Controlled Unclassified Information, or CUI, is unclassified federal information that a law, regulation, or Government-wide policy requires an agency to protect with safeguarding or dissemination controls. Before the program existed, more than 100 different markings for sensitive information were scattered across the executive branch, which created confusion about what to protect and how. Today a single Government-wide framework governs CUI, and for the roughly 220,000 companies in the Defense Industrial Base, getting it right is the difference between winning federal work and losing eligibility for it. This guide explains what CUI is, the two types you will encounter, how it differs from Federal Contract Information, and what protecting it actually requires.
Why Controlled Unclassified Information Matters Now
CUI sits between two extremes. It is not classified national security information, so it does not carry the restrictions of Confidential, Secret, or Top Secret material. It is also not freely shareable, because the government has determined that releasing it could cause real harm. That middle ground is exactly where most organizations struggle, because the obligation to protect CUI is easy to overlook until an auditor, a contracting officer, or a breach makes it impossible to ignore.
A Government-Wide Program, Not Just a Defense Rule
The most common misunderstanding is that CUI is a Department of Defense concept. It is not. The CUI Program was established by Executive Order 13556 in November 2010, and the National Archives and Records Administration (NARA), through its Information Security Oversight Office, serves as the Executive Agent that oversees it across the entire federal executive branch. In September 2016, NARA issued the final rule at 32 CFR Part 2002, which set uniform policy for designating, safeguarding, disseminating, marking, decontrolling, and disposing of CUI.
The program replaced a patchwork of agency-specific labels such as For Official Use Only and Sensitive But Unclassified with one consistent system. That history matters because it explains why CUI rules feel rigid. They were designed to remove the inconsistency that let the same document be treated as restricted at one agency and shared openly at another. Every federal agency, from the Environmental Protection Agency to the General Services Administration, now operates under the same baseline, and any contractor that handles CUI on behalf of an agency inherits those obligations.
The Compliance Stakes for Contractors
For defense contractors, CUI is not an abstract policy. Protecting it is a contractual requirement enforced through DFARS clause 252.204-7012, which points to the security controls in NIST SP 800-171, and verified through the Cybersecurity Maturity Model Certification program. An organization that handles CUI for a defense contract must implement those controls, document them, and increasingly prove that implementation to an independent assessor rather than simply attesting to it.
The cost of getting this wrong is concrete. A contractor that misjudges what counts as CUI can under-protect sensitive data and expose itself to breaches and legal liability, or over-protect everything and waste resources on controls it never needed. Both outcomes are expensive, and both trace back to the same root cause: an unclear understanding of what CUI is and where it lives. Understanding the broader framework of CMMC compliance starts with getting this foundation right.
What Controlled Unclassified Information Actually Is
The federal definition is precise, and the precision is the point. Controlled Unclassified Information is information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. In the words of the rule itself, all unclassified information throughout the executive branch that requires any safeguarding or dissemination control is CUI.
Two parts of that definition carry the most weight. First, the obligation must come from a law, regulation, or Government-wide policy, not from an individual employee deciding something feels sensitive. Second, the information must not already be classified under Executive Order 13526 or the Atomic Energy Act. If it meets both conditions, it is CUI, and the standardized handling rules apply.
CUI Basic vs CUI Specified
CUI comes in two forms, and the distinction determines how you handle it. The difference is whether the authority that requires protection also dictates specific handling rules. Most organizations encounter both types, often within the same project, which is why understanding the split is essential before you build any safeguarding process.
| Aspect | CUI Basic | CUI Specified |
|---|---|---|
| Handling controls | The standard safeguarding requirements in 32 CFR Part 2002 | Specific controls set by the authorizing law, regulation, or policy |
| Source of rules | The uniform CUI baseline | The underlying statute or regulation for that category |
| Dissemination | Per the standard CUI rules | Per the specific authority, with CUI Basic rules filling any gaps |
| Typical examples | General personnel or privacy information | Certain tax, export control, or law enforcement categories |
In practice, CUI Basic is the default. When a category requires protection but the governing authority does not spell out particular handling instructions, you apply the standardized controls in 32 CFR Part 2002. CUI Specified is the exception that demands extra attention, because the authorizing law imposes its own requirements that may go beyond or differ from the baseline. Where a Specified authority is silent on a particular point, the CUI Basic rules fill the gap, so you are never left without a standard to follow.
How CUI Is Organized in the CUI Registry
NARA maintains the CUI Registry at archives.gov/cui as the authoritative, Government-wide repository of every approved category. The categories and subcategories listed there are the exclusive designations for CUI, which means an agency cannot invent its own label outside the Registry. This is what makes the program consistent across more than 100 departments and agencies that once used their own systems.
