If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
CUI Marked Drawings You Were Not Expecting? Do This
CUI marked drawings arrive in a quote package with no warning at all. An engineer opens the file and there it is across the top of the sheet: CUI. Nobody told you this job involved controlled information. The RFQ did not mention it. The buyer never said a word. And the file has already been in your email for four days, has been forwarded to two machinists, and is sitting in whatever your MSP uses for mail archiving. This is one of the most common ways a manufacturer discovers it has a compliance problem. Contain it, do not destroy it, and tell the sender in writing before you decide what it means. This article is part of Something Just Happened and You Need CMMC: A Triage Guide.
Four things not to do in the first hour
- Do not delete it. Deleting data that arrived in error destroys the record of what you received and when. If this later becomes a dispute or an inquiry, that record is your defense. Isolate, do not erase.
- Do not forward it to anyone else. That includes your attorney’s personal Gmail, your provider’s ticketing system and any consultant. Every forward creates another copy in another system.
- Do not print it, and check whether somebody already has. Print queues and copier hard drives are systems too.
- Do not answer the RFQ yet. Quoting the job is an implicit statement that you can handle the data.
Read the markings on the drawings before you react
What is printed on CUI marked drawings tells you which obligation just attached. Look for four things:
| Marking | Where it appears | What it tells you |
|---|---|---|
Banner marking,
CUI
or
CONTROLLED
| Top and bottom of each page | The document is designated CUI. This is the baseline trigger. |
Category marking, for example
CUI//SP-CTI
| Appended to the banner | Which CUI category applies. CTI is Controlled Technical Information, which covers most drawings, specifications and CAD models. |
Limited Dissemination Control, such as
NOFORN
,
FED ONLY
or
DL ONLY
| After the double slash | Who may see it. NOFORN on a drawing in a shop with foreign national employees is an immediate personnel problem, not just an IT one. |
| Distribution statement B through F, and export control warnings | Usually a block on the drawing face | Export control. ITAR or EAR obligations run in parallel with CUI handling and are enforced separately, with heavier penalties. |
A drawing carrying an export control warning and a NOFORN marking is a materially different situation from a plain CUI banner, and it should be escalated the same day. If the CUI designation itself is new to you, start with What is Controlled Unclassified Information (CUI)?
Which of the three situations produced your CUI marked drawings
1. You were supposed to receive it, and the obligation was already yours
Check the contract or the purchase order behind the quote package. If DFARS 252.204-7012 is in it, the safeguarding obligation attached at signature. The drawing did not create the obligation, it just made it visible. This is the most common case, and it is the one where companies find out they have been out of compliance for two years without knowing it. See What DFARS 252.204-7012 Requires, in Plain English.
2. You were not the intended recipient
Wrong distribution list, wrong Smith, a buyer who sent one RFQ to fourteen suppliers at once. This is a CUI spillage on the sender’s side. You still have obligations, meaning containment and notification, but you are not the party that failed.
3. You were the intended recipient, but the data should not have been sent that way
A prime emails CUI drawings in the clear to a supplier with no safeguarding clause in place. It happens constantly. The sender has a problem, and now you have a copy of controlled information in an environment that probably cannot protect it, which means you have one too.
Find every copy of the CUI marked drawings
Before you talk to anyone, know the blast radius. CUI marked drawings spread faster than people expect, so check all of these:
- The original mailbox, plus every mailbox it was forwarded to
- Sent items, and any mailbox rule that auto-forwards or auto-files
- Mail archiving or journaling, usually run by your provider and often in a system you have never seen
- Mobile devices where that mailbox is synced, including personal phones
- Local downloads, the shared drive, the ERP attachment field, the quoting folder
- Backups, and their retention window
- Print queues, MFP storage, and anything physically printed
- Any CAM, nesting or CAD system the file was opened in, because these copy files silently
- Anything sent onward to your own subcontractors or vendors
Write it down with timestamps. That list is what makes every later conversation short and credible.
Is this a reportable cyber incident?
