What Is CUI? Controlled Unclassified Information Explained

by Jordan Dean on Sep 23, 2026

What Is CUI? Controlled Unclassified Information Explained_Graphic

A document does not become sensitive government information simply because it looks confidential. If you’re a government contractor, you may have seen seemingly innocuous data marked as CUI and subjected to specific protections.

So, what is CUI?

Controlled Unclassified Information (CUI) is government-related information that requires safeguarding or limits on its sharing. It is unclassified information, but organizations still need to protect it under applicable laws, regulations, or governmentwide policies.

The National Archives and Records Administration (NARA) defines CUI as information the government creates or possesses, or that an entity creates or possesses for the government, when an applicable authority requires or permits safeguarding or dissemination controls.

For federal contractors, the practical questions are often harder than the definition. You need to know what qualifies, where it lives, who can access it, and which protection requirements apply to you.

Key Takeaways

  • CUI is unclassified federal information that requires protection. An applicable law, regulation, or governmentwide policy must establish or permit those controls.
  • CUI Basic and CUI Specified describe how controls are established. They are not low- and high-sensitivity rankings.
  • CUI reaches beyond defense contracting. Federal contractors across many agencies may handle it, and a proposed FAR rule could further standardize contract requirements.

What Is CUI and What Information Counts?

The CUI Program was created to give the executive branch a consistent way to handle protected unclassified information.

Executive Order 13556 established the CUI program in 2010. It also designated NARA as the CUI Executive Agent. Title 32 of the Code of Federal Regulations, Part 2002, later established the governmentwide implementing rules.

Information generally needs three characteristics to qualify as CUI:

  • It has a federal connection. The government creates or possesses it, or another organization does so on its behalf.
  • It is unclassified. Classified national security information is subject to separate requirements.
  • An applicable authority requires or permits controls. That authority must come from a law, regulation, or governmentwide policy.

The CUI Registry maintained by NARA identifies the approved categories and subcategories. It also shows applicable authorities, markings, and handling guidance.

CUI can take many forms:

CUI Category

Possible Examples

Controlled Technical Information

Certain engineering drawings, specifications, technical reports, or manufacturing information used in covered government work

Export Controlled

Technical information subject to applicable export-control requirements

Procurement and Acquisition

Certain source-selection, cost, pricing, or procurement information

Privacy

Certain government-related personal or personnel records

Critical Infrastructure

Protected infrastructure, emergency management, or vulnerability information covered by applicable authorities

Proprietary Business Information

Certain protected business, financial, product, or research information provided to or created for the government

These categories can be broad. The Registry includes everything from Controlled Technical Information to Privacy, Procurement and Acquisition, Export Control, and Proprietary Business Information.

The category alone is not enough.

Your company’s internal employee spreadsheet, for example, does not automatically become CUI because the Registry contains privacy categories. The information needs the required federal connection and an applicable authority.

That distinction prevents teams from labeling every confidential document as CUI.

If your organization handles technical information under a federal contract, see our guide to NIST SP 800-171.

CUI Basic vs. CUI Specified

Once information qualifies as CUI, you also need to know which type of controls apply.

The distinction between CUI Basic and CUI Specified comes from the underlying legal authority. It does not describe how sensitive one document is compared with another.

What Is CUI Basic?

To determine what is CUI Basic, start with the authority behind the information.

CUI Basic applies when a law, regulation, or governmentwide policy requires or permits protection without establishing its own specific controls.

Standard CUI Program requirements then provide the baseline. Organizations should also follow applicable agency guidance and contract requirements.

For example, NARA's Registry shows several categories with the standard CUI banner marking under Basic authorities.

What Is CUI Specified?

CUI Specified applies when the underlying authority establishes specific requirements for safeguarding or dissemination.

Those requirements may address how the information is stored, shared, marked, or otherwise handled.

Where the authority specifies only some controls, standard CUI Basic controls fill the areas the authority does not address. Here's the practical difference:

Comparison Point

CUI Basic

CUI Specified

Source of controls

Standard CUI Program controls

Specific requirements from the applicable authority

Banner marking

May use the standard CUI banner

Uses an applicable CUI Specified marking

Handling

Follows standard CUI requirements

Follows the specified authority, plus Basic controls where needed

Sensitivity

Not a lower sensitivity level

Not automatically a higher sensitivity level

NARA's Registry uses SP- in banner markings to identify CUI Specified authorities. Some categories can include both Basic and Specified authorities.

That is why the underlying authority matters more than assumptions about the information's sensitivity.

How Do You Identify CUI in Your Organization?

