I’m totally aging myself (due to reruns) but The Jetsons (created by William Hanna and Joseph Barbera (1962-63)), promised us a future where you pushed a button and the “Food-a-Rac-a-Cycle,” a machine, made whatever you wanted. Dinner. Clothes. Maybe an off-brand Spacely sprocket or two. Additive manufacturing has gotten us remarkably close. Give a 3D printer the right digital file, the right material, and the right process parameters, and out comes the part. George Jetson would recognize the concept immediately. What George did not have was the Defense Federal Acquisition Regulation Supplement (DFARS).

For defense contractors, the hard part is not simply protecting the thing that comes out of the printer. It is protecting, and understanding the rights in, the digital information that makes the thing possible. That raises three separate questions: What information is Controlled Unclassified Information (CUI)? What information did the contractor develop? And what rights did the government acquire in it? In additive manufacturing, the answers often wind up in the same file.

Key Takeaways

  • The printed part is only the beginning. The digital thread may extend from the original build file through engineering software, machine-specific files, printer-generated data, inspection records, subcontractors, removable media, and archives.
  • The physical part, the technical data needed to reproduce it, and the contractor’s manufacturing know-how are different things. Permission to ship the part does not necessarily mean permission to send its digital build package.
  • CUI status and government technical-data rights are different questions. Ownership, government license rights, delivery obligations, export controls, and proprietary rights need to be treated separately.
  • Do not wait until the government asks for the files. Identify government-furnished inputs, document internally developed processes, make the necessary assertions, use the proper legends, and address technical-data rights and cybersecurity requirements early.

The Part Is Only Half the Problem

CUI is government-owned or government-controlled information that requires safeguarding or dissemination controls but is not classified. For defense contractors, that can include Controlled Technical Information (CTI), export-controlled information, and other information falling within an authorized CUI category. Start with the build file. An STL, STEP, AMF, or proprietary machine file can contain much of what someone needs to manufacture a component. If a government-furnished file contains CTI about a defense article, it may be CUI.

But focusing only on the build file misses the larger problem. A technical data package may include drawings, material specifications, process requirements, acceptance criteria, inspection protocols, post-processing instructions, and nondestructive evaluation standards. A statement of work may reveal sensitive technical or program information. Inspection criteria may disclose something about how a part is expected to perform. And the absence of a conspicuous CUI marking does not necessarily end the inquiry. Contractors still need to know what information they have and what authority governs its protection.

Follow the File

Here is where additive manufacturing gets complicated. The government delivers technical data. An engineer imports it into build-preparation software. The software creates machine-specific information. An operator sends the job to the printer. The printer generates logs, telemetry, and perhaps layer images. The quality group produces computed tomography scans, inspection data, and acceptance records.

The original file has been busy. Some of the information created along the way may contain or reveal the same controlled information found in the government’s technical data. Some may reflect the contractor’s own manufacturing knowledge. Some may do both. So putting the original file on a protected server is not enough. A contractor needs to know where the information goes after someone opens it, which applications touch it, which machines receive it, what derivative files are created, where inspection results go, whether subcontractors can access them, whether removable media is involved, and what ultimately gets archived. For an additive manufacturer, the CUI boundary can extend well beyond the folder conveniently labeled “CUI.”

The Bracket Is Not the Recipe

Here is the part George Jetson would understand. The meal and the “Food-a-Rac-a-Cycle” (See.e.g., The Jetsons recipe are two different things. So are the printed component and the technical information needed to reproduce it. A titanium bracket sitting on the loading dock may not itself be CUI. A build file containing CTI about that bracket may be.

That distinction matters when information moves to suppliers and subcontractors. Permission to ship the physical part does not necessarily mean permission to send its digital build package to another printer. “The part isn’t classified” answers the wrong question. The technical data may still be subject to CUI safeguarding requirements, export controls, contractual restrictions, or more than one of them at once.

Now, Who Owns the Recipe?

