Skip to main content

CMMC Pause: What DoW & Primes Still Require

background

What Is CUI? A Guide to Controlled Unclassified Information

  • cui
  • What Is CUI? A Guide to Controlled Unclassified Information

If you're a defense contractor, there's a good chance you're handling Controlled Unclassified Information (CUI), whether it’s labeled that way or not. So how do you know what counts as CUI? And why does it matter so much in the first place?

The official CUI definition

CUI stands for Controlled Unclassified Information. Per 32 CFR Part 2002, the definition of controlled unclassified information is: 

Information the government creates or possesses, or that a contractor creates or possesses on the government's behalf, where a law, regulation, or government-wide policy requires or permits safeguarding or dissemination controls.

Essentially, CUI is government information that's sensitive enough to require protection under federal law or policy, but doesn't meet the bar for classification. Some examples of CUI include: 

  • Engineering drawings or technical manuals for a defense system (Controlled Technical Information)
  • Technical data subject to an export license under ITAR or EAR (Export Controlled information)
  • Personnel records protected under the Privacy Act, like background investigation files

That last example points to a common misconception: not all sensitive data is CUI. It only becomes CUI when it's tied to a specific law, regulation, or government-wide policy that requires safeguarding, like the Privacy Act covering federal personnel records. General PII your HR department collects in the normal course of business isn't CUI just because it's PII; it has to connect back to a government contract and a recognized CUI authority to qualify under 32 CFR 2002

Recommended reading

Examples of CUI for Defense Contractors

Read More

Why CUI matters for US national security

Every year, the Department of Defense shares sensitive information with the companies that build, maintain, and support its weapons systems, vehicles, aircraft, and IT infrastructure. Think engineering specs for a fighter jet component, test results from a new radar system, or technical drawings for a vehicle used in the field. 

None of that information is classified in the traditional sense (it's not Secret or Top Secret) but if it fell into the wrong hands, it could give an adversary insight into how US defense systems work, where their vulnerabilities are, or how to counter them.

This means every contractor who touches CUI becomes part of the nation's defense posture. A single unprotected laptop, an email sent to the wrong address, or a vendor with insufficient security controls can become the weak link an adversary exploits to access information that can affect national security.

Where the CUI Program came from

Before 2010, federal agencies used a patchwork of labels to mark information: "For Official Use Only" (FOUO), "Sensitive But Unclassified" (SBU), "Law Enforcement Sensitive" (LES), and others. There was no shared standard, which created confusion for contractors and friction between agencies.

Executive Order 13556, signed on November 4, 2010, established a single government-wide CUI Program, named the National Archives (NARA) as the Executive Agent, and extended safeguarding requirements to non-federal systems.

NARA's Information Security Oversight Office (ISOO) now maintains the official CUI Registry, the definitive list of what qualifies as CUI and how it must be handled. The Department of Defense maintains its own DoD CUI Program aligned with DFARS and CMMC.

The ISOO Registry organizes CUI into categories like Defense, Export Control, Privacy, Financial, Law Enforcement, and more, each tied to its own legal authority. A defense contractor might encounter CUI under several of these categories at once, depending on the contract.

What is CMMC, and what does it have to do with CUI?

The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense's program for verifying that contractors throughout the defense industrial base have the required cybersecurity controls in place to protect sensitive information. 

If you handle CUI under a DoD contract, your contract likely includes a CMMC Level 2 requirement. That involves implementing all 110 security controls in NIST SP 800-171, completing a self-assessment against the DoD Assessment Methodology, submitting an accurate score into the Supplier Performance Risk System (SPRS), and affirming continued compliance annually. 

Recommended reading

How to Meet CMMC Level 2 Compliance Requirements + Checklist

Read More

How CUI and CMMC affect your contract eligibility

CMMC requirements are being written directly into defense contracts. That means if you aren’t certified to the required CMMC level, you can lose your eligibility to bid on or continue performing DoD work. For many contractors, that directly impacts revenue.

CMMC has multiple levels, and the level that applies to you depends on one key question: do you handle CUI?

  • If you only handle Federal Contract Information (FCI), you're likely subject to CMMC Level 1. This requires only 15 basic security practices based on FAR 52.204-21
  • If you handle CUI, you're likely subject to CMMC Level 2, which requires all 110 security controls in NIST SP 800-171. 

That's a significant jump in scope, cost, and effort. It's exactly why knowing what counts as CUI and whether you handle it is one of the most important aspects of your compliance program and your overall business growth strategy.

Note: Proposed regulatory changes and the Revolutionary FAR Overhaul (RFO)

The regulatory landscape around CUI is actively evolving. In June 2026, the FAR Council published a proposed rule (FAR Case 2026-001) that would standardize CUI requirements across all federal agencies and contractors, not just the DoD supply chain. 

Key proposed changes include a new standardized form (SF XXX) for communicating CUI obligations in every contract, new FAR clauses (52.240-6 and 52.240-7), and a rename of Federal Contract Information to "Covered Federal Information." 

The proposed rule would not replace DFARS 252.204-7012 for DoD contractors. Comments closed July 23, 2026; final rules are expected to take effect in 2026. See CUI Compliance: DFARS, 32 CFR, and CMMC for details and the full regulatory breakdown.

Why understanding CUI matters for your business

Whether you handle CUI is the core factor everything else in your defense contracting and CMMC journey builds on. It directly affects your compliance obligations, and those obligations directly affect your contract eligibility. 

Once you know whether you handle CUI and which categories apply, you can define your CUI boundary, understand your compliance obligations, and prepare for a CMMC self-assessment with a clear picture of what you’ll need to do.

FAQs

Is PII controlled unclassified information? 

PII only becomes CUI when it's tied to a specific law or policy requiring safeguarding, like the Privacy Act covering certain federal records. General PII a company collects in the normal course of business isn't CUI on its own.

Is all government information CUI? 

No. CUI only covers unclassified information that a specific law, regulation, or government-wide policy requires safeguarding.

Is CUI the same as classified information?

No. Classified information (Confidential, Secret, Top Secret) is governed by Executive Order 13526 and requires significantly stricter handling. CUI is unclassified but still requires protection under 32 CFR Part 2002 and the CUI Registry.

If CUI is combined with non-CUI information in the same document, does the whole document become CUI? 

Per 32 CFR 2002's marking rules, authorized holders must portion-mark documents so CUI and non-CUI content is clearly distinguished, but a document containing any CUI is generally handled as a CUI document overall.

Loading...