# CUI marking

URL: /security/cui-marking

Set the system-high banner and the CUI designation indicator once, in Settings. Foxborne shows the banner on every screen and prints both marks on every report and case file from the next render.



A report that holds controlled unclassified information carries two marks. The banner says the document holds CUI, and the designation indicator says who designated it. An admin sets both once, and Foxborne applies them everywhere.

This page shows where each mark goes. It is not legal advice: your contract and your security office choose the category and the controls, and Foxborne puts them on the page.

## Before you start [#before-you-start]

* You need the **Admin** role.
* You have your program's marking decisions: who controls the information, the office, the CUI category, the dissemination control and a point of contact.
* You have the text of the system use notice your security office requires.

## What the two marks are [#what-the-two-marks-are]

32 CFR 2002.20 lets a CUI banner hold up to three elements. The control marking, CUI or CONTROLLED, is mandatory. Category markings are mandatory for CUI Specified, and limited dissemination control markings come third.

Double slashes separate the groups, and a Specified category takes an `SP-` prefix. A government-wide banner for export-controlled data under a Specified authority, limited to federal employees and contractors, reads `CUI//SP-EXPT//FEDCON`.

The designation indicator says who designated the information: at minimum the agency, by letterhead or a Controlled by line. It may appear on the first page or cover alone.

DoDI 5200.48 turns the designation indicator into a fixed block of five lines. DoD practice prints a generic CUI banner at the top and bottom of each page and moves the codes into the block.

| Code     | What the CUI Registry lists it as                                       | Where Foxborne prints it   |
| -------- | ----------------------------------------------------------------------- | -------------------------- |
| `EXPT`   | Export Controlled, a category marking                                   | The **CUI category** line  |
| `FEDCON` | Federal Employees and Contractors Only, a limited dissemination control | The **Dissemination** line |

Only the designating agency may apply a limited dissemination control, and other holders need its approval. A marking also does not make information CUI. The law, regulation or government-wide policy behind the category does, and marking information that does not qualify counts as misuse.

## How Foxborne places the marks [#how-foxborne-places-the-marks]

<Figure caption="The top of a report's first page: the banner, then the designation indicator. The banner repeats at the foot of every page. Neutral example values.">
  <MarkingBanner level="cui" />

  <DesignationIndicator by="Your organization" office="Your office" category="EXPT" control="FEDCON" poc="poc@example.mil" />
</Figure>

Foxborne's banner holds one word: **CUI** or **UNCLASSIFIED**. The category and the dissemination control go in the designation indicator, whose five lines match the DoDI 5200.48 block.

| Banner           | Color                              | Designation indicator                                   |
| ---------------- | ---------------------------------- | ------------------------------------------------------- |
| **CUI**          | Purple, `#502b85`, with white text | Printed on the first page of every report and case file |
| **UNCLASSIFIED** | Green, `#007a33`, with white text  | Not printed                                             |

<Figure caption="The UNCLASSIFIED banner. Reports under it carry no designation indicator.">
  <MarkingBanner level="u" />
</Figure>

The **Marking** panel describes these as **the Astro UXDS banner colors used across defense systems**. The banner is a fixed strip at the top of every screen, and its text repeats as the first segment of the status bar.

Classified deployments do not set their banner here. The marking dialog says so: &#x2A;*A classified deployment sets its banner from its own accreditation, not from here.**

## Set the marking [#set-the-marking]

<Steps>
  <Step title="Open the Marking panel">
    Go to **Settings**. The **Marking** panel reads **System-high marking, in the Astro UXDS banner colors used across defense systems**.
  </Step>

  <Step title="Show the banner">
    Turn on **Show the marking banner**, described as **Fixed at the top of every screen and repeated in the status bar**. The switch applies at once, with no confirmation. The console confirms **Marking banner shown**, and the audit log records **Changed marking** with the detail **Banner shown**.
  </Step>