The Registry organizes information into more than 20 groupings that cover the full range of sensitive but unclassified data. Common categories include privacy information such as Social Security numbers and health records, law enforcement sensitive information, proprietary business information, tax information, export-controlled information, and controlled technical information. For defense contractors, controlled technical information is often the most relevant category, because it covers technical data with military or space application, including engineering drawings, specifications, and source code generated under a contract.
Controlled Unclassified Information vs Federal Contract Information
One of the most persistent points of confusion in federal contracting is the relationship between CUI and Federal Contract Information, or FCI. The two are related, but they come from different authorities and carry very different protection requirements. Confusing them leads directly to scoping errors that inflate cost or leave gaps.
| Aspect | Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) |
|---|---|---|
| Defining authority | FAR 52.204-21 | Executive Order 13556 and 32 CFR Part 2002 |
| What it covers | Non-public information provided by or generated for the government under a contract | Information that law, regulation, or policy requires to be safeguarded |
| Protection standard | 15 basic safeguarding requirements | NIST SP 800-171 (110 requirements) for defense contractors |
| CMMC level | Level 1 | Level 2 or Level 3 |
The table shows why the distinction is more than academic. FCI is the broad set of non-public information tied to a contract, and it requires a basic level of cyber hygiene. CUI is the subset that a specific authority says must be safeguarded, and it requires the far more demanding controls of NIST SP 800-171. The protection burden, the documentation, and the assessment all scale up sharply when information crosses from FCI into CUI.
Where the Two Overlap in Defense Contracting
For a contractor, information that qualifies as CUI is generally also FCI, because the contractor holds it under a government contract and it is not intended for public release. The reverse is not true. Not all FCI rises to the level of CUI, because much contract information carries no specific safeguarding mandate. A useful way to think about it is that CUI is the more sensitive island inside the larger sea of FCI, and the controls that protect that island are significantly stronger.
It is worth remembering that CUI exists well beyond contracting. A federal agency can create and hold CUI that is never tied to any contractor, because the program is Government-wide. For organizations in the Defense Industrial Base, though, the practical question is almost always the same: which information in your environment carries a safeguarding obligation, and have you identified all of it. That question is where protection begins.
How to Identify and Protect Controlled Unclassified Information
Knowing the definition is necessary but not sufficient. The organizations that handle CUI well treat identification, marking, and protection as a connected process rather than three separate tasks. The work begins with finding the data and ends with controls that an assessor can verify.
Find Where CUI Lives in Your Environment
You cannot protect what you cannot locate, so the first step is mapping where CUI is created, received, processed, stored, and transmitted. That means tracing data flows across systems, including the middleware, file transfers, and cloud platforms that are easy to overlook, and building an asset inventory that ties each system to the information it touches. This exercise defines your protection boundary, and a boundary drawn too wide pulls unnecessary systems into scope while one drawn too narrow leaves sensitive data exposed.
For defense contractors, this is the heart of CMMC preparation. A disciplined approach to scoping your environment keeps the assessment focused and the cost contained. Many organizations go further and isolate CUI inside a dedicated enclave, and the practical steps for defining your CUI boundaries are worth studying before you finalize any architecture.
Mark, Safeguard, and Handle CUI Correctly
Once you know where CUI lives, it must be marked according to the categories in the CUI Registry so that everyone who handles it knows what it is and how to treat it. Marking is not cosmetic. It drives the safeguarding and dissemination decisions that follow, and inconsistent marking is one of the fastest ways to create a finding or a leak. Safeguarding then covers how the information is stored and transmitted, while dissemination controls govern who may receive it.
One nuance trips up even experienced teams. Decontrolling CUI, which removes the safeguarding requirements when they are no longer needed, is not the same as authorizing public release. Those are separate determinations, and treating them as one is a common mistake. Until information is formally decontrolled and cleared for release through the proper process, it keeps its protections.
Meet the Required Security Controls
For most defense contractors, protecting CUI means implementing the 110 security requirements of NIST SP 800-171, which DFARS 252.204-7012 has required since 2017 and which the CMMC program now verifies at Level 2. These controls span access control, audit and accountability, configuration management, identification and authentication, incident response, and more, and each one must be both implemented and evidenced. The detailed obligations for primes and subcontractors are covered in the guide to CMMC requirements, and the assessment specifics appear in the breakdown of CMMC Level 2.
