What Is CUI? Controlled Unclassified Information, Explained
What is CUI? Controlled Unclassified Information is unclassified information that a law, regulation, or government-wide policy requires the Federal Government to safeguard or to control before it is disseminated. It is defined by Executive Order 13556, implemented government-wide by 32 CFR Part 2002, and implemented inside the Department of Defense by DoD Instruction 5200.48. If your contract puts CUI on your systems, DFARS 252.204-7012 and NIST SP 800-171 decide how those systems have to be built.
The short version
- Definition and legal basis. Executive Order 13556 created the CUI Program in 2010. The National Archives and Records Administration is the Executive Agent, and its rule at 32 CFR Part 2002 sets the government-wide standard.
- The DoD instruction that implements CUI is DoDI 5200.48. It establishes Department of Defense policy for identifying, marking, safeguarding, disseminating, decontrolling, and destroying CUI.
- Two flavors. CUI Basic follows the uniform controls in 32 CFR Part 2002. CUI Specified follows the specific handling controls written into the underlying law, regulation, or government-wide policy.
- Types of CUI come from the CUI Registry published by the National Archives, which organizes every approved category into index groupings such as Defense, Export Control, Privacy, Procurement and Acquisition, and Critical Infrastructure.
- Who can control CUI. Designation authority is a Federal Government function. Contractors are authorized holders: they receive, mark, safeguard, disseminate, and destroy CUI according to the contract and the governing policy.
- System level required for CUI. A nonfederal system that processes, stores, or transmits CUI under DFARS 252.204-7012 has to implement NIST SP 800-171, which maps to CMMC Level 2 under 32 CFR Part 170.
What Is CUI? The Legal Definition
Controlled Unclassified Information is information the Federal Government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. That definition comes directly from 32 CFR 2002, the rule the National Archives and Records Administration issued to implement the CUI Program.
Three parts of that definition do the real work, and contractors get into trouble when they skip any of them.
First, CUI is unclassified. It is not Confidential, Secret, or Top Secret. Classified national security information is governed by a separate executive order and a separate marking and clearance regime. CUI sits below that line and above ordinary public information.
Second, CUI requires an authority. Information is not CUI because it feels sensitive, because a program manager calls it proprietary, or because an email footer says it is confidential. It is CUI only when a law, a regulation, or a government-wide policy authorizes the control. The National Archives calls those the authorizing laws, regulations, and government-wide policies, and every approved CUI category traces back to at least one of them.
Third, CUI is about handling, not secrecy in the abstract. The control attaches to safeguarding the information and to limiting how it is disseminated. That is why the practical consequences of CUI show up as system requirements, marking requirements, transmission requirements, and destruction requirements rather than as clearances.
Where the CUI Program came from
Before 2010, agencies invented their own control markings. Estimates of the number of distinct legacy markings ran into the dozens, and none of them had a shared definition, a shared safeguarding baseline, or a shared decontrol rule. "For Official Use Only" meant one thing at one agency and something else at another, and a contractor holding information from two agencies had no consistent standard to apply.
Executive Order 13556, signed on November 4, 2010, ended that. It established a single, government-wide CUI Program, designated the National Archives and Records Administration as the Executive Agent, and directed the Executive Agent to publish implementing standards. Those standards became 32 CFR Part 2002, which is the regulation that binds executive branch agencies today.
What DoD Instruction Implements CUI
The DoD instruction that implements CUI is DoD Instruction 5200.48, "Controlled Unclassified Information (CUI)." It was issued on March 6, 2020 and it is the answer defense contractors are usually looking for when they ask which DoD instruction implements the CUI program.
DoDI 5200.48 does several things that matter to a contractor:
- It establishes Department of Defense policy consistent with Executive Order 13556 and 32 CFR Part 2002, so DoD components stop applying component-specific control markings.
- It assigns responsibilities for designating, marking, safeguarding, disseminating, decontrolling, and destroying CUI inside the Department.
- It discontinues the legacy "For Official Use Only" marking for newly created information. Legacy FOUO material still in circulation does not automatically become uncontrolled, but new material is marked as CUI.
