Skip to main content

CMMC Pause: What DoW & Primes Still Require

background

Examples of CUI for Defense Contractors

  • cui
  • Examples of CUI for Defense Contractors

If you're a defense contractor, you're likely handling Controlled Unclassified Information (CUI). This is government information that's sensitive enough to require safeguards under federal law or policy, but isn’t classified information. Knowing exactly what counts as CUI matters because it determines your compliance obligations, cybersecurity requirements, and ultimately your eligibility to bid on DoD contracts.

But understanding what CUI is at a definitional level is different from being able to identify what it looks like in your contracts and day to day work. 

This article walks through real examples of controlled unclassified information, organized by category, so you can start identifying and protecting CUI in your own contracts and systems.

What is CUI?

CUI is any information that falls under one of the categories defined by the ISOO CUI Registry, meaning it's tied to a specific federal law, regulation, or government-wide policy that requires safeguarding. It's not classified, but it's not public either. 

Examples of CUI by category

Examples of controlled unclassified information (CUI) include data tied to dozens of categories, each with its own legal basis for protection. 

Here are the categories defense contractors most often encounter: 

  • Defense Information related to military or national defense that isn't classified but still requires protection, such as technical and operational data tied to weapons systems and defense infrastructure.
  • Export Control Information controlled by export regulations like ITAR or EAR, covering technical data and research that requires a license before it can be shared outside the US or with foreign nationals.
  • Privacy Personally identifiable information (PII) and other data protected under privacy laws, covering everything from health records to personnel files.
  • Procurement and Acquisition Information related to federal procurement and acquisition processes, including proposals, evaluations, and source selection materials.
  • Proprietary Business Information Sensitive commercial or business information a company shares with the government, including trade secrets and confidential agreements.
  • Critical Infrastructure Information related to physical or virtual systems essential to public safety, economic security, or national security.
  • Law Enforcement Information tied to law enforcement investigations or operations, including records, communications, and protections for people involved.
  • Financial Information about financial institutions, systems, or individuals, including regulatory reports and sensitive financial data.

The table below pulls directly from the National Archives' ISOO CUI Registry to show the actual subcategories and give common examples within each. 

Note that this isn't the full registry, which includes approximately 20 categories and dozens of subcategories. It's a curated list of the categories defense contractors most commonly encounter.

Common ISOO Registry CUI categories + examples for defense contractors

CUI Category CUI Examples
Defense
Controlled Technical Information Engineering drawings, technical manuals, and specifications for defense systems
Naval Nuclear Propulsion Information Technical data related to naval nuclear propulsion systems
Unclassified Controlled Nuclear Information - Defense Unclassified nuclear information tied to defense programs
Export Control
Export Controlled Technical data and items controlled under ITAR or EAR
Export Controlled Research Research data subject to export control requirements
Privacy
Health Information Medical records and other health information covered by privacy law
Personnel Records Records related to the employees of federal agencies
Military Personnel Records Personnel records specific to military service members
Procurement and Acquisition
General Procurement and Acquisition Cost or pricing data, contract information, and rate data tied to federal acquisitions
Source Selection Source selection sensitive information tied to a federal acquisition
Small Business Research and Technology Technical and proprietary data submitted under small business research programs
Proprietary Business Information
General Proprietary Business Information Trade secrets and confidential business data shared with the government
Proprietary Manufacturer Information about the production of a consumer product, including private-label products
Critical Infrastructure
Critical Energy Infrastructure Information Sensitive information about energy infrastructure systems
Information Systems Vulnerability Information Information that could result in adverse effects to information systems if not protected, such as vulnerability data
Physical Security Information related to the protection of federal buildings, grounds, or property
Law Enforcement
Criminal History Records Information Criminal history records maintained by law enforcement
Investigation Information obtained during a law enforcement investigation or action, civil or criminal
Informant Information that could identify a confidential informant
Financial
Bank Secrecy Reports filed under the Bank Secrecy Act
General Financial Information Information tied to financial institutions or US government fiscal functions, such as customer information held by a financial institution

While the ISOO Registry is the government-wide source, it’s important to note that the Department of Defense maintains its own DoD CUI Registry, aligned with DFARS and CMMC requirements specifically for defense contracts. If you're working under a DoD contract, this is often the version you’ll want to reference, since it ties CUI categories to the requirements you're actually subject to.

Recommended reading

CUI Categories and the DoD + ISOO CUI Registry

Read More

Examples of derivative CUI

If you create a new document that incorporates or references CUI source material, that new document typically inherits the original CUI designation. 

Examples of derivative CUI include:

  • An engineering analysis built on CUI drawings
  • A technical report summarizing CUI test data
  • An internal memo that reproduces CUI content

If the source material is CUI, treat the derivative as CUI too, unless it's been formally decontrolled.

Identifying CUI within your organization

Knowing the categories is one thing. Spotting CUI in your actual day-to-day operations is another. Here's where it tends to show up for most defense contractors:

  • In your engineering and technical systems. If you design, build, or maintain hardware or software for a defense program, your PLM system, CAD files, test data repositories, and version control systems are common homes for Controlled Technical Information. This is often the first place CUI enters an organization, frequently before anyone has formally flagged it as such.
  • In your email and file sharing. CUI doesn't stay contained to the system it originated in. It moves through email attachments, shared drives, and collaboration tools the moment someone forwards a drawing, attaches a test report to a status update, or uploads a document to a shared folder. This is also where CUI is most likely to leak outside your boundary, since email and general-purpose cloud storage often aren't configured to handle it.
  • In your contracts and procurement files. Look at your SharePoint sites, contract management systems, and shared folders used during proposal development. Source selection materials, technical proposals, and acquisition planning documents frequently contain CUI well before a contract is even awarded.
  • In your HR and personnel systems. Background investigation files, personnel records tied to military or government personnel, and any system storing employee PII for cleared or contract-specific roles can fall under CUI's privacy categories.
  • On laptops, mobile devices, and in printed form. CUI isn't only a digital concern. Printed engineering drawings left on a desk, a laptop with cached CUI files taken off-site, or a phone with CUI email synced to it are all part of your CUI boundary too, and all common sources of mishandling.
  • With your subcontractors and vendors. If you share CUI with a subcontractor, supplier, or partner, whether through email, a shared portal, or physical documents, that flow of information is part of your CUI boundary as well. A subcontractor's weak controls can become your compliance gap.

CUI rarely lives in one tidy, well-labeled location. It moves across systems, departments, and people, often without being explicitly marked. This is why defining your CUI boundary and mapping where this information actually flows through your organization is one of the most important steps in scoping your CMMC compliance program. 

The goal isn't to memorize every CUI category, but to build the habit of asking where this information lives and how it moves before it becomes a compliance gap or security breach.

Once you've started identifying CUI in your own environment, the next step is formally mapping it. Read our guide to CUI scoping for a step-by-step walkthrough to identify, map, and define your CUI boundary.

Loading...