This is where many organizations decide they need help, because the gap between knowing the controls and proving them is wide. Elevate Consult works with organizations across the Defense Industrial Base to identify their CUI, define the boundary, implement the required controls, and prepare for assessment. To pressure-test where your environment stands, you can talk to an advisor before your next deadline.
The Real Cost of Getting CUI Wrong
The consequences of mishandling Controlled Unclassified Information reach beyond a failed audit. When an affirming official certifies a security posture to the government, that certification is a legal representation, and an inaccurate one can create exposure under the False Claims Act. The standard is not whether an organization intended to deceive, but whether it knew or should have known that its representation was wrong, which raises the stakes for any contractor that certifies compliance without validating it.
Beyond legal exposure, the practical risk is lost eligibility. A contractor that cannot demonstrate proper protection of CUI can lose the ability to win or keep federal work, and in a market where demand for assessments already exceeds capacity, falling behind is costly to reverse. The contractors that treat CUI seriously, identify it completely, and protect it with verifiable controls are the ones that stay eligible and competitive.
Conclusion
Controlled Unclassified Information is not a defense-only rule or a box to check. It is a Government-wide framework, built on Executive Order 13556 and 32 CFR Part 2002, that determines how sensitive but unclassified federal information must be protected. For the organizations that handle it, the practical work comes down to three things: understanding what CUI is, finding all of it in your environment, and protecting it with controls you can prove.
The difference between CUI Basic and CUI Specified, the boundary between CUI and FCI, and the requirements of NIST SP 800-171 are not trivia. They are the foundation of every compliant program, and getting the foundation wrong makes everything built on top of it harder to defend. Organizations that invest in clarity early spend far less time and money correcting course later.
If your team is working to identify, scope, or protect CUI ahead of a CMMC assessment, Elevate Consult can help you build a defensible program from the ground up. Talk to an advisor to map your path before the next contract deadline arrives.
Key Takeaways
- CUI is a Government-wide program. It was established by Executive Order 13556 and implemented through 32 CFR Part 2002, with NARA as the Executive Agent across the entire federal executive branch, not only the Department of Defense.
- The definition is authority-based. Information is CUI only when a law, regulation, or Government-wide policy requires it to be safeguarded, and only when it is not already classified.
- CUI Basic and CUI Specified are handled differently. Basic follows the standardized controls in 32 CFR Part 2002, while Specified follows the specific rules of its authorizing law, with Basic rules filling any gaps.
- CUI and FCI are not the same. CUI carries a specific safeguarding mandate and requires NIST SP 800-171, while FCI requires only basic safeguards, which maps to the difference between CMMC Level 1 and Level 2.
- Protection starts with identification. You cannot safeguard CUI until you map where it lives, so accurate data flows and asset inventories are the foundation of any compliant program.
- The stakes are legal and commercial. Mishandling CUI can create False Claims Act exposure and the loss of federal contract eligibility, which makes accuracy a business priority, not just a compliance one.
Frequently Asked Questions
What is Controlled Unclassified Information (CUI)?
Controlled Unclassified Information is unclassified federal information that a law, regulation, or Government-wide policy requires an agency to protect with safeguarding or dissemination controls. It was established by Executive Order 13556 and is overseen Government-wide by the National Archives and Records Administration. It is more sensitive than ordinary information but does not meet the threshold for classification.
What is the difference between CUI Basic and CUI Specified?
CUI Basic requires protection but has no specific handling instructions in its governing authority, so it follows the standardized safeguarding requirements in 32 CFR Part 2002. CUI Specified is governed by a law or regulation that imposes its own specific handling or dissemination rules. Where a Specified authority is silent on a point, the CUI Basic rules apply.
What is the difference between CUI and FCI?
Federal Contract Information (FCI) is non-public information provided by or generated for the government under a contract, and it requires 15 basic safeguards under FAR 52.204-21. Controlled Unclassified Information is information a specific authority requires to be safeguarded, and for defense contractors it requires the 110 controls of NIST SP 800-171. For a contractor, CUI is generally also FCI, but not all FCI rises to the level of CUI.
Who has to protect Controlled Unclassified Information?
Every federal executive branch agency must protect CUI, along with any organization, including contractors and subcontractors, that creates, receives, or handles CUI on behalf of an agency. For defense contractors, this obligation is enforced through DFARS 252.204-7012 and verified through the CMMC program.
How do defense contractors protect Controlled Unclassified Information?
Defense contractors protect CUI by identifying where it lives, defining a clear protection boundary, and implementing the 110 security requirements of NIST SP 800-171. Those controls cover areas such as access control, audit and accountability, and incident response, and each must be both implemented and documented. CMMC Level 2 then verifies that protection through an assessment.