- It ties CUI handling in the contract environment to the DFARS and to the safeguarding requirements that come with it, rather than leaving handling to informal instruction.
Two related instruments come up constantly alongside DoDI 5200.48. DoD Instruction 5230.24 governs distribution statements on technical documents, which is why so much CUI in the defense industrial base is technical data carrying a Distribution B through F statement. And the DoD CUI Program office publishes marking guidance that translates the regulation into the banner and portion markings assessors actually look for.
What Is CUI Versus FCI, CDI, and Classified Information
These four terms are not interchangeable, and mixing them up is the most common scoping mistake we see.
| Term | Source | What it means for your systems |
|---|---|---|
| FCI Federal Contract Information | FAR 52.204-21 | Information not intended for public release, provided by or generated for the government under a contract. Triggers the 15 basic safeguarding requirements in FAR 52.204-21, which is CMMC Level 1. |
| CUI Controlled Unclassified Information | EO 13556, 32 CFR Part 2002, DoDI 5200.48 | Unclassified information requiring safeguarding or dissemination control under law, regulation, or government-wide policy. Triggers NIST SP 800-171 through DFARS 252.204-7012 and CMMC Level 2. |
| CDI Covered Defense Information | DFARS 252.204-7012 | The contract-clause term for the unclassified controlled technical information and other information that the clause requires you to protect. In practice CDI is the subset of CUI that arrives under a DFARS 7012 contract. |
| Classified | Separate executive order | Confidential, Secret, or Top Secret. Requires facility clearance, personnel clearances, and accredited systems. Out of scope for CMMC. |
A useful rule of thumb: every DoD contractor handling FCI has to meet the FAR 52.204-21 baseline. Only the contractors who actually receive or generate CUI take on the full NIST SP 800-171 obligation. Getting that boundary right is the single highest-leverage decision in a compliance program, which is why it is the first thing we work through in a CMMC gap assessment. For a side-by-side walkthrough with contract examples, see our field guide on CUI versus FCI for defense contractors.
CUI Basic and CUI Specified
32 CFR Part 2002 divides CUI into two subsets, and the distinction changes what you are allowed to do with the information.
CUI Basic
CUI Basic is the default. The authorizing law, regulation, or government-wide policy requires protection but does not spell out how. In that case the uniform controls in 32 CFR Part 2002 apply: the moderate confidentiality baseline, the standard marking, and the standard dissemination rules. Most CUI a mid-sized supplier sees is CUI Basic.
CUI Specified
CUI Specified is the exception. The authorizing instrument prescribes specific controls that differ from the CUI Basic baseline. Export-controlled information is the canonical example: the International Traffic in Arms Regulations and the Export Administration Regulations impose their own access restrictions on foreign persons, and those restrictions govern even when the general CUI rules would be looser. When a category is Specified, you follow the underlying authority, not the default.
The practical consequence is that you cannot design a single handling procedure and apply it blindly. A Specified category can add nationality restrictions, physical storage requirements, or reporting duties that the Basic baseline never mentions. The CUI Registry entry for each category tells you which subset applies.
Types of CUI and the CUI Registry
People ask which of the following are types of CUI as though there were a short fixed list. There is a list, it is authoritative, and it lives in one place: the CUI Registry, maintained by the National Archives. The Registry is the only approved source of CUI categories. If a category is not in the Registry, it is not CUI.
The Registry organizes categories into index groupings. The groupings include, among others:
- Defense, which covers controlled technical information, naval nuclear propulsion information, and unclassified controlled nuclear information related to defense.
- Export Control, covering information subject to export control laws and regulations. This grouping is CUI Specified.
- Procurement and Acquisition, covering source selection information, contractor bid or proposal information, and small business research and technology information.
- Privacy, covering personally identifiable information, health information, and related categories.
- Critical Infrastructure, covering protected critical infrastructure information and related security information.
- Proprietary Business Information, covering trade secrets and other proprietary material the government holds.
- Law Enforcement, Legal, Intelligence, Nuclear, Tax, Statistical, Transportation, Immigration, Financial, International Agreements, NATO, Patent, and Natural and Cultural Resources.
