What Is Controlled Unclassified Information (CUI)?
CUI is information the government creates or possesses that requires safeguarding but is not classified. Understanding exactly what qualifies as CUI — and what doesn't — is the foundation of scoping your CMMC environment.
Controlled Unclassified Information (CUI) is information that the government has determined requires safeguarding or dissemination controls consistent with applicable law, regulations, and government-wide policies. It is defined under Executive Order 13556 and managed by the National Archives and Records Administration (NARA) through the CUI Registry, which lists over 125 categories across 20 groupings.
CUI is not classified. It does not require a security clearance to access. But it requires protection under specific legal authorities, and mishandling it can result in contract termination, debarment, and civil or criminal penalties under laws like the Trade Secrets Act.
CUI Basic vs. CUI Specified
- ✓CUI Basic: handling and safeguarding requirements are governed by the CUI Program rules alone (32 CFR Part 2002). NIST SP 800-171 is the standard for CUI Basic protection.
- ✓CUI Specified: the authorizing law, regulation, or policy imposes more specific handling requirements than the baseline CUI rules. Export-controlled technical data (EAR/ITAR) is the most common example in the defense sector.
Common CUI categories in the defense industrial base
- ✓Controlled Technical Information (CTI): technical data with military or space application subject to controls on access, use, reproduction, modification, or release
- ✓Export Controlled: technical data and software subject to the Export Administration Regulations (EAR) or International Traffic in Arms Regulations (ITAR)
- ✓Naval Nuclear Propulsion Information (NNPI): information about design, manufacture, and maintenance of naval nuclear propulsion systems
- ✓Procurement and Acquisition: source selection information, contractor bid/proposal information, procurement-sensitive data
- ✓Privacy: personally identifiable information about DoD personnel or their families
Practical rule
What is NOT CUI
Public information (anything cleared for public release), administrative matters that do not touch federal interests, commercial off-the-shelf product specifications, and general business communications with no sensitive government data are not CUI. The distinction matters because it determines your CUI boundary — the systems, networks, and devices you need to include in your CMMC assessment scope.
Ready to start your CMMC journey?
Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.
More in Getting Started
