What Is CUI (Controlled Unclassified Information)?
Also known as: Controlled Unclassified Information, CDI
Definition
CUI (Controlled Unclassified Information) is unclassified information created or possessed by the US government, or by a contractor on its behalf, that laws, regulations, or government-wide policy require to be safeguarded or restricted in dissemination.
CUI (Controlled Unclassified Information) Explained
CUI was created by Executive Order 13556 in 2010 to replace a sprawl of agency-specific markings - FOUO, Sensitive But Unclassified, Law Enforcement Sensitive, and dozens more - that had no consistent definition or handling rules. The National Archives serves as executive agent and maintains the CUI Registry, which is the authoritative list of categories. If a category is not in the Registry, it is not CUI, and agencies may not invent new control markings on their own.
The Registry groups categories under organizational index groupings such as Critical Infrastructure, Defense, Export Control, Financial, Privacy, and Procurement and Acquisition. Each category cites the underlying law or policy that authorizes control. Categories divide into CUI Basic and CUI Specified. Basic follows the uniform handling rules of 32 CFR Part 2002. Specified categories carry additional handling requirements written into their authorizing statute, and those specific rules override the general baseline.
Marking is procedural and precise. A designated banner marking appears at the top and bottom of each page, and portion markings may be applied to individual paragraphs. A designation indicator identifies the originating organization. In practice, contractors receive CUI more often than they create it, and the recurring failure is derivative documents: an engineer copies a controlled dimension from a marked government drawing into an unmarked internal work instruction, and the marking chain breaks even though the information remains controlled.
In the defense context the operative term is often Covered Defense Information, the DFARS phrase for the CUI subset relevant to DoD contracts. It includes controlled technical information, export-controlled information, and other categories marked in the contract or generated during performance. Because export-controlled information is itself a CUI category, ITAR and EAR obligations and NIST SP 800-171 obligations frequently attach to the exact same file, and both regimes must be satisfied simultaneously.
For systems architects the important consequence is that CUI is a data attribute, not a system attribute. It travels. It arrives as an email attachment, gets pasted into an ERP text field, lands in a backup, and gets indexed by a search tool or an AI retrieval pipeline. Scoping a compliant environment therefore starts with a data flow inventory - where CUI enters, where it comes to rest, and which systems and people can reach it - because that inventory defines the assessment boundary that CMMC and DFARS will examine.
Why It Matters
- The presence of CUI, not the size of the contract, determines whether NIST SP 800-171, DFARS 7012, and CMMC Level 2 obligations attach.
- CUI spreads through email, shared drives, ERP text fields, and AI indexes, so uncontrolled sprawl silently expands the assessment boundary and its cost.
- Many CUI categories are also export controlled, meaning a single file can carry simultaneous ITAR, EAR, and cybersecurity obligations.
- Improper marking or mishandling can breach contract terms and, for export-controlled categories, trigger separate and far larger regulatory penalties.
In Practice
A useful test during scoping: ask where a controlled drawing has been in the last 90 days. At one defense electronics supplier the honest answer included the PLM vault, an estimator's laptop, a quoting spreadsheet emailed to a broker, a printed traveler on the shop floor, and the file attachment table of the ERP database. Only the first was inside the intended enclave. Reducing that list to two locations was cheaper and faster than certifying the other four.
Frequently Asked Questions
What is the difference between CUI Basic and CUI Specified?
CUI Basic follows the uniform safeguarding and dissemination controls in 32 CFR Part 2002 with no additional requirements. CUI Specified applies when the authorizing law, regulation, or government-wide policy imposes specific handling rules beyond that baseline, such as particular dissemination limits or destruction methods. Those category-specific rules take precedence over the general Basic controls.
Who decides whether information is CUI?
Only an authorized holder acting on behalf of the government designates information as CUI, and only using categories listed in the NARA CUI Registry. Contractors generally do not create CUI designations independently; they inherit them from contract documents, government-furnished information, or the requirement to protect information generated in performance of a contract that meets a Registry category.
Related Terms
NIST SP 800-171
NIST SP 800-171 is the National Institute of Standards and Technology publication that defines the security requirements for protecting Controlled Unclassified Information in nonfederal systems, and it is the technical baseline behind DFARS 252.204-7012 and CMMC Level 2.
DFARS 252.204-7012
DFARS 252.204-7012 is the Defense Department contract clause requiring contractors to protect covered defense information by implementing NIST SP 800-171, to report cyber incidents to DoD within 72 hours, and to flow the same obligations down to subcontractors.
ITAR
ITAR (International Traffic in Arms Regulations) is the US State Department regulation, at 22 CFR Parts 120-130, that controls the export of defense articles, defense services, and related technical data listed on the United States Munitions List.
Go Deeper
CMMC 2.0 Level 2 Readiness Assessment
Answer 10 questions mapped to NIST SP 800-171 control families and get an instant CMMC Level 2 readiness score with prioritized next steps.
AI Governance for Export-Controlled Data (ITAR/EAR)
AI governance for export-controlled data: policies, access controls, and audit trails that keep ITAR and EAR data out of public LLMs and off foreign servers.
CMMC-Compliant AI Deployment: What Level 2 Contractors Must Know
CMMC-compliant AI deployment explained: how Level 2 defense contractors can run AI on CUI without expanding assessment scope. Controls, enclaves, and costs.
Working with CUI (Controlled Unclassified Information) in a live environment? Our engineers do this every day - and our AI agents automate most of it.