For a defense supplier, the categories that appear on real contracts are overwhelmingly Controlled Technical Information under the Defense grouping, export-controlled data, and procurement-sensitive material. Drawings, specifications, process sheets, test data, and engineering change documents carrying a distribution statement are the day-to-day reality of CUI in a machine shop or a contract manufacturer.
Who Can Control CUI and Who Can Designate It
Designation is a government function. An authorized holder acting on behalf of a Federal agency determines that information falls within a CUI category and applies the control. A contractor does not get to invent CUI, and a contractor cannot unilaterally decide that its own commercial data is CUI simply because it wants the protection.
That said, contractors do create CUI in the ordinary course of performance. When you generate a drawing, a test report, or an analysis for the government under a contract that involves CUI, the resulting material is marked and handled as CUI according to the contract's requirements and the government's guidance. The authority still traces back to the government; you are executing it, not originating it.
What a CUI authorized holder is responsible for
32 CFR Part 2002 defines an authorized holder as an individual, agency, organization, or group of users that is permitted to designate or handle CUI in accordance with the CUI Program. Every employee at a defense supplier who touches CUI is an authorized holder, and the obligations attach to the individual, not only to the company.
A CUI authorized holder is responsible for:
- Determining, before dissemination, whether the recipient has a lawful government purpose. The CUI Program replaced "need to know" with the lawful government purpose standard. You share CUI when the sharing furthers a lawful government purpose and no limited dissemination control forbids it.
- Applying and maintaining the correct markings so that the next holder knows what they have received and what restrictions travel with it.
- Safeguarding the information at rest, in transit, and in physical form, which in a contract environment means the controls in NIST SP 800-171 plus physical protections.
- Not removing or downgrading markings on someone else's information. Only the designating agency may decontrol.
- Challenging designations believed to be improper. The CUI Program expects holders who think information was over-designated or under-designated to raise it through the process the regulation establishes rather than acting unilaterally.
- Reporting suspected or confirmed unauthorized disclosure through the required channels, which under DFARS 252.204-7012 means reporting a cyber incident to the Department of Defense.
- Destroying CUI when it is no longer required in a manner that makes it unreadable, indecipherable, and unrecoverable.
Those responsibilities are also why CUI training is not optional overhead. NIST SP 800-171 has an entire Awareness and Training family, and the personnel security requirements extend the obligation across hiring, transfer, and termination. We cover the personnel side in detail on protecting CUI during personnel actions.
CUI Marking and Handling Requirements
Marking is what makes the rest of the program work. If CUI is not marked, downstream holders do not know it is controlled, and it leaks by default.
Banner markings
CUI carries a banner marking at the top of the document. The banner uses the control marking CUI or the word CONTROLLED. For CUI Specified, the banner adds the category marking after a double forward slash, for example CUI//SP-EXPT for export-controlled information. Limited dissemination controls follow in the same banner, for example CUI//SP-EXPT//FED ONLY.
Designation indicator
Documents also carry a designation indicator identifying the office that designated the information, commonly rendered as a "Controlled by" block with the controlling office, the applicable category, the limited dissemination control if any, and a point of contact. That block is what lets a recipient trace the authority and ask questions.
Limited dissemination controls
Limited dissemination controls are the approved way to narrow distribution beyond the lawful government purpose standard. The approved set is published in the CUI Registry and includes controls such as NOFORN, FED ONLY, FEDCON, NOCON, DL ONLY, REL TO, and DISPLAY ONLY. Only agencies may apply them, and once applied they travel with the information.
Media, portable storage, and mobile devices
Physical media holding CUI has to be marked and controlled as well. That obligation is where NIST SP 800-171's Media Protection family becomes concrete. Rather than restate those requirements here, this hub links down to the implementation pages for each one, below.
What Level of System Is Required for CUI
This is the question with the most expensive wrong answers. The short version: a nonfederal information system that processes, stores, or transmits CUI under a DFARS 252.204-7012 contract has to implement NIST SP 800-171, and under 32 CFR Part 170 that maps to CMMC Level 2.
