Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

CUI Marked Drawings You Were Not Expecting? Do This

CUI marked drawings arrive in a quote package with no warning at all. An engineer opens the file and there it is across the top of the sheet: CUI. Nobody told you this job involved controlled information. The RFQ did not mention it. The buyer never said a word. And the file has already been in your email for four days, has been forwarded to two machinists, and is sitting in whatever your MSP uses for mail archiving. This is one of the most common ways a manufacturer discovers it has a compliance problem. Contain it, do not destroy it, and tell the sender in writing before you decide what it means. This article is part of Something Just Happened and You Need CMMC: A Triage Guide.

Four things not to do in the first hour

  • Do not delete it. Deleting data that arrived in error destroys the record of what you received and when. If this later becomes a dispute or an inquiry, that record is your defense. Isolate, do not erase.
  • Do not forward it to anyone else. That includes your attorney’s personal Gmail, your provider’s ticketing system and any consultant. Every forward creates another copy in another system.
  • Do not print it, and check whether somebody already has. Print queues and copier hard drives are systems too.
  • Do not answer the RFQ yet. Quoting the job is an implicit statement that you can handle the data.

Read the markings on the drawings before you react

What is printed on CUI marked drawings tells you which obligation just attached. Look for four things:

MarkingWhere it appearsWhat it tells you
Banner marking, CUI or CONTROLLED Top and bottom of each pageThe document is designated CUI. This is the baseline trigger.
Category marking, for example CUI//SP-CTI Appended to the bannerWhich CUI category applies. CTI is Controlled Technical Information, which covers most drawings, specifications and CAD models.
Limited Dissemination Control, such as NOFORN , FED ONLY or DL ONLY After the double slashWho may see it. NOFORN on a drawing in a shop with foreign national employees is an immediate personnel problem, not just an IT one.
Distribution statement B through F, and export control warningsUsually a block on the drawing faceExport control. ITAR or EAR obligations run in parallel with CUI handling and are enforced separately, with heavier penalties.

A drawing carrying an export control warning and a NOFORN marking is a materially different situation from a plain CUI banner, and it should be escalated the same day. If the CUI designation itself is new to you, start with What is Controlled Unclassified Information (CUI)?

Which of the three situations produced your CUI marked drawings

1. You were supposed to receive it, and the obligation was already yours

Check the contract or the purchase order behind the quote package. If DFARS 252.204-7012 is in it, the safeguarding obligation attached at signature. The drawing did not create the obligation, it just made it visible. This is the most common case, and it is the one where companies find out they have been out of compliance for two years without knowing it. See What DFARS 252.204-7012 Requires, in Plain English.

2. You were not the intended recipient

Wrong distribution list, wrong Smith, a buyer who sent one RFQ to fourteen suppliers at once. This is a CUI spillage on the sender’s side. You still have obligations, meaning containment and notification, but you are not the party that failed.

3. You were the intended recipient, but the data should not have been sent that way

A prime emails CUI drawings in the clear to a supplier with no safeguarding clause in place. It happens constantly. The sender has a problem, and now you have a copy of controlled information in an environment that probably cannot protect it, which means you have one too.

Find every copy of the CUI marked drawings

Before you talk to anyone, know the blast radius. CUI marked drawings spread faster than people expect, so check all of these:

  1. The original mailbox, plus every mailbox it was forwarded to
  2. Sent items, and any mailbox rule that auto-forwards or auto-files
  3. Mail archiving or journaling, usually run by your provider and often in a system you have never seen
  4. Mobile devices where that mailbox is synced, including personal phones
  5. Local downloads, the shared drive, the ERP attachment field, the quoting folder
  6. Backups, and their retention window
  7. Print queues, MFP storage, and anything physically printed
  8. Any CAM, nesting or CAD system the file was opened in, because these copy files silently
  9. Anything sent onward to your own subcontractors or vendors

Write it down with timestamps. That list is what makes every later conversation short and credible.

Is this a reportable cyber incident?

Usually not, and this distinction is worth getting right because the two paths have different clocks and different audiences.

CUI spillage or mishandlingCyber incident under DFARS 252.204-7012
What it isCUI ended up somewhere it should not have been, through misdirection or mismarkingCompromise, or an actual or potentially adverse effect on a covered contractor information system or the CUI on it
Who you tellThe sender or originator, and your contracting officer or prime’s contracts leadDoD via DIBNet, plus the prime
ClockPromptly. Same day is the standard to hold yourself toRapidly, within 72 hours of discovery
Extra obligationsContainment, disposition instructions from the originatorPreserve and protect affected media and images for at least 90 days, and support the DoD damage assessment

Receiving misdirected CUI is not automatically a cyber incident. It becomes one if there is evidence of compromise, meaning the mailbox was already breached, the file went to an unauthorized third party, or the drawing sat on a system you know to be infected. Note also that DIBNet reporting requires a DoD approved medium assurance certificate, which takes time to obtain. If nobody at your company holds one, find that out now rather than at hour 70. Detail is in 72-Hour DoD Breach Notification: DFARS Reporting Requirements.

