates the material.
The anatomy of a CUI marking
Competitor pages rarely show what the holder actually applies. A properly marked CUI document has:
- Banner marking - a header (and footer) reading
CUIat the top of every page, plus any category and dissemination control, e.g.CUI//SP-PRVCY//NOFORN. - Portion markings -
(CUI)at the start of individual paragraphs, titles, or sections when required, so readers can tell which parts are controlled. - Designation indicator - a block identifying the agency/office that designated the CUI and a point of contact.
- Dissemination controls - limited-distribution markings (like
NOFORNorFED ONLY) that state who may and may not receive the information.
Why other options are wrong
- "The original classification authority (OCA)" - OCAs designate classified national security information (Confidential/Secret/Top Secret). CUI is unclassified, so an OCA is not the marking authority here. This is the most common trap.
- "The security manager or facility security officer" - they oversee the program and provide guidance, but they do not mark every document; the holder who creates the information does.
- "The recipient of the information" - the recipient must protect and correctly handle CUI, but responsibility for applying the original markings lies with the creator, not the reader.
- "Anyone who touches the file" - too broad; the specific duty falls on the authorized holder at the time of creation.
The bigger picture
The CUI program (established under Executive Order 13556 and 32 CFR Part 2002) replaced dozens of inconsistent agency labels like FOUO and SBU with one standardized system. Correct marking matters because the markings are how everyone downstream knows the information is controlled and how it may be shared or safeguarded. If the authorized holder fails to mark CUI at creation, later handlers may mishandle it. That is why the responsibility is placed squarely and early: whoever creates the information, while authorized to hold it, must mark it and set its dissemination instructions right away.
Who Is Responsible for Applying CUI Markings and Dissemination Instructions?
Frequently asked
What is an authorized holder of CUI?
An authorized holder is any individual who has lawful access to CUI and who creates, possesses, or handles it as part of their duties. When they create CUI, they are responsible for marking it correctly and applying dissemination controls.
What are the required elements of a CUI marking?
At minimum a document needs a banner marking ("CUI" at the top of each page with any category and dissemination controls) and a designation indicator identifying the designating agency and point of contact. Portion markings are added when required.
When must CUI markings be applied?
At the time of creation. The authorized holder who generates the information identifies it as CUI and applies the proper markings and dissemination instructions immediately, rather than waiting until the document is shared or reviewed later.
Who designates information as CUI?
An authorized holder designates information as CUI when it falls into an approved CUI category defined by law, regulation, or government-wide policy (listed in the CUI Registry). Unlike classified information, CUI does not require an original classification authority.
What is a CUI dissemination control?
A dissemination control is a marking that limits who may receive CUI - for example NOFORN (no foreign nationals) or FED ONLY (federal employees only). It is applied by the authorized holder alongside the banner marking to restrict distribution.