The clause chain
DFARS 252.204-7012 requires adequate security on covered contractor information systems, defines adequate security as implementing NIST SP 800-171, requires rapid reporting of cyber incidents to the Department of Defense within 72 hours of discovery, requires preservation of affected media and images for 90 days, requires submission of malicious software when isolated, and requires flow-down of the clause to subcontractors whose performance involves covered defense information.
DFARS 252.204-7019 and 252.204-7020 add the assessment layer: a current NIST SP 800-171 self-assessment score posted in the Supplier Performance Risk System, and the government's right to conduct higher-level assessments. If you have not scored yourself, our SPRS score calculator walks the arithmetic.
DFARS 252.204-7021 is the CMMC clause. Where it applies, self-attestation is replaced or supplemented by the certification requirement defined in the CMMC Program rule at 32 CFR Part 170. CMMC Level 2 is the 110 security requirements of NIST SP 800-171, assessed either by a certified third-party assessment organization or, for a limited set of contracts, by self-assessment. Level 3 layers a selected set of enhanced requirements drawn from NIST SP 800-172 on top of Level 2 for the highest-risk programs. Our CMMC levels explained page walks the level boundaries, and CMMC Level 3 covers the enhanced tier.
Cloud, encryption, and the details that fail assessments
Three technical constraints catch contractors repeatedly:
- Cloud service providers. DFARS 252.204-7012 requires a cloud service provider handling covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline. Commercial productivity tenants that were never assessed against that baseline do not satisfy the clause.
- FIPS-validated cryptography. NIST SP 800-171 requires FIPS-validated cryptography to protect the confidentiality of CUI. Encryption that is strong but not validated does not meet the requirement as written.
- External connections and flow. Information flow between the CUI environment and everything else has to be controlled and documented. See controlling CUI flow.
For a broader treatment of the 110 requirements and the 14 families, see our NIST SP 800-171 compliance page. For the assessment mechanics, see C3PAO assessment and CMMC Level 2 certification.
CUI Handling, Control by Control
This hub explains the program. The pages below explain the individual NIST SP 800-171 and CMMC requirements that govern how CUI is stored, moved, marked, and destroyed. Each one covers scope, implementation, evidence, and the assessment objectives.
Control CUI Flow
Enforcing approved authorizations for controlling the flow of CUI within and between systems.
3.1.19Encrypt CUI on Mobile Devices
Encryption on mobile devices and mobile computing platforms that carry CUI.
3.1.22CUI on Public Systems
Controlling CUI posted or processed on publicly accessible systems, including websites.
3.8.1Protect CUI on System Media
Protecting system media containing CUI, both paper and digital.
3.8.2Limit Access to CUI on Media
Limiting access to CUI on system media to authorized users.
3.8.3Sanitize or Destroy CUI Media
Sanitizing or destroying media containing CUI before disposal or release for reuse.
3.8.4Mark CUI Media
Marking media with necessary CUI markings and distribution limitations.
3.8.5Control and Account for CUI Media
Controlling access to media containing CUI and maintaining accountability during transport.
3.8.6Cryptography on Portable Storage
Cryptographic mechanisms protecting CUI on digital media during transport.
3.8.9Protect Backup CUI
Protecting the confidentiality of backup CUI at storage locations.
3.9.2CUI During Personnel Actions
Protecting CUI during and after personnel transfers and terminations.
3.13.8Cryptography for CUI in Transit
Preventing unauthorized disclosure of CUI during transmission.
3.13.16Protect CUI at Rest
Protecting the confidentiality of CUI at rest across storage tiers.
Destruction, Decontrol, and Incident Reporting
Destruction
CUI is destroyed when it is no longer needed, and the standard is outcome-based: the information must be rendered unreadable, indecipherable, and unrecoverable. For digital media that means sanitization consistent with NIST SP 800-88, "Guidelines for Media Sanitization," which distinguishes clearing, purging, and physical destruction and matches the method to the media type. For paper it means cross-cut shredding or equivalent. Keeping a destruction record is not glamorous, but it is the evidence an assessor asks for. The requirement-level detail lives on sanitize or destroy CUI media before disposal.
