A document does not become sensitive government information simply because it looks confidential. If you’re a government contractor, you may have seen seemingly innocuous data marked as CUI and subjected to specific protections.
So, what is CUI?
Controlled Unclassified Information (CUI) is government-related information that requires safeguarding or limits on its sharing. It is unclassified information, but organizations still need to protect it under applicable laws, regulations, or governmentwide policies.
The National Archives and Records Administration (NARA) defines CUI as information the government creates or possesses, or that an entity creates or possesses for the government, when an applicable authority requires or permits safeguarding or dissemination controls.
For federal contractors, the practical questions are often harder than the definition. You need to know what qualifies, where it lives, who can access it, and which protection requirements apply to you.
Key Takeaways
|
The CUI Program was created to give the executive branch a consistent way to handle protected unclassified information.
Executive Order 13556 established the CUI program in 2010. It also designated NARA as the CUI Executive Agent. Title 32 of the Code of Federal Regulations, Part 2002, later established the governmentwide implementing rules.
Information generally needs three characteristics to qualify as CUI:
The CUI Registry maintained by NARA identifies the approved categories and subcategories. It also shows applicable authorities, markings, and handling guidance.
CUI can take many forms:
|
CUI Category |
Possible Examples |
|
Controlled Technical Information |
Certain engineering drawings, specifications, technical reports, or manufacturing information used in covered government work |
|
Export Controlled |
Technical information subject to applicable export-control requirements |
|
Procurement and Acquisition |
Certain source-selection, cost, pricing, or procurement information |
|
Privacy |
Certain government-related personal or personnel records |
|
Protected infrastructure, emergency management, or vulnerability information covered by applicable authorities |
|
|
Proprietary Business Information |
Certain protected business, financial, product, or research information provided to or created for the government |
These categories can be broad. The Registry includes everything from Controlled Technical Information to Privacy, Procurement and Acquisition, Export Control, and Proprietary Business Information.
The category alone is not enough.
Your company’s internal employee spreadsheet, for example, does not automatically become CUI because the Registry contains privacy categories. The information needs the required federal connection and an applicable authority.
That distinction prevents teams from labeling every confidential document as CUI.
If your organization handles technical information under a federal contract, see our guide to NIST SP 800-171.
Once information qualifies as CUI, you also need to know which type of controls apply.
The distinction between CUI Basic and CUI Specified comes from the underlying legal authority. It does not describe how sensitive one document is compared with another.
To determine what is CUI Basic, start with the authority behind the information.
CUI Basic applies when a law, regulation, or governmentwide policy requires or permits protection without establishing its own specific controls.
Standard CUI Program requirements then provide the baseline. Organizations should also follow applicable agency guidance and contract requirements.
For example, NARA's Registry shows several categories with the standard CUI banner marking under Basic authorities.
CUI Specified applies when the underlying authority establishes specific requirements for safeguarding or dissemination.
Those requirements may address how the information is stored, shared, marked, or otherwise handled.
Where the authority specifies only some controls, standard CUI Basic controls fill the areas the authority does not address. Here's the practical difference:
|
Comparison Point |
CUI Basic |
CUI Specified |
|
Source of controls |
Standard CUI Program controls |
Specific requirements from the applicable authority |
|
Banner marking |
May use the standard CUI banner |
Uses an applicable CUI Specified marking |
|
Handling |
Follows standard CUI requirements |
Follows the specified authority, plus Basic controls where needed |
|
Sensitivity |
Not a lower sensitivity level |
Not automatically a higher sensitivity level |
NARA's Registry uses SP- in banner markings to identify CUI Specified authorities. Some categories can include both Basic and Specified authorities.
That is why the underlying authority matters more than assumptions about the information's sensitivity.
CUI identification starts with the government requirement, rather than an employee deciding that a file looks sensitive. A practical review can follow five steps.
Start with your contract, task order, subcontract, data requirements, and security attachments.
Look for instructions that identify CUI categories, safeguarding requirements, or agency-specific handling rules.
Federal contractors should follow CUI requirements when those requirements are incorporated into their contract or agreement. NARA also advises contractors to direct unclear information status back to the government contracting activity.
Use the Registry to confirm whether the information falls into an approved category or subcategory.
Do not rely on labels such as “confidential,” “sensitive,” or “internal use” alone.
The Registry ties legitimate CUI categories to an underlying law, regulation, or governmentwide policy.
CUI may include indicators such as:
Markings can make identification easier, but they remain part of a broader contractual and agency process.
CUI is not limited to documents the government sends you.
A contractor may create information for the government that qualifies as CUI under the contract.
Examples could include technical reports, engineering outputs, research, testing information, or other contract deliverables.
NARA confirms that industry can generate CUI on behalf of the government when the contract permits it.
Do not guess when information is unmarked or inconsistently marked.
NARA says agencies are responsible for marking or identifying CUI they share with nonfederal entities. Questions about marked or unmarked information should go back to the originating agency or contracting activity.
Your contract remains the key reference point.
If you are narrowing which systems should handle CUI, learn how a CMMC enclave can create a controlled subsection of your business.
CUI is a governmentwide program.
It is easy to associate the term primarily with Department of Defense contractors because of NIST SP 800-171 and the Cybersecurity Maturity Model Certification (CMMC), but the CUI Program itself spans executive branch agencies.
