Controlled Unclassified Information (CUI) is information created or possessed by the U.S. Government, or information an entity creates or possesses for or on behalf of the Government, that requires safeguarding or dissemination controls under applicable law, regulation, or governmentwide policy. CUI is not classified information, but it cannot necessarily be handled in the same way as ordinary public or unrestricted business information.
The governmentwide CUI Program was established by Executive Order 13556 in 2010 to standardize how executive branch agencies handle sensitive unclassified information. The National Archives and Records Administration (NARA) serves as the Executive Agent for the program, while 32 CFR Part 2002 establishes the governmentwide implementing requirements. For federal contractors, CUI becomes particularly important when contract performance requires access to government information that must be protected outside federal systems.
What Information Can Be Considered CUI?
CUI is not a single type of document or data. It is an umbrella framework covering information that requires protection because a law, regulation, or governmentwide policy establishes safeguarding or dissemination controls. Information cannot properly become CUI merely because an agency or contractor considers it sensitive.
The authoritative source for CUI categories and subcategories is the CUI Registry maintained by NARA. The Registry organizes CUI into numerous categories covering different government functions and identifies the authorities associated with each category. These include areas such as defense, privacy, procurement and acquisition, financial information, critical infrastructure, export control, law enforcement, and intelligence-related information.
Depending on the applicable authority and contract, examples of information that may fall within the CUI framework include:
- certain controlled technical information;
- export-controlled information;
- specific procurement and acquisition information;
- certain personally identifiable information;
- critical infrastructure information subject to applicable controls;
- information concerning security vulnerabilities;
- certain law enforcement information;
- information protected under particular statutory or regulatory programs.
Not every piece of information in these areas automatically qualifies as CUI. The relevant safeguarding or dissemination requirement must be based on an authority recognized by the CUI Program. This prevents agencies from creating their own informal categories of sensitive unclassified information without an appropriate legal or policy basis.
The distinction also matters for contractors. A company’s proprietary pricing, internal business plan, customer database, or confidential commercial information does not automatically become CUI simply because the company considers it sensitive. CUI is specifically tied to government information and the authorities governing its protection.
CUI Basic, CUI Specified, and Classified Information
The CUI framework distinguishes between CUI Basic and CUI Specified. Both are Controlled Unclassified Information, but the source and nature of the required controls differ.
CUI Basic is information for which the authorizing law, regulation, or governmentwide policy does not establish specific handling or dissemination controls. It is handled according to the uniform requirements of the CUI Program.
CUI Specified applies when the underlying authority contains specific controls that differ from, or add requirements to, the general CUI framework. Organizations handling CUI Specified therefore need to consider both the CUI Program and the requirements established by the relevant authority.
| Information Type | Classification Status | General Handling Basis |
|---|---|---|
| Public information | Unclassified | Approved for public release and does not require CUI controls |
| CUI Basic | Unclassified | Standard CUI safeguarding and dissemination requirements apply |
| CUI Specified | Unclassified | Specific controls are established or required by the underlying authority |
| Classified information | Classified | Handled under the federal classified national security information framework |
The distinction between CUI and classified information is fundamental. CUI does not include information classified under Executive Order 13526 or the Atomic Energy Act, as amended. CUI remains unclassified even when disclosure could cause harm and specific controls are required.
This also means that labels such as “sensitive,” “proprietary,” or “confidential” should not automatically be treated as synonyms for CUI. The CUI designation depends on the governmentwide framework and an applicable authority, not simply on the perceived sensitivity of the information.
How CUI Is Marked and Shared
CUI markings help authorized users recognize information that requires controlled handling. NARA’s CUI Marking Handbook provides guidance for marking documents and other materials containing CUI. The CUI banner marking is generally placed at the top of each page containing CUI and can identify whether the information is CUI Basic or include additional category or dissemination information when required.
The marking system can include:
- the CUI control marking;
- CUI category or subcategory markings when required;
- limited dissemination control markings;
- designation indicators identifying the organization responsible for designating the information;
- portion markings when they are required or used.
Marking is important, but it is not the sole factor determining whether information is CUI. The underlying information and applicable authority remain central. An incorrect or missing marking does not necessarily mean that information requiring CUI protection can be freely disclosed.
CUI also is not intended to prevent legitimate information sharing. Authorized holders may share CUI when the recipient has a lawful government purpose for receiving it and the disclosure is consistent with applicable controls. “Lawful Government Purpose” is an important concept within the CUI Program because access is based on whether the information is needed in connection with an authorized government activity rather than on a traditional security clearance.
