What is Controlled Unclassified Information?
Controlled Unclassified Information (CUI) is information the United States Government creates or possesses, or that an organization creates or possesses on its behalf, that a law, regulation, or government-wide policy requires to be safeguarded or to have its dissemination controlled.
Two parts of that definition carry the weight.
It is unclassified. CUI is not Confidential, Secret, or Top Secret. It sits below the classification system entirely, which is why people underestimate it.
The requirement comes from an authority, not from an opinion. Something is CUI because a law, regulation, or government-wide policy says it must be protected. A marking on a document reflects that determination. It does not create it.
Where the categories come from
The National Archives and Records Administration (NARA) maintains the CUI Registry, which is the authoritative list of categories. If a category is not in the Registry, it is not CUI.
Common categories in the defense industrial base include Controlled Technical Information, Export Controlled information, and Critical Infrastructure Security Information. The Registry groups categories into organizational index groupings and states the authority behind each.
CUI Basic and CUI Specified
| Type | What it means |
|---|---|
| CUI Basic | The authority requires safeguarding but does not specify how. The standard CUI controls apply. |
| CUI Specified | The authority names specific handling, marking, dissemination, or destruction requirements. Those requirements take precedence. |
CUI Specified is the one that surprises organizations, because its controls can exceed the general baseline and vary by category.
CUI and FCI are not the same
| Federal Contract Information (FCI) | Controlled Unclassified Information (CUI) | |
|---|---|---|
| Definition source | FAR 52.204-21 | 32 CFR part 2002 and the NARA CUI Registry |
| What it is | Information provided by or generated for the government under a contract, not intended for public release | Information a law, regulation, or government-wide policy requires to be safeguarded |
| Typical protection level | CMMC Level 1 (Self), 15 basic safeguarding requirements | CMMC Level 2, the 110 requirements of NIST SP 800-171 |
| Marking | Not marked as a category | Marked per the CUI program |
Most organizations that hold CUI also hold FCI. The reverse is not true, and scoping a contract correctly starts with knowing which you actually have.
What handling CUI obliges you to do
If a contract includes DFARS 252.204-7012, holding CUI on your own systems means:
- Implementing the 110 security requirements of NIST SP 800-171.
- Reporting a cyber incident to the Department of War within 72 hours through the DIBNet portal.
- Ensuring any cloud service provider processing CUI meets FedRAMP Moderate or equivalent.
- Flowing the clause down to subcontractors who will handle CUI.
- Posting a self-assessment score to the Supplier Performance Risk System (SPRS) under DFARS 252.204-7019 and 252.204-7020.
See DFARS 252.204-7012, NIST SP 800-171 self-assessment, and your SPRS score.
Marking
CUI carries a banner marking at the top of each page, an optional portion marking on each paragraph, and a designation indicator identifying who designated it and under what authority. See CUI marking for the full rules, including why FOUO and similar legacy markings were retired.
What the kit does
Item
- CMMC, US government, NATO, and national markings with clearances, mandatory access control, and audited formal release. The label catalog includes Unclassified, FCI, CUI, and CUI Specified.
- Enforce the markings. Each person gets a top clearance, and in enforce mode a person cannot read a record marked above it.
- Record who accessed a marked record and when
- Mail for Federal Contract Information or Controlled Unclassified Information inside the kit
- Store and share sensitive files with classification marking
- Decide which of your own documents are CUI, and apply banner and portion markings to documents created outside the kit
See data classification.
Common questions
Who decides something is CUI?
The government designates it, through the authority that requires its protection. A contractor applies markings consistent with that designation and with what the contract states.
Is CUI classified information?
No. It is unclassified. The protections are contractual and regulatory rather than part of the national security classification system.
Does CUI expire?
The control ends when the authority no longer requires it, through a process called decontrolling. Decontrolling does not authorize public release on its own.
What if we are not sure whether we hold CUI?
Ask the contracting officer. Guessing in either direction is costly: assuming you do not creates an unmet obligation, and assuming you do expands your scope and your cost.
Does FCI become CUI over time?
No. They are separate definitions with separate authorities. A contract can involve both.
Related pages
- CUI marking
- DFARS 252.204-7012
- NIST SP 800-171 and the self-assessment
- Your SPRS score
- CMMC Level 2 and CMMC Level 1
- CMMC Phase 2
- Data classification
- AIC CMMC Completeâ„¢ and pricing
- Glossary