CUI identification starts with the government requirement, rather than an employee deciding that a file looks sensitive. A practical review can follow five steps.

1. Review Contracts and Agency Instructions

Start with your contract, task order, subcontract, data requirements, and security attachments.

Look for instructions that identify CUI categories, safeguarding requirements, or agency-specific handling rules.

Federal contractors should follow CUI requirements when those requirements are incorporated into their contract or agreement. NARA also advises contractors to direct unclear information status back to the government contracting activity.

2. Compare the Information With the CUI Registry

Use the Registry to confirm whether the information falls into an approved category or subcategory.

Do not rely on labels such as “confidential,” “sensitive,” or “internal use” alone.

The Registry ties legitimate CUI categories to an underlying law, regulation, or governmentwide policy.

3. Check Markings and Designation Details

CUI may include indicators such as:

  • A CUI banner marking
  • A category or subcategory marking
  • A CUI Specified marking
  • Limited dissemination controls
  • A designation indicator
  • Decontrol instructions

Markings can make identification easier, but they remain part of a broader contractual and agency process.

4. Trace Information Created During Contract Performance

CUI is not limited to documents the government sends you.

A contractor may create information for the government that qualifies as CUI under the contract.

Examples could include technical reports, engineering outputs, research, testing information, or other contract deliverables.

NARA confirms that industry can generate CUI on behalf of the government when the contract permits it.

5. Escalate Unclear Cases

Do not guess when information is unmarked or inconsistently marked.

NARA says agencies are responsible for marking or identifying CUI they share with nonfederal entities. Questions about marked or unmarked information should go back to the originating agency or contracting activity.

Your contract remains the key reference point.

If you are narrowing which systems should handle CUI, learn how a CMMC enclave can create a controlled subsection of your business.

Who Must Protect CUI?

CUI is a governmentwide program.

It is easy to associate the term primarily with Department of Defense contractors because of NIST SP 800-171 and the Cybersecurity Maturity Model Certification (CMMC), but the CUI Program itself spans executive branch agencies.

NARA states that the rule affects federal executive branch agencies and organizations that handle, possess, use, share, or receive CUI. It also covers organizations that operate or access federal information systems on an agency's behalf.

Depending on the work involved, CUI can reach:

  • Prime contractors
  • Subcontractors
  • Research organizations
  • Universities
  • Cloud and technology providers
  • Professional service firms
  • Organizations supporting government healthcare programs
  • Transportation and infrastructure organizations
  • Financial service providers
  • Other federal program partners

Being in one of those industries does not automatically create a CUI obligation.

The organization must receive, create, possess, process, share, or otherwise handle qualifying information in the course of an applicable government relationship.

For contractors, those obligations usually become operational through a contract, agreement, or applicable regulation.

Why Federal Contractors Should Prepare Now

Defense contractors already work with established CUI requirements through mechanisms such as the Defense Federal Acquisition Regulation Supplement (DFARS), NIST SP 800-171, and CMMC.

Other federal contractors should pay close attention to current FAR rulemaking.

On June 23, 2026, the FAR Council published a revised proposed rule that includes new governmentwide requirements for contracts involving CUI. It remains a proposal as of August 2026. The proposal includes:

  • FAR 52.240-6, Notice of Controlled Unclassified Information Requirements
  • FAR 52.240-7, Controlled Unclassified Information
  • A standardized form identifying contract-specific CUI requirements
  • NIST SP 800-171 Revision 3 for applicable contractor systems
  • Flowdown requirements for relevant subcontractors
  • A limited exception for contracts solely involving Commercially Available Off-the-Shelf items

The comment period closed July 23, 2026. No final rule or effective date has been announced yet.

Federal contractors outside the Defense Industrial Base should avoid treating these proposed clauses as current requirements; however, they can still use the proposal to understand where governmentwide CUI contracting may be headed.

The first step is understanding what information you currently handle and which requirements already apply.

Tip: For more detail, review RADICL's NIST 800-171 compliance resources and guide to DFARS 252.204-7012.

How Is CUI Different From Classified Information, FCI, and CDI?

CUI sits alongside several other government information categories. The terms can overlap in conversation, but they carry different requirements.

Information Type

Plain-Language Meaning

Typical Relevance

Controlled Unclassified Information (CUI)

Unclassified government-related information requiring specific safeguarding or dissemination controls

Governmentwide programs and contracts

Classified Information

National security or atomic energy information protected under classification authorities

Work requiring classified systems, processes, or clearances

Federal Contract Information (FCI)

Nonpublic information provided by or generated for the government under a contract

Many federal contracts

Covered Defense Information (CDI)

Certain protected unclassified information covered by DFARS requirements

Department of Defense contracts and subcontracts

Classified information is governed by separate classification authorities. CUI itself is unclassified.

