If you're a defense contractor, you're likely handling Controlled Unclassified Information (CUI). This is government information that's sensitive enough to require safeguards under federal law or policy, but isn’t classified information. Knowing exactly what counts as CUI matters because it determines your compliance obligations, cybersecurity requirements, and ultimately your eligibility to bid on DoD contracts.
But understanding what CUI is at a definitional level is different from being able to identify what it looks like in your contracts and day to day work.
This article walks through real examples of controlled unclassified information, organized by category, so you can start identifying and protecting CUI in your own contracts and systems.
What is CUI?
CUI is any information that falls under one of the categories defined by the ISOO CUI Registry, meaning it's tied to a specific federal law, regulation, or government-wide policy that requires safeguarding. It's not classified, but it's not public either.
Examples of CUI by category
Examples of controlled unclassified information (CUI) include data tied to dozens of categories, each with its own legal basis for protection.
Here are the categories defense contractors most often encounter:
- Defense Information related to military or national defense that isn't classified but still requires protection, such as technical and operational data tied to weapons systems and defense infrastructure.
- Export Control Information controlled by export regulations like ITAR or EAR, covering technical data and research that requires a license before it can be shared outside the US or with foreign nationals.
- Privacy Personally identifiable information (PII) and other data protected under privacy laws, covering everything from health records to personnel files.
- Procurement and Acquisition Information related to federal procurement and acquisition processes, including proposals, evaluations, and source selection materials.
- Proprietary Business Information Sensitive commercial or business information a company shares with the government, including trade secrets and confidential agreements.
- Critical Infrastructure Information related to physical or virtual systems essential to public safety, economic security, or national security.
- Law Enforcement Information tied to law enforcement investigations or operations, including records, communications, and protections for people involved.
- Financial Information about financial institutions, systems, or individuals, including regulatory reports and sensitive financial data.
The table below pulls directly from the National Archives' ISOO CUI Registry to show the actual subcategories and give common examples within each.
Note that this isn't the full registry, which includes approximately 20 categories and dozens of subcategories. It's a curated list of the categories defense contractors most commonly encounter.
Common ISOO Registry CUI categories + examples for defense contractors
| CUI Category | CUI Examples |
|---|---|
| Defense | |
| Controlled Technical Information | Engineering drawings, technical manuals, and specifications for defense systems |
| Naval Nuclear Propulsion Information | Technical data related to naval nuclear propulsion systems |
| Unclassified Controlled Nuclear Information - Defense | Unclassified nuclear information tied to defense programs |
| Export Control | |
| Export Controlled | Technical data and items controlled under ITAR or EAR |
| Export Controlled Research | Research data subject to export control requirements |
| Privacy | |
| Health Information | Medical records and other health information covered by privacy law |
| Personnel Records | Records related to the employees of federal agencies |
| Military Personnel Records | Personnel records specific to military service members |
| Procurement and Acquisition | |
| General Procurement and Acquisition | Cost or pricing data, contract information, and rate data tied to federal acquisitions |
| Source Selection | Source selection sensitive information tied to a federal acquisition |
| Small Business Research and Technology | Technical and proprietary data submitted under small business research programs |
| Proprietary Business Information | |
| General Proprietary Business Information | Trade secrets and confidential business data shared with the government |
| Proprietary Manufacturer | Information about the production of a consumer product, including private-label products |
| Critical Infrastructure | |
| Critical Energy Infrastructure Information | Sensitive information about energy infrastructure systems |
| Information Systems Vulnerability Information | Information that could result in adverse effects to information systems if not protected, such as vulnerability data |
| Physical Security | Information related to the protection of federal buildings, grounds, or property |
| Law Enforcement | |
| Criminal History Records Information | Criminal history records maintained by law enforcement |
| Investigation | Information obtained during a law enforcement investigation or action, civil or criminal |
| Informant | Information that could identify a confidential informant |
| Financial | |
| Bank Secrecy | Reports filed under the Bank Secrecy Act |
| General Financial Information | Information tied to financial institutions or US government fiscal functions, such as customer information held by a financial institution |
While the ISOO Registry is the government-wide source, it’s important to note that the Department of Defense maintains its own DoD CUI Registry, aligned with DFARS and CMMC requirements specifically for defense contracts. If you're working under a DoD contract, this is often the version you’ll want to reference, since it ties CUI categories to the requirements you're actually subject to.
Recommended reading
CUI Categories and the DoD + ISOO CUI Registry
Read MoreExamples of derivative CUI
If you create a new document that incorporates or references CUI source material, that new document typically inherits the original CUI designation.
Examples of derivative CUI include:
- An engineering analysis built on CUI drawings
- A technical report summarizing CUI test data
- An internal memo that reproduces CUI content
If the source material is CUI, treat the derivative as CUI too, unless it's been formally decontrolled.
Identifying CUI within your organization
Knowing the categories is one thing. Spotting CUI in your actual day-to-day operations is another. Here's where it tends to show up for most defense contractors:
- In your engineering and technical systems. If you design, build, or maintain hardware or software for a defense program, your PLM system, CAD files, test data repositories, and version control systems are common homes for Controlled Technical Information. This is often the first place CUI enters an organization, frequently before anyone has formally flagged it as such.
- In your email and file sharing. CUI doesn't stay contained to the system it originated in. It moves through email attachments, shared drives, and collaboration tools the moment someone forwards a drawing, attaches a test report to a status update, or uploads a document to a shared folder. This is also where CUI is most likely to leak outside your boundary, since email and general-purpose cloud storage often aren't configured to handle it.
- In your contracts and procurement files. Look at your SharePoint sites, contract management systems, and shared folders used during proposal development. Source selection materials, technical proposals, and acquisition planning documents frequently contain CUI well before a contract is even awarded.
- In your HR and personnel systems. Background investigation files, personnel records tied to military or government personnel, and any system storing employee PII for cleared or contract-specific roles can fall under CUI's privacy categories.
- On laptops, mobile devices, and in printed form. CUI isn't only a digital concern. Printed engineering drawings left on a desk, a laptop with cached CUI files taken off-site, or a phone with CUI email synced to it are all part of your CUI boundary too, and all common sources of mishandling.
- With your subcontractors and vendors. If you share CUI with a subcontractor, supplier, or partner, whether through email, a shared portal, or physical documents, that flow of information is part of your CUI boundary as well. A subcontractor's weak controls can become your compliance gap.
CUI rarely lives in one tidy, well-labeled location. It moves across systems, departments, and people, often without being explicitly marked. This is why defining your CUI boundary and mapping where this information actually flows through your organization is one of the most important steps in scoping your CMMC compliance program.
The goal isn't to memorize every CUI category, but to build the habit of asking where this information lives and how it moves before it becomes a compliance gap or security breach.
Once you've started identifying CUI in your own environment, the next step is formally mapping it. Read our guide to CUI scoping for a step-by-step walkthrough to identify, map, and define your CUI boundary.