NARA states that the rule affects federal executive branch agencies and organizations that handle, possess, use, share, or receive CUI. It also covers organizations that operate or access federal information systems on an agency's behalf.
Depending on the work involved, CUI can reach:
Being in one of those industries does not automatically create a CUI obligation.
The organization must receive, create, possess, process, share, or otherwise handle qualifying information in the course of an applicable government relationship.
For contractors, those obligations usually become operational through a contract, agreement, or applicable regulation.
Defense contractors already work with established CUI requirements through mechanisms such as the Defense Federal Acquisition Regulation Supplement (DFARS), NIST SP 800-171, and CMMC.
Other federal contractors should pay close attention to current FAR rulemaking.
On June 23, 2026, the FAR Council published a revised proposed rule that includes new governmentwide requirements for contracts involving CUI. It remains a proposal as of August 2026. The proposal includes:
The comment period closed July 23, 2026. No final rule or effective date has been announced yet.
Federal contractors outside the Defense Industrial Base should avoid treating these proposed clauses as current requirements; however, they can still use the proposal to understand where governmentwide CUI contracting may be headed.
The first step is understanding what information you currently handle and which requirements already apply.
Tip: For more detail, review RADICL's NIST 800-171 compliance resources and guide to DFARS 252.204-7012.
CUI sits alongside several other government information categories. The terms can overlap in conversation, but they carry different requirements.
|
Information Type |
Plain-Language Meaning |
Typical Relevance |
|
Controlled Unclassified Information (CUI) |
Unclassified government-related information requiring specific safeguarding or dissemination controls |
Governmentwide programs and contracts |
|
Classified Information |
National security or atomic energy information protected under classification authorities |
Work requiring classified systems, processes, or clearances |
|
Federal Contract Information (FCI) |
Nonpublic information provided by or generated for the government under a contract |
Many federal contracts |
|
Covered Defense Information (CDI) |
Certain protected unclassified information covered by DFARS requirements |
Department of Defense contracts and subcontracts |
Classified information is governed by separate classification authorities. CUI itself is unclassified.
Federal Contract Information (FCI) is broader. FAR 4.1901 defines FCI as nonpublic information provided by or generated for the government under a contract, with specific exclusions.
Covered Defense Information (CDI) is specific to defense contracting. DFARS 252.204-7012 defines it to include certain unclassified controlled technical information and other protected information associated with a covered defense contract.
The applicable contract determines which requirements your organization needs to follow.
Tip: Defense contractors can learn more in The Complete Guide to CMMC.
Protecting CUI starts with understanding where it exists, and technology is part of the answer. Your policies, people, workflows, providers, and evidence also shape whether safeguards work as intended.
Identify all systems and workflows that store, process, or transmit CUI. That could include:
A smaller, clearly defined boundary can make requirements easier to manage.
Give CUI access only to authorized users with a lawful reason to receive it. Depending on your requirements, protections may include:
The goal is to know who can access CUI and retain evidence that those controls are working.
Review how CUI moves inside and outside your organization. That includes email, file transfers, cloud services, backups, remote work, and removable media.
Use the security measures required by your applicable contract and authority. A product describing itself as “CUI compliant” does not, by itself, make the broader environment compliant.
People need to recognize CUI before they can handle it correctly. Training should explain:
RADICL's Managed Security Awareness provides ongoing training and phishing exercises that help reinforce secure behaviors.
Your documentation should match the environment you actually operate. Depending on your requirements, that may include:
NIST SP 800-171 Revision 3 provides recommended security requirements for nonfederal systems that process, store, transmit, or protect CUI. Federal agencies can incorporate those requirements into contracts or other agreements.
The specific revision and requirements you must follow depend on your current contract.
RADICL's Managed Compliance Adherence supports organizations with direct access to compliance consultants. You can ask questions specific to your environment and get guidance on compliant implementation.
RADICL consultants also review evidence and validate submissions for assessment readiness. Your internal team or Managed Service Provider (MSP) completes the hands-on configuration and remediation work.
That combination helps keep compliance documentation connected to the security operations behind it.
Effective CUI protection begins with accurate identification.
Start with your federal relationship, contract language, applicable authority, and the CUI Registry. Then trace where that information moves through your systems and who can access it.
For federal contractors, that work may become more important as governmentwide FAR requirements develop.
You do not have to work through every question alone. RADICL consultants can help clarify your CUI boundary, review evidence, and prepare documentation for applicable assessments.
Speak with RADICL about your CUI requirements and assessment readiness.
No. Controlled Unclassified Information is unclassified.
It still requires protection because an applicable law, regulation, or governmentwide policy requires or permits safeguarding or dissemination controls. Classified information falls under separate national security or atomic energy classification authorities.
The word “unclassified” should not be interpreted as permission to release CUI publicly.
The official term is CUI Specified.
CUI Specified applies when the law, regulation, or governmentwide policy that protects the information also establishes specific handling controls. Standard CUI Basic controls continue to apply where that authority does not provide a particular control.
CUI Specified is not automatically more sensitive than CUI Basic.
No. The CUI Program is governmentwide.
Defense contractors encounter established CUI requirements through DFARS, NIST SP 800-171, and CMMC. However, civilian federal agencies and their contractors can also create, receive, or handle CUI.
The proposed 2026 FAR CUI rule could create a more standardized approach across federal contracts if finalized.