Suppose the government provides the design, material requirements, and acceptance criteria. Your engineers make it printable. They determine the build orientation, develop the support strategy, adjust scan parameters, refine heat treatment and post-processing, and, after repeated builds, develop process-control information that lets them make the part reliably instead of merely making it once. The government supplied the destination. Your company figured out how to get there.

Who gets that information? At that point, we have left pure cybersecurity and entered technical-data rights. The government’s rights in technical data depend on the applicable contract clauses, the type of data involved, and how the underlying item, component, or process was developed. Depending on the circumstances, the government may obtain unlimited rights, government purpose rights, limited rights, or specifically negotiated license rights. Private-expense development can make a major difference. It does not answer every other question.

“We paid for it” does not necessarily determine whether information must be delivered. It does not determine whether particular information is CUI. Nor does it eliminate the need for proper assertions and markings. Ownership, government license rights, delivery obligations, and CUI status are different issues. Treat them that way.

The Computer Does Not Care Who Paid for Development

Unfortunately, the files themselves rarely cooperate. A machine-parameter file may contain a government-specified material requirement next to a scan strategy the contractor developed at private expense. An inspection report may incorporate government acceptance criteria while also revealing proprietary process capability. The lawyers may see two categories of information. The printer sees one file.

That is why contemporaneous records matter. If a company develops additive manufacturing know-how at private expense, it should document that development while the work is being done. Make sure to maintain your files as well as Rosey the Robot kept the apartment for “Mr. J.”  This means identifying government-furnished inputs, tracking internally developed processes, and preserving evidence of development funding. When doing this, use the appropriate restrictive legends and assertions and think forward – don’t try to reconstruct the story three years later because a contracting officer has asked for the build package. Memory and woulda/coulda/shoulda is not a data-rights strategy.

Map the Digital Thread Before Someone Else Does

Cybersecurity deserves the same discipline. Where DFARS 252.204-7012 applies, covered defense information residing on or transiting through a covered contractor information system triggers the clause’s safeguarding requirements, including its National Institute of Standards and Technology Special Publication 800-171 (NIST SP 800-171) requirements. Cybersecurity Maturity Model Certification (CMMC) adds another layer to that compliance structure. The Department of Defense’s implementation of CMMC continues to evolve, including its July 2026 decision to suspend the Phase 2 requirements that had been scheduled to begin later in the year. That development did not make existing contractual cybersecurity obligations disappear.

For an additive shop, the exercise is straightforward even if the answers are not: map the actual flow of information. Start where build files arrive. Follow them into engineering software. Follow them to the printer. Follow the data the printer generates, the inspection records, and the archive. Then figure out who can reach each stop along the way. That exercise is usually more useful than staring at an information-security diagram that bears only a passing resemblance to what actually happens on the shop floor.

Do Not Wait Until They Ask for the Files

The same rule applies to technical-data rights: deal with them early. If proprietary machine parameters, support strategies, manufacturing methods, or process information matter to the company, identify them during proposal preparation and contract formation. Determine what the solicitation requires the contractor to deliver. Make the necessary assertions. Use the proper legends. Negotiate rights where appropriate.

The bad time to have that discussion is after the government asks for the files (or, as Astro would say: “Ruh-roh.”). Decontrol does not necessarily settle the matter either. Information that is no longer subject to CUI controls does not automatically become public or free of other restrictions. Government license rights, contractual obligations, export controls, proprietary rights, and trade secret protections can continue to matter. One label disappearing does not erase the rest of the contract.

“Jane! Stop this crazy thing!”

Additive manufacturing makes an old government-contracting problem harder because the product, the technical data, and the manufacturing know-how can become tightly intertwined. The government may supply the design. The contractor may supply the process that makes the design manufacturable. The resulting files may contain pieces of both.

That is why additive manufacturers need to do more than protect CUI. They need to know what they received, what they developed, what they agreed to deliver, what rights the government obtained, and where the information goes once the printer gets involved. The government may have ordered the sprocket. It did not necessarily buy the Food-a-Rac-a-Cycle. Sort that out before anyone asks for the recipe.