  <Step title="Fill in the designation indicator">
    Select **Edit** on **Designation indicator**, described as **Printed on the first page of every report and case file**. The **Marking** dialog opens with the note &#x2A;*Applies to the banner, every report and every case file from the next render.**

    | Field                     | What goes in it                                                               | Printed as                      |
    | ------------------------- | ----------------------------------------------------------------------------- | ------------------------------- |
    | **Banner**                | **CUI** or **UNCLASSIFIED**                                                   | The banner text, top and bottom |
    | **Controlled by**         | The organization that controls the information                                | Line 1, Controlled by           |
    | **Office**                | The office that made the determination                                        | Line 2, Controlled by           |
    | **CUI category**          | Every CUI category in your reports, such as `EXPT`                            | Line 3, CUI category            |
    | **Dissemination control** | A limited dissemination control such as `FEDCON`, or a distribution statement | Line 4, Dissemination           |
    | **Point of contact**      | A phone number or an office mailbox                                           | Line 5, POC                     |
  </Step>

  <Step title="Save">
    Select **Save**. The console confirms **Marking saved**, and the banner and status bar redraw. The audit log records **Changed marking** on **Settings**, with the banner and the category as the detail, such as **CUI, EXPT**.
  </Step>
</Steps>

<Callout type="marking" title="Lines one and four come from the contract">
  On a DoD program, line one names the DoD Component, and DCSA's marking job aid fills it with the Government Contracting Activity. For export-controlled technical information, line four holds a distribution statement letter rather than a dissemination control. Read both off the contract before the first report goes out.
</Callout>

DoD's marking training aid accepts an organizational email for the point of contact. It also says contractors may create and mark CUI and appear as the point of contact.

## What changes when you save [#what-changes-when-you-save]

* **The banner.** It redraws at the top of every screen and at the start of the status bar.
* **Reports.** Each incident report takes the new marking at the top and bottom of the page, with the designation indicator under the top banner.
* **Case files.** The **Export** dialog shows the marking chip and a summary such as **Category EXPT, FEDCON, controlled by** your organization. Its hint reads &#x2A;*L1 and L2 files carry the banner string. The case file prints it at the top and bottom of every page, with the designation indicator on the first.**
* **The UNCLASSIFIED case.** Under **UNCLASSIFIED**, reports carry no designation indicator, and the export dialog reads **No CUI designation**.

A case file exported before the change was rendered with the old marking. Export it again if it needs the new one, as [Export a case file](/investigate/export) describes.

## Set the system use notice [#set-the-system-use-notice]

<Steps>
  <Step title="Open the notice">
    In **Settings**, under **Marking**, find **System use notice**, described as **Shown on the sign-in page and acknowledged before every session**. Select **Edit**.
  </Step>

  <Step title="Write the notice">
    The **System use notice** dialog notes &#x2A;*Everyone acknowledges this before signing in. Changing it is audited.** Enter the text your security office requires: the dialog refuses an empty notice.
  </Step>

  <Step title="Save">
    Select **Save**. The console confirms **Saved**. The audit log records **Changed settings** on **System use notice**, with the detail **Text updated**.
  </Step>
</Steps>

The example notice says the system holds CUI, including export-controlled technical data. It adds that use is monitored and recorded, and that access is limited to authorized US persons. On the sign-in screen the notice sits above the **I understand and consent** checkbox, and each acknowledgment writes **Acknowledged notice** to the audit log.

## Check the result [#check-the-result]

* The banner shows at the top of every screen and at the left of the status bar.
* An incident's **Report** tab shows the marking at the top, the designation indicator under it and the marking again at the foot.
* The **Export** dialog shows the marking chip and the designation summary.
* The audit log's **Administration** filter lists your **Changed marking** and **Changed settings** entries.

## Troubleshoot [#troubleshoot]

**No banner on screen.** **Show the marking banner** is off. Turn it on in **Settings**.

**Reports carry no designation indicator.** The banner is set to **UNCLASSIFIED**, and the export dialog reads **No CUI designation**. The indicator prints only under **CUI**.

**A report still shows the old marking.** The marking applies from the next render. Open the report again.

**The program needs a classified banner.** Foxborne offers **CUI** and **UNCLASSIFIED** only. A classified deployment sets its banner from its own accreditation.

## Next [#next]

* [Export-controlled evidence](/security/export-control) gates evidence marked EXPT by US person status.
* [Markings and handling](/concepts/markings) covers the handling side of the same marks.
* [Export a case file](/investigate/export) shows the marking on the way out.
