Skip to main content
Shakewell

Explainer

Distribution Statements, Decoded

Every DoD technical document carries one of six statements declaring who may receive it. Here's what each one means — and the part the instruction can't do for you: enforcement.

The Six

A Through F, Plainly

Under DoD Instruction 5230.24, technical documents carry a distribution statement — access control that is distinct from classification and travels with the document for its whole life. Condensed:

StmtAuthorized audienceIn practice
AApproved for public release — distribution is unlimited.The only statement compatible with a public website.
BU.S. Government agencies only.Other requests referred to the controlling DoD office.
CU.S. Government agencies and their contractors.The common statement on contractor-supporting technical data.
DDepartment of Defense and U.S. DoD contractors only.Tighter than C — non-DoD agencies drop out.
EDoD components only.Contractors drop out entirely.
FFurther dissemination only as directed by the controlling office.The most restrictive; used where the controlling office must decide case by case.

The Real Requirement

A Marking Is a Promise. A System Keeps It.

Access-controlled entry to a technical content platform
'Distribution C' as an account rule, not a title-page decoration — permission-scoped search, watermarked downloads, and an audit trail.

Read operationally, a distribution statement is a permission-scoping requirement: “U.S. Government agencies and their contractors” is an access-control expression wearing legal language. Files can't enforce it — which is why the classic failures are all structural: markings that disagree with the share drive's reality, re-marked documents whose old revisions stay reachable, correctly-marked PDFs forwarded beyond recall. The copy problem, with statutory stakes.

The system-shaped answer is the one we build: per-document scoping by organization and role, permission-aware search that never advertises what a user can't open, per-download watermarking, version supersession so a re-marked document's history behaves, and event capture that answers “who accessed what, when” — the Content Portal's access model doing precisely this job. Distribution statements also travel with siblings — export-control markings and CUI among them — and the same enforcement architecture serves all of them. If your compliance story for controlled technical data is “the statement is printed on page one,” the honest question is who's enforcing page one. The answer should be the platform.

FAQ

Questions We Hear

What governs distribution statements, and are they classification?

DoD Instruction 5230.24, Distribution Statements on Technical Documents (current issuance January 2023), requires DoD technical documents to carry one of six statements, A through F. They are not classification — a document can be entirely unclassified and still carry Distribution D — but they are binding access control: the statement declares who may receive the document and routes everyone else to the controlling DoD office. They also interact with other markings (export-control warnings, CUI) rather than replacing them.

Who assigns the statement, and can it change?

The controlling DoD office — typically the program office responsible for the technical data — assigns the statement when the document is created, and owns changes to it. Statements do get revisited: restrictive markings are expected to be reviewed rather than live forever, and downgrading (say, F toward wider distribution) is a controlling-office decision on a deliberate cycle. For contractors the practical rule is simpler: you apply what the contract and controlling office direct, and you never widen distribution on your own judgment.

What do distribution statements demand from a delivery platform?

Enforcement, not decoration. A statement printed on a title page is a promise; the system serving the document is what keeps it. That means per-document access scoping that can express 'U.S. Government agencies and their contractors' as actual account and organization rules, permission-aware search that never advertises documents to users who can't open them, watermarking and download controls for accountability, and an audit trail answering who accessed what, when. If your library serves mixed statements from one repository — most do — the platform's permission model is your compliance story.

What are the common failure modes?

The usual three: the statement on the document disagreeing with the system's actual access rules (the marking says D, the share drive says everyone); revision drift, where a re-marked document's old versions remain accessible under the old statement; and the email problem — a correctly-marked PDF forwarded outside its audience, unrecoverable. All three are structural: files carry markings but can't enforce them. Controlled distribution is precisely the job a governed delivery platform exists to do.

Get In Touch

Enforced, or Just Printed?

If your controlled documents live on a share drive with their statements as decoration, the gap between marking and enforcement is your exposure. We build the platform that closes it.