Usually not, and this distinction is worth getting right because the two paths have different clocks and different audiences.
| CUI spillage or mishandling | Cyber incident under DFARS 252.204-7012 | |
|---|---|---|
| What it is | CUI ended up somewhere it should not have been, through misdirection or mismarking | Compromise, or an actual or potentially adverse effect on a covered contractor information system or the CUI on it |
| Who you tell | The sender or originator, and your contracting officer or prime’s contracts lead | DoD via DIBNet, plus the prime |
| Clock | Promptly. Same day is the standard to hold yourself to | Rapidly, within 72 hours of discovery |
| Extra obligations | Containment, disposition instructions from the originator | Preserve and protect affected media and images for at least 90 days, and support the DoD damage assessment |
Receiving misdirected CUI is not automatically a cyber incident. It becomes one if there is evidence of compromise, meaning the mailbox was already breached, the file went to an unauthorized third party, or the drawing sat on a system you know to be infected. Note also that DIBNet reporting requires a DoD approved medium assurance certificate, which takes time to obtain. If nobody at your company holds one, find that out now rather than at hour 70. Detail is in 72-Hour DoD Breach Notification: DFARS Reporting Requirements.
Notify the sender, in writing
A short, factual email. No speculation, no apology for something you did not do, and no promises about deletion until you have disposition instructions.
On [date] we received [document/package] from [name]. The material carries CUI markings [quote the exact banner]. Our records indicate no safeguarding clause in the associated purchase order.
We have restricted access to the material and stopped further distribution. We have not deleted it, in order to preserve the record. Please confirm: (1) whether this transmission was intended, (2) your instructions for disposition, and (3) the contract vehicle and clauses under which this material was released.
Send it to the buyer and to the prime’s contracts or security function, not only to the person who sent the file. Buyers frequently do not know their own company’s CUI process. Keep the reply, because it is what documents that you acted correctly.
The consequence nobody mentions, which is that your scope just moved
The moment CUI lands in your general purpose email tenant and file shares, those systems are in scope for all 110 NIST SP 800-171 requirements. Not just the laptop it was opened on. The environment. For most small manufacturers that means a commercial Microsoft 365 tenant that was never designed to carry controlled information, because commercial Microsoft 365 was not built to meet the DFARS 252.204-7012 cloud conditions.
You have three real options:
- Do not take this work. Legitimate, and sometimes correct if it is one small job.
- Bring the whole environment up to 800-171. Expensive and slow, and it puts every laptop and every employee inside the boundary permanently.
- Reduce scope with an enclave. Put controlled information in a dedicated environment, keep it out of general email and file shares, and leave the rest of the company outside the boundary. This is why enclaves exist, and it is the difference between a 90 day answer and a two year program.
Related situations: your CUI is sitting in commercial Microsoft 365 covers the cleanup path in detail, and 90 days to get compliant covers what is achievable if a delivery date is already committed.
Week one, in order
- Contain access. Restrict the mailbox items and files holding the CUI marked drawings to the smallest possible group. Do not delete.
- Build the copy inventory with timestamps.
- Check the drawing for export control and dissemination markings, and screen for foreign national access if either is present.
- Send the written notification and request disposition instructions.
- Pull the purchase order and check for 252.204-7012, 7019, 7020, and FAR 52.204-21.
- Make the incident determination, spillage or cyber incident, and document how you reached it.
- Decide the scoping path before you quote any further work from this customer.
- Write it up. One page covering what arrived, when, where it went, what you did and what the originator said.
That one page is the artifact that matters. It converts a story about CUI sitting in your email into a record showing that you identified it, contained it, notified the originator and changed your process. Those are completely different positions to be in.
Next step
Before you decide whether to harden your environment or move CUI out of it, find out how far it has already spread. The CUI Scoping Workbook walks you through identifying every system that touches controlled information and drawing a defensible boundary around it. That decision sets your cost and your timeline for everything that follows.
Frequently asked
Questions about this topic
Should I just delete CUI marked drawings I was not supposed to receive?
Do I have to report receiving CUI by mistake to the DoD?
Do CUI marked drawings arriving once make us subject to CMMC?
Our contract has no cybersecurity clauses. Are we off the hook?
What if the drawing is marked CUI but our buyer says it is not really CUI?
Can we keep quoting the job while we sort this out?
Keep reading
More in Trigger Events & Urgent Situations
- 90 Days to CMMC Compliance: What Is Really Possible →
- CMMC Compliant MSP? How to Verify What Yours Claims →
- CMMC Level 2 Certification an RFP Wants? Bid Anyway →
- CMMC Trigger Events: A Triage Guide for Contractors →
- CUI in Commercial Microsoft 365: What to Do Now →
- Cybersecurity Questionnaire From Your Prime? Do This →
- DFARS 7021 Clause Found After Award? Read This First →
- Dropped Without CMMC? What a Prime Can Actually Do →
- Expired SPRS Score and a Bid Due? Fix It This Week →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5