Notify the sender, in writing

A short, factual email. No speculation, no apology for something you did not do, and no promises about deletion until you have disposition instructions.

On [date] we received [document/package] from [name]. The material carries CUI markings [quote the exact banner]. Our records indicate no safeguarding clause in the associated purchase order.

We have restricted access to the material and stopped further distribution. We have not deleted it, in order to preserve the record. Please confirm: (1) whether this transmission was intended, (2) your instructions for disposition, and (3) the contract vehicle and clauses under which this material was released.

Send it to the buyer and to the prime’s contracts or security function, not only to the person who sent the file. Buyers frequently do not know their own company’s CUI process. Keep the reply, because it is what documents that you acted correctly.

The consequence nobody mentions, which is that your scope just moved

The moment CUI lands in your general purpose email tenant and file shares, those systems are in scope for all 110 NIST SP 800-171 requirements. Not just the laptop it was opened on. The environment. For most small manufacturers that means a commercial Microsoft 365 tenant that was never designed to carry controlled information, because commercial Microsoft 365 was not built to meet the DFARS 252.204-7012 cloud conditions.

You have three real options:

  1. Do not take this work. Legitimate, and sometimes correct if it is one small job.
  2. Bring the whole environment up to 800-171. Expensive and slow, and it puts every laptop and every employee inside the boundary permanently.
  3. Reduce scope with an enclave. Put controlled information in a dedicated environment, keep it out of general email and file shares, and leave the rest of the company outside the boundary. This is why enclaves exist, and it is the difference between a 90 day answer and a two year program.

Related situations: your CUI is sitting in commercial Microsoft 365 covers the cleanup path in detail, and 90 days to get compliant covers what is achievable if a delivery date is already committed.

Week one, in order

  1. Contain access. Restrict the mailbox items and files holding the CUI marked drawings to the smallest possible group. Do not delete.
  2. Build the copy inventory with timestamps.
  3. Check the drawing for export control and dissemination markings, and screen for foreign national access if either is present.
  4. Send the written notification and request disposition instructions.
  5. Pull the purchase order and check for 252.204-7012, 7019, 7020, and FAR 52.204-21.
  6. Make the incident determination, spillage or cyber incident, and document how you reached it.
  7. Decide the scoping path before you quote any further work from this customer.
  8. Write it up. One page covering what arrived, when, where it went, what you did and what the originator said.

That one page is the artifact that matters. It converts a story about CUI sitting in your email into a record showing that you identified it, contained it, notified the originator and changed your process. Those are completely different positions to be in.

Next step

Before you decide whether to harden your environment or move CUI out of it, find out how far it has already spread. The CUI Scoping Workbook walks you through identifying every system that touches controlled information and drawing a defensible boundary around it. That decision sets your cost and your timeline for everything that follows.

Frequently asked

Questions about this topic

Should I just delete CUI marked drawings I was not supposed to receive?
Not on your own initiative. Deleting destroys the record of what you received and when, and disposition is the originator’s call. Restrict access, notify the sender in writing, and follow the disposition instructions you get back. Then document that you followed them.
Do I have to report receiving CUI by mistake to the DoD?
Typically no. Misdirected or mismarked CUI is a spillage handled with the originator and your contracting officer. The DFARS 252.204-7012 report to DIBNet within 72 hours is for cyber incidents, meaning compromise or an actual or potentially adverse effect on a covered system or the controlled information on it. If there is any indication of compromise, treat it as an incident and make the determination quickly, because the clock runs from discovery.
Do CUI marked drawings arriving once make us subject to CMMC?
They make you subject to safeguarding obligations under whatever clause is in your contract, most often DFARS 252.204-7012 and NIST SP 800-171. CMMC Level 2 certification assessments have been suspended since July 13, 2026, so certification is not currently the question. The 110 requirements and the annual affirmation are.
Our contract has no cybersecurity clauses. Are we off the hook?
You have less exposure, but not none. You now hold controlled information, and the export control and dissemination markings on the drawing apply regardless of what your purchase order says. Get the sender to state in writing which vehicle released the material, because that answer determines what you owe.
What if the drawing is marked CUI but our buyer says it is not really CUI?
Treat the marking as authoritative until the originator says otherwise in writing. A verbal assurance from a buyer is not a redesignation, and only the originating agency or an authorized holder can make that call. Get it in email, or keep handling the document as CUI.
Can we keep quoting the job while we sort this out?
You can quote, as long as you are explicit about your handling capability rather than proceeding quietly. A supplier who says it can machine the part and then explains how it will handle the technical data wins work. A supplier who quotes fast and is later found to have kept controlled information in a commercial mailbox loses the relationship and inherits the liability.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Table of Contents