CUI Handling Best Practices for Arizona Defense Subcontractors

You might be handling CUI without knowing it

Small defense suppliers in Arizona’s East Valley often handle Controlled Unclassified Information (CUI) without realizing it. If your machine shop in Gilbert receives engineering drawings from Boeing Mesa, those drawings are likely CUI. If your electronics firm in Chandler gets test specifications from Northrop Grumman, those specs are likely CUI. If your logistics company ships components with technical data packages, those packages contain CUI.

CUI isn’t classified information. It’s sensitive government information that requires safeguarding under NIST SP 800-171 and, eventually, CMMC Level 2 certification. Mishandling it puts your contracts at risk and exposes you to False Claims Act enforcement.

Identifying CUI in your business

CUI is marked with specific banners and category markings. Common categories defense subcontractors encounter include:

  • CUI//SP-CTI: Controlled Technical Information like engineering drawings, specs, and test data
  • CUI//SP-EXPT: Export-controlled technical data
  • CUI//SP-PRVCY: Privacy information including employee and personnel data
  • CUI//SP-PROPIN: Proprietary business information

If you receive documents with these markings (or documents that should have these markings but don’t), you’re handling CUI and must protect it accordingly.

CUI storage requirements

CUI must be stored in systems that meet NIST 800-171 requirements:

  • Encryption at rest: AES-256 or FIPS 140-2 validated encryption on all storage containing CUI
  • Access control: Only authorized personnel with a legitimate need can access CUI systems
  • Audit logging: All access to CUI must be logged and reviewable
  • Physical security: CUI in physical form (printed drawings, USB drives) must be stored in controlled areas
  • Boundary definition: Your SSP must define exactly which systems store, process, or transmit CUI

CUI transmission rules

When sending CUI outside your organization:

  • Email containing CUI must be encrypted end-to-end (standard email is not sufficient)
  • File transfers must use encrypted channels (SFTP, encrypted cloud sharing)
  • Physical shipments of CUI media must use tamper-evident packaging
  • Never send CUI through personal email, consumer cloud storage, or unencrypted channels

CUI destruction

When CUI is no longer needed, it must be destroyed using methods that prevent recovery:

  • Digital: NIST SP 800-88 Rev 2 compliant sanitization (cryptographic erase or physical destruction)
  • Paper: Cross-cut shredding (strip-cut is not sufficient for CUI)
  • Media: Degaussing, physical destruction, or cryptographic erase depending on media type

Document every destruction event in a destruction log with date, method, description, and responsible party.

Building your CUI handling procedure

Your documented CUI handling procedure should cover identification, marking, storage, transmission, and destruction. It becomes part of your System Security Plan and is reviewed during CMMC assessment.

Asteroid IT works with Arizona defense contractors to build CMMC-compliant environments including CUI handling procedures that satisfy NIST 800-171 requirements. We serve contractors across Chandler, Mesa, Gilbert, and Tucson.

Call us at 480-937-7021 or schedule a conversation.

Scroll to Top