A CUI media policy template for subcontractors should require every hardcopy and digital medium containing CUI to display applicable CUI markings, authorized distribution limitations, and an identifiable owner where practical. The seven clauses below give proposal teams a ready-to-customize policy that supports NIST SP 800-171 Rev. 2 and CMMC 2.0 Level 2 practice MP.L2-3.8.4, while giving primes and assessors clear evidence of how subcontractor media will be identified and controlled.
Why must policy come before tooling?
Tools can print labels, apply sensitivity markings, encrypt USB drives, and restrict external sharing, but they cannot determine which CUI category, limited dissemination control, or contract-specific distribution statement applies. Those decisions must originate with the contract, the prime contractor’s flowdown requirements, the authorized CUI source, and the organization’s designated CUI authority.
For a federal proposal writer, the policy is also the narrative bridge between an RFP requirement and operational evidence. A subcontractor CUI media policy should tell the evaluator who decides the marking, what is placed on a physical or digital medium, what happens when a device is too small to label, and how the company prevents personnel from inventing markings that were not authorized by the Government or prime.
Under MP.L2-3.8.4, the objective is not merely to use a “CUI” sticker. Media must be marked with applicable CUI markings and applicable distribution limitations. NARA CUI marking guidance should be used for the marking format, while the contract, CUI Registry category, prime instructions, or Government-provided source material should determine the actual category and dissemination limitations. Media ownership is addressed separately by MP.L2-3.8.8, but including it on a label or inventory record makes lost-media response and accountability more practical.
What should a CUI media policy template for subcontractors include?
The following template is written as policy text. Replace every bracketed field before approval. Keep the defined responsibilities aligned with the organization’s System Security Plan, subcontract terms, media inventory process, and incident-response procedures.
Clause 1: Purpose and policy statement
Policy: [ORGANIZATION NAME] shall mark media containing Controlled Unclassified Information (CUI) with applicable CUI markings and authorized distribution limitations before the media is stored, transported, shared, or made available to personnel. This policy applies to CUI received from [PRIME CONTRACTOR/GOVERNMENT CUSTOMER], CUI created in performance of [CONTRACT OR PROGRAM NAME], and CUI derived from those sources.
Rationale: This clause establishes that marking is required for both received and internally generated CUI, not only for documents delivered by the prime.
Clause 2: Scope of covered media
Policy: Covered media includes paper records, drawings, binders, removable storage devices, external hard drives, optical media, mobile devices approved for CUI, backup media, virtual-machine images, system export files, and electronic repositories that store CUI. For this policy, a container, sleeve, binder spine, storage case, or repository banner may serve as the media marking location when direct marking of the individual item is impracticable.
Rationale: The clause prevents a narrow interpretation that treats only USB drives and printed reports as media. It also accommodates small or technically constrained media consistent with applicable NARA guidance.
Clause 3: Required CUI markings
Policy: Personnel shall apply the CUI control marking and any applicable category, subcategory, or limited dissemination control authorized by the originating contract, source document, or [CUI PROGRAM MANAGER/TITLE]. At a minimum, a physical label or electronic display shall visibly alert an authorized recipient that the medium contains CUI. Personnel shall not create, alter, or remove CUI category markings, limited dissemination controls, or decontrol instructions without authorization from [CUI PROGRAM MANAGER/TITLE] or the originating authority.
Rationale: A generic “Confidential” or “Sensitive” label does not satisfy the CUI marking objective. The policy also avoids a common subcontractor error: assigning a limitation such as NOFORN or a category label without an authorized basis.
Clause 4: Distribution limitations and handling instructions
Policy: Media containing CUI shall display or reference applicable distribution limitations provided by [PRIME CONTRACTOR/GOVERNMENT CUSTOMER], including any contractually required distribution statement, limited dissemination control, export-control notice, or recipient restriction. Where direct marking is not feasible, the limitation shall appear on the protective container, accompanying transmittal record, repository access banner, or inventory entry. Media shall be distributed only to individuals with an authorized work-related need and access approved under [ACCESS CONTROL POLICY NAME].
Rationale: Distribution limitations are not interchangeable with CUI markings. This language requires the subcontractor to preserve restrictions supplied by the authorized source instead of substituting internal handling labels.
Clause 5: Media label content and ownership
Policy: To the extent size and media type permit, labels for CUI media shall include: CUI; applicable authorized category or dissemination marking; applicable distribution limitation; [ORGANIZATION NAME] or [PROGRAM NAME]; an owner, custodian, asset identifier, or inventory reference; and handling or return instructions when required by [CONTRACT OR PRIME FLOWDOWN]. Labels shall be legible, durable, and placed where they are visible during normal handling.
Rationale: Ownership information supports the related MP.L2-3.8.8 expectation that media have an identifiable owner, while an asset or inventory reference lets the organization identify the device without exposing unnecessary project details on its exterior.
