Skip to main content

🔔 Notifications Hub: See compliance updates in one place

Covered Defense Information (CDI)

Covered Defense Information is the DFARS 252.204-7012 term for unclassified information that requires safeguarding. In practice, CDI means Controlled Unclassified Information (CUI) used in DoD contracts. It is what triggers NIST SP 800-171 implementation and CMMC Level 2 scope. If your contract says 252.204-7012 and identifies CDI, you are handling CUI.

CDI vs CUI vs CTI

CDI is the DFARS-specific term. CUI is the government-wide category from the NARA CUI program. CTI (Controlled Technical Information) is a specific CUI subcategory for military/space technical data. In DoD contracts, 'CDI' usually means 'the CUI and CTI we're sharing under this contract.' Don't read too much into the term difference; for practical safeguarding purposes they are the same data.

How CDI Gets Identified

  • Contract markings: specific deliverables or data types are flagged as controlled.
  • DD Form 254 (Contract Security Classification Specification): identifies controlled information categories when classified or controlled work is involved.
  • Statement of Work: references CUI categories or handling requirements.
  • Government-provided contractor guidance: additional documents from the program office.

What CDI Triggers

Once CDI is in the contract, DFARS 252.204-7012 applies. That means all 110 NIST SP 800-171 practices, 72-hour cyber incident reporting to DIBNet, and flow-down to subcontractors where CDI is shared. It also means CMMC Level 2 is the right target, not Level 1.

When Classification Is Unclear

If you can't tell whether specific information in your contract is CDI, ask the contracting officer in writing. Don't guess. Guessing upward (treating everything as CDI) inflates your scope and assessment cost. Guessing downward leaves you non-compliant when the contracting officer eventually clarifies. The CO is required to tell you.