Decontrol
Decontrol is the formal removal of CUI status. It happens when the law, regulation, or government-wide policy no longer requires control, when the designating agency decides control is no longer needed, or when the information is released under a public disclosure process. The key rule for contractors is simple: you do not decontrol government information. If you believe a document is over-controlled, raise it with the designating office through the contract channel.
Incident reporting
Under DFARS 252.204-7012, a contractor that discovers a cyber incident affecting covered defense information or affecting its ability to perform operationally critical support must rapidly report to the Department of Defense within 72 hours of discovery. Reporting goes through the DoD reporting portal and requires a medium assurance certificate, which takes time to obtain. Getting that certificate before you need it is a five-minute task that becomes a crisis if it is deferred.
The clause also requires preserving images of affected systems and relevant monitoring data for at least 90 days from the report so the government can request them, and submitting malicious software to the government if it is isolated in connection with the incident. Subcontractor incidents flow through the same structure, and the prime has to be notified.
If your CUI moves down a supply chain, the flow-down obligations are worth reading closely. We walk them in CUI handling for DoD subcontractors.
What Is a CUI Enclave and When It Makes Sense
A CUI enclave is a deliberately bounded environment that holds all of your CUI, so the security requirements apply to that environment rather than to your whole company. The term is architectural rather than regulatory. What makes it meaningful under CMMC is the asset categorization in the CMMC assessment scoping guidance, which sorts assets into CUI assets, security protection assets, contractor risk managed assets, specialized assets, and out-of-scope assets. An enclave is how you engineer the answer to that sort in advance instead of discovering it during an assessment.
Why teams build one
- Assessment scope shrinks. A shop with 200 endpoints that funnels CUI work through 25 devices inside an enclave is assessed on a much smaller footprint, with fewer systems to harden, document, monitor, and produce evidence for.
- Cost and disruption drop. FIPS-validated encryption, hardened baselines, session controls, and continuous logging are expensive to apply company-wide and reasonable to apply to a bounded environment.
- The boundary becomes explainable. An assessor can follow a diagram. A diffuse environment where CUI might be anywhere is very hard to attest to honestly.
- General business systems stay flexible. Sales, marketing, and general operations do not inherit CUI controls they do not need.
When an enclave is the wrong answer
An enclave adds a boundary, and boundaries have to be enforced. It is the wrong answer when CUI genuinely permeates the business, because you end up maintaining two environments and still assessing most of the company. It is also the wrong answer when the workflow forces constant movement of data across the boundary, since every crossing is a control point that can fail. And it fails outright when it exists only on paper: if engineers routinely email drawings to their personal workstations, the enclave boundary is fiction and the assessment will say so.
The honest decision comes out of a scoping exercise, not a product choice. Map where CUI enters, where it is processed, where it is stored, who touches it, and where it leaves. The right architecture usually becomes obvious once that map exists. That mapping is the first stage of our CMMC gap assessment, and the engineering patterns we deploy are documented on the CMMC technical stack page. If you want the buyer-facing overview of the whole program instead, start at CMMC compliance.
Frequently Asked Questions About CUI
What is CUI in simple terms?
CUI is unclassified information that the government requires you to protect or to limit sharing of, because a law, regulation, or government-wide policy says so. It is not classified, and it is not ordinary business data. Executive Order 13556 created the program and 32 CFR Part 2002 sets the rules.
What DoD instruction implements CUI?
DoD Instruction 5200.48, issued March 6, 2020, implements the CUI Program inside the Department of Defense. It establishes policy and assigns responsibilities for identifying, marking, safeguarding, disseminating, decontrolling, and destroying CUI, consistent with Executive Order 13556 and 32 CFR Part 2002.
Who can control CUI?
Designation is a Federal Government function performed by an authorized holder acting on behalf of an agency. Contractors are authorized holders who receive, mark, safeguard, disseminate, and destroy CUI according to the contract and the governing category rules. A contractor cannot designate its own commercial information as CUI, and cannot decontrol government information.
What is a CUI authorized holder responsible for?
Verifying a lawful government purpose before sharing, applying and preserving correct markings, safeguarding the information at rest and in transit, refraining from removing another agency's markings, challenging designations believed to be improper, reporting suspected unauthorized disclosure, and destroying CUI so that it is unreadable, indecipherable, and unrecoverable when it is no longer required.