Clause 6: Digital media and repository markings
Policy: For digital media, [ORGANIZATION NAME] shall apply CUI markings through approved file labels, document headers or footers, repository banners, folder notices, media labels, or equivalent technical methods. A removable device storing CUI shall have an external CUI label unless a documented physical limitation prevents it. When labeling the device is impracticable, the approved container and asset record shall identify the device as CUI media and identify its responsible owner or custodian.
Rationale: A file-level label alone may not alert a person handling the device, and a device label alone may not alert a person who receives an exported file. The policy calls for a combination appropriate to the medium.
Clause 7: Verification, exceptions, and reporting
Policy: [PROGRAM MANAGER], [INFORMATION SYSTEM SECURITY MANAGER], and designated media custodians shall verify required markings during media issuance, transfer, inventory, and disposal activities. Personnel who discover unmarked, incorrectly marked, or improperly distributed CUI media shall stop further distribution when safe to do so and report the condition to [SECURITY INCIDENT CONTACT] within [TIME PERIOD]. Exceptions must be documented, approved by [APPROVING ROLE], and include compensating marking or container controls. Records of reviews, exceptions, and corrective actions shall be retained for [RETENTION PERIOD].
Rationale: An assessor will look for evidence that the policy operates beyond initial training. This clause creates repeatable verification points and a defined response path for labeling defects.
What attachments and exhibits should accompany the policy?
The policy should remain stable while the operational details appear in controlled attachments. This approach lets a proposal response cite a mature policy without forcing a full policy revision every time a label printer, collaboration platform, or prime-specific legend changes.
| Attachment or exhibit | Purpose | Realistic implementation detail |
|---|---|---|
| Exhibit A: Approved marking examples | Shows labels for paper, USB media, backup drives, binders, and repository banners. | Include a 1-inch-by-2.625-inch Brady M211 label example reading CUI | [AUTHORIZED LDC] | Asset: IT-USB-042 | Owner: [ROLE]. |
| Exhibit B: Digital labeling standard | Maps policy requirements to file and repository labels. | Microsoft Purview sensitivity label CUI applies a footer containing CONTROLLED UNCLASSIFIED INFORMATION; label publishing is limited to the [CUI AUTHORIZED USERS] Entra ID group. |
| Exhibit C: Media register | Documents device ownership, serial number, CUI status, transfer history, and disposition. | Maintain the register in a restricted SharePoint list with version history enabled and access limited to Media Custodians and the ISSM. |
| Exhibit D: Prime flowdown matrix | Identifies the source of each required marking and distribution restriction. | Record the RFP section, subcontract clause, CUI category, authorized limitation, approving source, and affected deliverable or system. |
| Exhibit E: Exception form | Documents small-media or technical-labeling exceptions. | Require asset ID, reason direct marking is impracticable, container marking method, approver, expiration date, and corrective action. |
For removable-media controls, the exhibit may also identify supporting settings without presenting them as substitutes for policy. For example:
Microsoft Defender for Endpoint Device Control Device type: Removable storage Default action: Deny write access Allowed exception: [CUI-ENCRYPTED-USB GROUP] Required condition: BitLocker To Go encryption enabled Media register field: Asset ID and assigned custodian Physical label: CUI plus authorized limitation and asset reference
Who approves the policy and how often should it be reviewed?
[EXECUTIVE SPONSOR OR PRESIDENT] should approve the policy because it establishes an organization-wide handling obligation. [ISSM OR FSO], [CONTRACTS MANAGER], [CUI PROGRAM MANAGER], and [QUALITY MANAGER] should review it before approval. Contracts review is especially important because the organization must preserve prime and Government restrictions rather than normalize them into a generic internal label.
Review the CUI media-marking policy at least annually and within [30] days of a material contract award, prime flowdown change, CUI category change, finding from an internal review, CMMC assessment observation, or media-related incident. Retain the approval record, revision history, affected training updates, and evidence that superseded labels or job aids were removed from use.
How should different industries edit the template?
| Industry context | Recommended edit | Proposal-writing emphasis |
|---|---|---|
| Defense manufacturing | Add controlled technical information, shop-floor travelers, CAD exports, portable test equipment, and production backup media to the scope. | Explain how drawing packets and removable media remain marked between engineering, production, and quality functions. |
| Architecture and engineering | Add plan sets, site surveys, geospatial files, printed specifications, and field tablets. | Address large-format drawings and container marking when each sheet cannot carry a practical exterior label. |
| Managed IT or SaaS subcontractor | Add encrypted backups, exported logs, tenant data extracts, virtual-machine snapshots, and approved administrative workstations. | Map repository banners, Purview labels, and export procedures to the customer’s CUI boundary. |
| Research and professional services | Add notebooks, interview records, analytical datasets, working papers, and conference or travel materials. | State how personnel distinguish CUI from public research outputs before sharing drafts externally. |
Before submitting the RFP response, tailor the bracketed fields to the prime’s flowdowns and attach the completed marking examples as evidence that the policy can be executed on day one.