Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

What Is Controlled Unclassified Information (CUI)? The Plain-English Guide

August 11, 2026
hero-what-is-cui-1.png

Controlled Unclassified Information (CUI) is sensitive government information that needs protection but isn’t classified. It sits in the space below Secret and Top Secret, but well above information the public can freely access. If your business touches a federal or defense contract, you may already be handling it without realizing it.

That distinction matters. Classified information is protected under a completely different legal framework, with its own clearance system. CUI uses ordinary employees, ordinary computers, and ordinary offices, just with specific safeguarding rules attached. Understanding those rules is the first step toward NIST SP 800-171 compliance. For many small and midsize contractors, it eventually leads to CMMC certification too.

This guide breaks down what CUI actually is and where the term comes from. It also covers how to tell whether your business is on the hook for protecting it.

What CUI Is (and Isn’t)

The National Archives defines CUI as information that needs safeguarding or dissemination controls under law, regulation, or government-wide policy.

Common categories of CUI include:

  • Controlled technical information (military or dual-use technical data)
  • Export-controlled data
  • Certain personally identifiable information tied to federal programs
  • Law-enforcement-sensitive records

None of these require a security clearance to see. They do require specific handling.

Classified information and CUI are protected for different reasons, by different systems. Access requires a government-issued clearance and a documented need to know. CUI has no clearance requirement.

Almost any employee at a contractor company can end up handling CUI. That’s exactly why CUI is the trigger that pulls ordinary businesses, not just defense primes, into federal cybersecurity compliance.

Where the CUI Program Comes From

Examples included “For Official Use Only” and “Sensitive But Unclassified,” among dozens of agency-specific variants. There was no consistency, and no single rulebook.

The current CUI system replaced that patchwork through a specific chain of authority:

Chain of CUI Authority
  1. Executive Order 13556, signed in November 2010, established the CUI program government-wide.
  2. The order named the National Archives and Records Administration (NARA) as the CUI Executive Agent.
  3. NARA delegated day-to-day oversight to its Information Security Oversight Office (ISOO).
  4. ISOO’s rules were codified in 32 CFR Part 2002, the regulation contractors actually have to follow.

32 CFR Part 2002 sets requirements for designating, marking, safeguarding, sharing, and disposing of CUI. It applies to federal agencies, and to any organization that handles, possesses, or shares CUI on an agency’s behalf. If your company receives CUI under a contract, this regulation already binds you, whether you’ve read it or not.

CUI Basic vs. CUI Specified

32 CFR 2002 splits CUI into two control levels, not three. The difference isn’t about how sensitive the information is. It’s about whether the law or policy authorizing that category spells out its own specific handling rules.

Control LevelWhat It MeansHandling Requirement
CUI BasicThe default level. The authorizing law or policy doesn’t specify special handling controls.Follow the standardized safeguarding requirements in 32 CFR 2002 as written.
CUI SpecifiedThe authorizing law or policy DOES prescribe its own handling, marking, or dissemination controls, more specific or stricter than CUI Basic.Follow the category’s own controls, on top of the CUI Basic baseline.

Most CUI categories fall under CUI Basic. CUI Specified only applies when a category’s own authorizing source spells out extra requirements.

Which level applies to a given document isn’t something you guess. Every approved CUI category is listed in the CUI Registry, along with its control level and required markings. (More on the Registry in the next section.)

The CUI Registry: How Categories Get Defined and Marked

Not every agency gets to invent its own CUI label. Every approved category runs through NARA first.

CUI Registry Entry Fields

The Registry is the single, government-wide list of what counts. Each entry includes four things:

  • The category name (for example, Controlled Technical Information or Export Control)
  • The law, regulation, or policy that authorizes it
  • Its control level (CUI Basic or CUI Specified)
  • The exact markings required on documents in that category

Agencies and contractors are supposed to check the Registry before marking anything. Nobody invents their own label. That consistency was the whole point of the 2010 overhaul.

If a document lands in your inbox already stamped with a CUI banner, someone already did the Registry lookup for you. Your job from there is safeguarding it correctly, not deciding what it is.