What level of system is required for CUI?
A nonfederal system that processes, stores, or transmits CUI under DFARS 252.204-7012 must implement NIST SP 800-171. Under the CMMC Program rule at 32 CFR Part 170, that corresponds to CMMC Level 2, which is the 110 NIST SP 800-171 security requirements. Cloud services in that boundary must meet security requirements equivalent to the FedRAMP Moderate baseline, and cryptography protecting CUI must be FIPS-validated.
What is the difference between CUI Basic and CUI Specified?
CUI Basic follows the uniform safeguarding and dissemination controls in 32 CFR Part 2002 because the authorizing law or policy does not prescribe specifics. CUI Specified follows the specific controls written into the underlying authority, which may be stricter. Export-controlled information is a common Specified example because export law imposes its own access restrictions.
Which of the following are types of CUI?
The authoritative list is the CUI Registry maintained by the National Archives. Its index groupings include Defense, Export Control, Procurement and Acquisition, Privacy, Critical Infrastructure, Proprietary Business Information, Law Enforcement, Legal, Intelligence, Nuclear, Tax, Statistical, Transportation, Immigration, Financial, International Agreements, NATO, Patent, and Natural and Cultural Resources. If a category is not in the Registry, it is not CUI.
Is FCI the same as CUI?
No. Federal Contract Information is defined in FAR 52.204-21 as information not intended for public release that is provided by or generated for the government under a contract. FCI triggers the 15 basic safeguarding requirements of FAR 52.204-21, which is CMMC Level 1. CUI is a higher bar defined by Executive Order 13556 and 32 CFR Part 2002 and triggers NIST SP 800-171 and CMMC Level 2.
What is a CUI enclave?
A CUI enclave is a bounded environment that contains all of an organization's CUI so that security requirements and assessment scope apply to that environment rather than to the entire company. It is an architectural pattern, not a regulatory term, and it works only when the boundary is genuinely enforced in daily workflow.
How fast do I have to report a CUI incident?
DFARS 252.204-7012 requires rapid reporting to the Department of Defense within 72 hours of discovering a cyber incident affecting covered defense information. Reporting requires a medium assurance certificate, and the clause also requires preserving affected images and monitoring data for at least 90 days and submitting isolated malicious software to the government.
Does "For Official Use Only" still exist?
DoD Instruction 5200.48 discontinued the use of the FOUO marking for newly created information in favor of CUI markings. Legacy documents marked FOUO may still be in circulation and do not become uncontrolled automatically, but new material generated under DoD policy is marked as CUI.
Who can help us scope and protect CUI?
Petronella Technology Group, Inc. is a CMMC Registered Provider Organization, RPO #1449, based in Raleigh, North Carolina and serving defense contractors nationwide. Start with a CMMC gap assessment to map where CUI lives, then work the boundary and control implementation from there. Call (919) 348-4912.
Sources and Authorities
Every claim on this page traces to one of the following instruments. Read them directly before making a compliance decision.
- Executive Order 13556, "Controlled Unclassified Information," November 4, 2010
- 32 CFR Part 2002, "Controlled Unclassified Information," the National Archives implementing rule
- The CUI Registry, maintained by the National Archives and Records Administration
- DoD Instruction 5200.48, "Controlled Unclassified Information (CUI)," March 6, 2020
- DoD Instruction 5230.24, "Distribution Statements on DoD Technical Information"
- FAR 52.204-21, "Basic Safeguarding of Covered Contractor Information Systems"
- DFARS 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021
- NIST SP 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations"
- NIST SP 800-172, enhanced security requirements referenced by CMMC Level 3
- NIST SP 800-88, "Guidelines for Media Sanitization"
- 32 CFR Part 170, the CMMC Program rule, and the CMMC assessment scoping guidance
Find out exactly where your CUI lives
Most contractors do not have a CUI problem. They have a CUI boundary problem. A gap assessment maps every place CUI enters, rests, moves, and leaves your business, scores you against NIST SP 800-171, and gives you a remediation sequence you can actually execute. Petronella Technology Group, Inc., RPO #1449.