What Is Controlled Unclassified Information (CUI)? The Plain-English Guide
Controlled Unclassified Information (CUI) is sensitive government information that needs protection but isn’t classified. It sits in the space below Secret and Top Secret, but well above information the public can freely access. If your business touches a federal or defense contract, you may already be handling it without realizing it.
That distinction matters. Classified information is protected under a completely different legal framework, with its own clearance system. CUI uses ordinary employees, ordinary computers, and ordinary offices, just with specific safeguarding rules attached. Understanding those rules is the first step toward NIST SP 800-171 compliance. For many small and midsize contractors, it eventually leads to CMMC certification too.
This guide breaks down what CUI actually is and where the term comes from. It also covers how to tell whether your business is on the hook for protecting it.
What CUI Is (and Isn’t)
The National Archives defines CUI as information that needs safeguarding or dissemination controls under law, regulation, or government-wide policy.
Common categories of CUI include:
- Controlled technical information (military or dual-use technical data)
- Export-controlled data
- Certain personally identifiable information tied to federal programs
- Law-enforcement-sensitive records
None of these require a security clearance to see. They do require specific handling.
Classified information and CUI are protected for different reasons, by different systems. Access requires a government-issued clearance and a documented need to know. CUI has no clearance requirement.
Almost any employee at a contractor company can end up handling CUI. That’s exactly why CUI is the trigger that pulls ordinary businesses, not just defense primes, into federal cybersecurity compliance.
Where the CUI Program Comes From
Examples included “For Official Use Only” and “Sensitive But Unclassified,” among dozens of agency-specific variants. There was no consistency, and no single rulebook.
The current CUI system replaced that patchwork through a specific chain of authority:

- Executive Order 13556, signed in November 2010, established the CUI program government-wide.
- The order named the National Archives and Records Administration (NARA) as the CUI Executive Agent.
- NARA delegated day-to-day oversight to its Information Security Oversight Office (ISOO).
- ISOO’s rules were codified in 32 CFR Part 2002, the regulation contractors actually have to follow.
32 CFR Part 2002 sets requirements for designating, marking, safeguarding, sharing, and disposing of CUI. It applies to federal agencies, and to any organization that handles, possesses, or shares CUI on an agency’s behalf. If your company receives CUI under a contract, this regulation already binds you, whether you’ve read it or not.
CUI Basic vs. CUI Specified
32 CFR 2002 splits CUI into two control levels, not three. The difference isn’t about how sensitive the information is. It’s about whether the law or policy authorizing that category spells out its own specific handling rules.
| Control Level | What It Means | Handling Requirement |
|---|---|---|
| CUI Basic | The default level. The authorizing law or policy doesn’t specify special handling controls. | Follow the standardized safeguarding requirements in 32 CFR 2002 as written. |
| CUI Specified | The authorizing law or policy DOES prescribe its own handling, marking, or dissemination controls, more specific or stricter than CUI Basic. | Follow the category’s own controls, on top of the CUI Basic baseline. |
Most CUI categories fall under CUI Basic. CUI Specified only applies when a category’s own authorizing source spells out extra requirements.
Which level applies to a given document isn’t something you guess. Every approved CUI category is listed in the CUI Registry, along with its control level and required markings. (More on the Registry in the next section.)
The CUI Registry: How Categories Get Defined and Marked
Not every agency gets to invent its own CUI label. Every approved category runs through NARA first.

The Registry is the single, government-wide list of what counts. Each entry includes four things:
- The category name (for example, Controlled Technical Information or Export Control)
- The law, regulation, or policy that authorizes it
- Its control level (CUI Basic or CUI Specified)
- The exact markings required on documents in that category
Agencies and contractors are supposed to check the Registry before marking anything. Nobody invents their own label. That consistency was the whole point of the 2010 overhaul.
If a document lands in your inbox already stamped with a CUI banner, someone already did the Registry lookup for you. Your job from there is safeguarding it correctly, not deciding what it is.
How to Tell If Your Business Handles CUI
Most companies don’t get a memo announcing “you now handle CUI.” It shows up quietly, buried in a contract or an email attachment.