Organizations must still protect the information during transmission, storage, processing, and disposal. Sending CUI through an inappropriate communication channel or placing it in an uncontrolled public location can create a safeguarding problem even if every person involved was otherwise authorized to work on the contract.
CUI on Contractor Information Systems
CUI requirements become especially important when federal information leaves government-controlled environments and is processed, stored, or transmitted on contractor systems. The applicable cybersecurity requirements depend on the agency, contract, type of information, and governing regulations.
For nonfederal systems and organizations, NIST Special Publication 800-171 has long provided security requirements for protecting CUI. The publication addresses security areas such as access control, authentication, audit and accountability, configuration management, incident response, media protection, physical protection, risk assessment, and system integrity.
A contractor handling CUI should know at minimum:
- What CUI the contract requires the company to receive, create, store, process, or transmit.
- Which information systems and users will have access to that CUI.
- Which contract clauses and cybersecurity requirements apply.
- Whether subcontractors will receive or process the information.
- What controls apply to storage, transmission, access, incident reporting, and disposal.
- Whether additional requirements apply to a specific CUI category.
The Department of Defense has additional requirements for contractors handling CUI and other covered defense information. DFARS 252.204-7012 addresses safeguarding covered defense information and cyber incident reporting, while DoD’s Cybersecurity Maturity Model Certification program establishes assessment requirements associated with specified DoD contracts.
This DoD framework should not be generalized to every federal procurement. A civilian agency contractor handling CUI may operate under different contractual requirements. Contractors should therefore start with the actual solicitation and contract clauses rather than assuming that every CUI requirement automatically means DFARS or CMMC applies.
Subcontracting also deserves attention. When contract performance requires CUI to move to a subcontractor, the prime contractor needs to determine what requirements must flow down and whether the subcontractor’s systems are appropriate for handling the information. Sending CUI to another company does not remove the safeguarding obligations attached to it.
CUI and Federal Acquisition
CUI can affect an acquisition well before a contractor begins performing the work. Agencies should determine whether contract performance will involve CUI and communicate applicable requirements through procurement documentation. Offerors can then evaluate whether their systems, personnel, subcontractors, and procedures are capable of satisfying those requirements.
For contractors, this makes CUI review part of both proposal preparation and contract administration. Before accepting work involving CUI, a company should understand what information will be provided, how it must be protected, and whether its existing technology environment supports the required controls.
Several practical questions should be addressed during contract review:
- Will the contractor receive CUI from the agency or create CUI during performance?
- What CUI categories are expected?
- Which contract clauses establish safeguarding requirements?
- Can the information be stored in the contractor’s current systems?
- Are cloud services or external platforms involved?
- Will subcontractors need access?
- What reporting obligations apply if a security incident occurs?
These questions are particularly important for contractors accustomed to handling only publicly available solicitation and contract information. Documents posted publicly on SAM.gov, GSA eLibrary, or other authorized government sources should not be assumed to require CUI protection merely because they relate to a federal acquisition. Conversely, nonpublic information received during contract performance may require controls depending on its content and governing authority.
The CUI designation also does not automatically prohibit contractors from using commercial technology. The relevant question is whether the systems and services used to handle the information satisfy the requirements applicable to that contract and CUI environment.
What GSA Contractors Should Understand About CUI
GSA Schedule contractors should distinguish between obtaining a Multiple Award Schedule contract and performing an individual federal order that involves CUI. Holding a Schedule contract does not mean that every document exchanged with GSA or every agency customer is CUI. The information involved in a specific acquisition or order determines whether CUI requirements become relevant.
A contractor providing ordinary commercial products through a Schedule may encounter little or no CUI in some transactions. A contractor providing IT services, cybersecurity support, engineering work, system integration, professional services, or other work involving nonpublic government information may face much more significant safeguarding obligations.
For this reason, contractors should not create a single companywide rule that treats all government information as CUI. Overmarking can make legitimate information sharing and contract administration more difficult, while undermarking can expose information that actually requires protection. The better approach is to identify the applicable information category, authority, contract requirement, and system controls.
Contractors should also maintain procedures for employees who encounter information they believe may be improperly marked. Questions about CUI status should be addressed through the appropriate contracting or government channels rather than resolved by independently removing markings or publicly releasing the information.
CUI is ultimately a governmentwide system for controlling sensitive but unclassified information according to established authorities. For federal contractors, the practical issue is not simply recognizing the CUI label. Companies need to know what information they are receiving or creating, why it is controlled, what contractual safeguards apply, where it can be processed or stored, who may receive it, and what obligations continue when the information is shared with subcontractors.
