Society & Everyday Life

Who Can Decontrol CUI? Authority, Exceptions, and Limits

Learn which agency or authorized official can decontrol CUI, when decontrol may happen automatically, and why it is not the same as public release.

Controlled Unclassified Information (CUI) can be decontrolled by the federal agency that designated it or by agency personnel authorized under that agency’s policy. An authorized holder may request decontrol, but a request alone does not remove controls unless that holder also has the required authority. Some CUI is decontrolled automatically when a lawful condition or date occurs. The Archivist has limited authority over transferred records. Decontrol does not, by itself, authorize public release.

That is the government-wide rule under 32 CFR 2002.18. The exact decision-maker can differ by agency and by the law, regulation, or Government-wide policy that made the information CUI. A contractor, recipient, or employee should therefore not treat the words “authorized holder” as blanket permission to remove controls.

Who has what authority?

CUI decontrol roles under the government-wide rule
Person or organization Can decontrol CUI? What the authority or limit means
The designating agency Yes It may make an affirmative decontrol decision for CUI it designated, if that action is consistent with the governing authority.
Agency personnel named in agency policy Yes, within the delegated scope Each agency may identify which of its personnel are authorized to decontrol CUI.
An authorized holder Not automatically A holder may request decontrol. The holder can act directly only when the governing authority and agency policy give that holder the necessary authority.
A contractor or other nonfederal recipient Not merely because it created, received, or stores the item It must follow the contract or agreement and agency direction. If the controls appear no longer necessary, it should ask the government contracting activity or designating agency.
The Archivist of the United States In a specific archival setting The Archivist may decontrol records transferred to the National Archives, unless an agreement with the designating agency provides otherwise.
A person who disclosed the information without authorization No An unauthorized disclosure does not change the information’s CUI status.

The key distinction is between holding CUI and having authority to change its status. The National Archives defines an authorized holder broadly as a person or organization permitted to designate or handle CUI. That definition does not make every holder an agency decontrol official.

When can CUI be decontrolled?

CUI should be decontrolled when it no longer requires safeguarding or dissemination controls, unless decontrol would conflict with the law, regulation, or Government-wide policy that governs it. Section 2002.18 describes two broad routes: an automatic event recognized by the rule, or an affirmative decision by the designating agency.

Automatic decontrol may occur when:

  • the governing law, regulation, or Government-wide policy no longer requires control and the holder has the authority required by that governing source;
  • the designating agency makes an authorized proactive public disclosure;
  • the agency makes a legally permissible disclosure under an access law such as the Freedom of Information Act or Privacy Act through its public-release process; or
  • a predetermined event or date occurs, unless the governing authority requires coordination first.

The designating agency may also decontrol in response to a request from an authorized holder. A request is a route to a decision, not the decision itself. Until the applicable condition is confirmed or the authorized agency action occurs, the safer and legally faithful assumption is that the CUI controls remain in place.

A practical decontrol path

  1. Identify the designating agency. Use the designation indicator, origin information, contract records, or agency point of contact. If the status or marking is unclear, NARA directs questions back to the originator or government contracting activity.
  2. Identify the governing authority and CUI category. Check the CUI Registry and the agency’s implementing policy. CUI Specified may have decontrol requirements set by its underlying authority.
  3. Check for an authorized trigger. Determine whether a stated date or event has occurred, whether the governing authority still requires control, or whether an agency decision is needed.
  4. Use the agency’s authorized process. A holder without delegated authority should request decontrol from the designating agency and preserve the decision record.
  5. Handle markings correctly after decontrol. When decontrolled information is restated, reused, released, or donated, authorized holders must clearly indicate that it is no longer controlled. Agency policy can specify how old markings are removed or struck through.
  6. Evaluate public release separately. Decontrol removes CUI Program handling requirements; it does not automatically authorize publication or other public release.

This sequence is a reading guide to the federal rule, not permission to alter a real document. For an operational decision, follow the applicable agency CUI policy, contract or agreement, and the instructions of the agency’s CUI program office.

Decontrol is not the same as removing a label or releasing a file

Four actions that are often confused
Action What changes What it does not prove
Decontrol The information no longer requires handling under the CUI Program. It does not by itself authorize public release.
Changing or removing a marking The visible label on a document or system changes. Editing a label without authorized decontrol does not change the underlying status.
Public release The agency authorizes information for public access under its release procedures. A holder cannot infer public-release approval solely from decontrol.
Declassification Classified national-security information changes status under the classification system. It is a different process from CUI decontrol, although an agency may address both during the same review when appropriate.

The regulation also closes an important loophole: leaking CUI does not decontrol it, and an agency may not decontrol information simply to conceal an unauthorized disclosure or avoid accountability for it.

How the DoD rule fits

Department of Defense policy adds DoD-specific roles and review requirements. DoDI 5200.48 says decontrolling and releasing DoD CUI records is carried out by the information’s originator, an original classification authority when one is identified in a security classification guide, or designated decontrol offices using the applicable review-and-release procedures.

The same instruction requires a DoD originator or authorized CUI holder to ensure a prepublication and security-policy review before CUI is approved for public release, including posting it on a publicly accessible website. This is why “an authorized holder can request decontrol” must not be shortened into “any holder can publish it.” The DoD instruction applies in the DoD context; other agencies use their own implementing policies within the government-wide framework.

Examples that show the boundary

  • A control date arrives: If the document’s authorized decontrol instruction names a date and no governing authority requires prior coordination, the applicable automatic condition may be satisfied. The holder still follows agency marking and reuse procedures.
  • A contractor believes the information is obsolete: Obsolescence alone is not permission to decontrol. The contractor follows its agreement and asks the designating agency or government contracting activity for a determination.
  • A CUI document appears online after an unauthorized disclosure: Public availability does not decontrol it. The agency’s response and any later authorized release are separate matters.
  • Records are transferred to NARA: The Archivist may exercise the specific authority in 32 CFR 2002.18(m), subject to any agreement with the designating agency.

The shortest safe rule

Do not remove CUI controls just because you possess the information, created a derivative file, reached a date that looks relevant, or found the same material online. Confirm the governing authority and agency policy. If your role does not clearly include decontrol authority, request a decision from the designating agency and continue protecting the information until that decision is documented.

Sources