Federal Contract Information (FCI) is broader. FAR 4.1901 defines FCI as nonpublic information provided by or generated for the government under a contract, with specific exclusions.

Covered Defense Information (CDI) is specific to defense contracting. DFARS 252.204-7012 defines it to include certain unclassified controlled technical information and other protected information associated with a covered defense contract.

The applicable contract determines which requirements your organization needs to follow.

Tip: Defense contractors can learn more in The Complete Guide to CMMC.

How Should Organizations Protect CUI?

Protecting CUI starts with understanding where it exists, and technology is part of the answer. Your policies, people, workflows, providers, and evidence also shape whether safeguards work as intended.

Define the CUI Boundary

Identify all systems and workflows that store, process, or transmit CUI. That could include:

  • Endpoints
  • Email
  • Cloud platforms
  • Identity systems
  • File storage
  • Remote-access tools
  • Engineering applications
  • Users
  • Third-party providers
  • Physical locations and records

A smaller, clearly defined boundary can make requirements easier to manage.

Limit and Monitor Access

Give CUI access only to authorized users with a lawful reason to receive it. Depending on your requirements, protections may include:

  • Role-based access
  • Least privilege
  • Strong authentication
  • Managed accounts
  • Security logging
  • Periodic access review
  • Physical access controls

The goal is to know who can access CUI and retain evidence that those controls are working.

Protect Storage and Transmission

Review how CUI moves inside and outside your organization. That includes email, file transfers, cloud services, backups, remote work, and removable media.

Use the security measures required by your applicable contract and authority. A product describing itself as “CUI compliant” does not, by itself, make the broader environment compliant.

Train People Who Handle CUI

People need to recognize CUI before they can handle it correctly. Training should explain:

  • CUI markings and categories
  • Approved storage and sharing methods
  • Remote-work expectations
  • Physical document handling
  • Removable media
  • How to report mistakes or suspected incidents

RADICL's Managed Security Awareness provides ongoing training and phishing exercises that help reinforce secure behaviors.

Maintain Documentation and Evidence

Your documentation should match the environment you actually operate. Depending on your requirements, that may include:

  • Defined system boundaries
  • Security policies
  • System Security Plans (SSPs)
  • Plans of Action and Milestones (POA&Ms), when permitted
  • Access records
  • Security logs
  • Training records
  • Incident-response procedures
  • Evidence showing that required protections operate as described

NIST SP 800-171 Revision 3 provides recommended security requirements for nonfederal systems that process, store, transmit, or protect CUI. Federal agencies can incorporate those requirements into contracts or other agreements.

The specific revision and requirements you must follow depend on your current contract.

RADICL's Managed Compliance Adherence supports organizations with direct access to compliance consultants. You can ask questions specific to your environment and get guidance on compliant implementation.

RADICL consultants also review evidence and validate submissions for assessment readiness. Your internal team or Managed Service Provider (MSP) completes the hands-on configuration and remediation work.

That combination helps keep compliance documentation connected to the security operations behind it.

Know What CUI You Handle Before You Protect It

Effective CUI protection begins with accurate identification.

Start with your federal relationship, contract language, applicable authority, and the CUI Registry. Then trace where that information moves through your systems and who can access it.

For federal contractors, that work may become more important as governmentwide FAR requirements develop.

You do not have to work through every question alone. RADICL consultants can help clarify your CUI boundary, review evidence, and prepare documentation for applicable assessments.

Speak with RADICL about your CUI requirements and assessment readiness.

FAQs

Is CUI classified information?

No. Controlled Unclassified Information is unclassified.

It still requires protection because an applicable law, regulation, or governmentwide policy requires or permits safeguarding or dissemination controls. Classified information falls under separate national security or atomic energy classification authorities.

The word “unclassified” should not be interpreted as permission to release CUI publicly.

What is CUI specific?

The official term is CUI Specified.

CUI Specified applies when the law, regulation, or governmentwide policy that protects the information also establishes specific handling controls. Standard CUI Basic controls continue to apply where that authority does not provide a particular control.

CUI Specified is not automatically more sensitive than CUI Basic.

Does CUI only apply to defense contractors?

No. The CUI Program is governmentwide.

Defense contractors encounter established CUI requirements through DFARS, NIST SP 800-171, and CMMC. However, civilian federal agencies and their contractors can also create, receive, or handle CUI.

The proposed 2026 FAR CUI rule could create a more standardized approach across federal contracts if finalized.

Get Email Notifications

No Comments Yet

Let us know what you think