How to Tell If Your Business Handles CUI

Most companies don’t get a memo announcing “you now handle CUI.” It shows up quietly, buried in a contract or an email attachment.

Four signals a business handles CUI: contract language referencing CUI or FOUO, a contract clause citing DFARS 252.204-7012, documents already stamped with a CUI banner, or being a subcontractor under a prime's flow-down requirement.

Watch for these signals:

  • Contract language. Your contract references CUI, FOUO, or “covered defense information” directly.
  • A specific clause. Your contract cites DFARS 252.204-7012 explained, a clause that only shows up when covered defense information is in play.
  • Marked documents. You’ve received files or drawings already stamped with a CUI banner.
  • A prime contractor’s flow-down. You’re a subcontractor, and the prime’s terms require you to follow the same safeguarding rules they do.

Any single signal is enough on its own. You don’t need all four to be in scope.

From CUI to Compliance: NIST 800-171, 800-172, and CMMC

Knowing you handle CUI is step one. Protecting it is step two, and that step has its own rulebook.

NIST doesn’t decide what CUI is. NARA does. NIST publishes the security requirements for protecting it once it’s on your systems.

StandardWhat It CoversWhen It Applies
NIST SP 800-172Enhanced requirements layered on top of 800-171CUI facing elevated risk, such as an advanced persistent threat

NIST built SP 800-171 as its own publication instead of just pointing contractors at a slice of 800-53. The full catalog was written for federal systems, with requirements that don’t fit an ordinary contractor’s environment. SP 800-171 keeps the substance and drops the federal-specific noise.

Where CMMC Fits

CMMC doesn’t add new technical requirements on top of 800-171. Level 1 covers basic safeguarding, Level 2 maps to the full 800-171 set, and Level 3 adds a further slice of 800-172 controls for the highest-priority programs.

Want the full picture? Read what is NIST SP 800-53 and NIST 800-53 vs. CMMC, explained.

See Where You Stand

Reading about CUI tells you the rules. It doesn’t tell you where your business actually stands against them. Take the free 2-minute NIST 800-53 Risk-Check: plain-English questions on where you stand against the control families that matter most, and the gaps to fix first. No sign-up required to see your result.

Take the free 2-minute NIST 800-53 Risk-Check

Frequently Asked Questions

CUI is sensitive government information that needs safeguarding under a specific law, regulation, or government-wide policy, but isn’t classified. Common examples include controlled technical information, export-controlled data, certain federal-program-related personal information, and law-enforcement-sensitive records. Every approved category is listed in the CUI Registry along with its authorizing law and required markings.

No. CUI has no clearance requirement and can be handled by ordinary employees on ordinary systems, as long as the required safeguards are in place.

The National Archives and Records Administration (NARA) serves as the CUI Executive Agent under Executive Order 13556, with day-to-day oversight delegated to its Information Security Oversight Office. NARA maintains the CUI Registry, the official list of every approved category, its control level, and its required markings.

Both are control levels under 32 CFR Part 2002, and neither is “more sensitive” than the other by rank. CUI Basic applies when the authorizing law or policy doesn’t spell out its own handling rules, so the standard 32 CFR 2002 safeguards apply. CUI Specified applies when the authorizing source prescribes its own extra controls on top of that baseline.

No. Plenty of federal and commercial-item contracts never touch CUI at all. Signals that you do include contract language referencing CUI or covered defense information, a clause like DFARS 252.204-7012, or documents you’ve received that already carry a CUI marking.

NIST itself has no fine authority, since it’s a technical standards body, not a regulator. Consequences instead flow through the contracts built on top of it: falsely certifying compliance can trigger False Claims Act liability, and the Department of Justice has pursued multi-million dollar settlements against contractors over exactly that under its Civil Cyber-Fraud Initiative. Contract termination and suspension or debarment from future federal work are also on the table.

Get a Clear Picture of Your CUI Exposure

Figuring out whether you handle CUI is the easy part. Building the controls to protect it is where most businesses need help. LeadingIT sets up and manages the access control, logging, incident response, and system safeguards that NIST 800-171 and CMMC actually check for.

See LeadingIT’s NIST 800-53 and federal compliance IT services, or book a call to walk through where your business stands.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.