Watch for these signals:
- Contract language. Your contract references CUI, FOUO, or “covered defense information” directly.
- A specific clause. Your contract cites DFARS 252.204-7012 explained, a clause that only shows up when covered defense information is in play.
- Marked documents. You’ve received files or drawings already stamped with a CUI banner.
- A prime contractor’s flow-down. You’re a subcontractor, and the prime’s terms require you to follow the same safeguarding rules they do.
Any single signal is enough on its own. You don’t need all four to be in scope.
From CUI to Compliance: NIST 800-171, 800-172, and CMMC
Knowing you handle CUI is step one. Protecting it is step two, and that step has its own rulebook.
NIST doesn’t decide what CUI is. NARA does. NIST publishes the security requirements for protecting it once it’s on your systems.
| Standard | What It Covers | When It Applies |
|---|---|---|
| NIST SP 800-172 | Enhanced requirements layered on top of 800-171 | CUI facing elevated risk, such as an advanced persistent threat |
NIST built SP 800-171 as its own publication instead of just pointing contractors at a slice of 800-53. The full catalog was written for federal systems, with requirements that don’t fit an ordinary contractor’s environment. SP 800-171 keeps the substance and drops the federal-specific noise.
Where CMMC Fits
CMMC doesn’t add new technical requirements on top of 800-171. Level 1 covers basic safeguarding, Level 2 maps to the full 800-171 set, and Level 3 adds a further slice of 800-172 controls for the highest-priority programs.
Want the full picture? Read what is NIST SP 800-53 and NIST 800-53 vs. CMMC, explained.
See Where You Stand
Reading about CUI tells you the rules. It doesn’t tell you where your business actually stands against them. Take the free 2-minute NIST 800-53 Risk-Check: plain-English questions on where you stand against the control families that matter most, and the gaps to fix first. No sign-up required to see your result.
Take the free 2-minute NIST 800-53 Risk-Check
Related Guides
- What Is NIST SP 800-53? The Plain-English Guide
- NIST 800-53 vs. CMMC: What’s the Difference?
- DFARS 252.204-7012 Explained: What Defense Contractors Must Actually Do
- What Is an SPRS Score? The DoD Contractor’s Guide to Self-Assessment Scoring
Frequently Asked Questions
CUI is sensitive government information that needs safeguarding under a specific law, regulation, or government-wide policy, but isn’t classified. Common examples include controlled technical information, export-controlled data, certain federal-program-related personal information, and law-enforcement-sensitive records. Every approved category is listed in the CUI Registry along with its authorizing law and required markings.
No. CUI has no clearance requirement and can be handled by ordinary employees on ordinary systems, as long as the required safeguards are in place.
The National Archives and Records Administration (NARA) serves as the CUI Executive Agent under Executive Order 13556, with day-to-day oversight delegated to its Information Security Oversight Office. NARA maintains the CUI Registry, the official list of every approved category, its control level, and its required markings.
Both are control levels under 32 CFR Part 2002, and neither is “more sensitive” than the other by rank. CUI Basic applies when the authorizing law or policy doesn’t spell out its own handling rules, so the standard 32 CFR 2002 safeguards apply. CUI Specified applies when the authorizing source prescribes its own extra controls on top of that baseline.
No. Plenty of federal and commercial-item contracts never touch CUI at all. Signals that you do include contract language referencing CUI or covered defense information, a clause like DFARS 252.204-7012, or documents you’ve received that already carry a CUI marking.
NIST itself has no fine authority, since it’s a technical standards body, not a regulator. Consequences instead flow through the contracts built on top of it: falsely certifying compliance can trigger False Claims Act liability, and the Department of Justice has pursued multi-million dollar settlements against contractors over exactly that under its Civil Cyber-Fraud Initiative. Contract termination and suspension or debarment from future federal work are also on the table.
Get a Clear Picture of Your CUI Exposure
Figuring out whether you handle CUI is the easy part. Building the controls to protect it is where most businesses need help. LeadingIT sets up and manages the access control, logging, incident response, and system safeguards that NIST 800-171 and CMMC actually check for.
See LeadingIT’s NIST 800-53 and federal compliance IT services, or book a call to walk through where your business stands.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
