If you're a defense contractor working through CMMC compliance, you've likely come across the terms CUI Basic and CUI Specified. Most of the CUI you handle falls into the first category.
This article breaks down what CUI Basic means, how it differs from CUI Specified, and what it means for your cybersecurity program.
What is CUI Basic?
CUI Basic is the default category for Controlled Unclassified Information. It covers information that requires safeguarding or dissemination controls under the CUI Program, but doesn't carry any additional requirements beyond the standard rules set out in 32 CFR Part 2002 and the CUI Registry.
In other words, CUI Basic follows the baseline protections. No special handling instructions, and no extra legal requirements layered on top.
Most CUI you’ll encounter as a defense contractor falls into the CUI Basic category. For example, personnel records are sensitive information and require protection under the Privacy Act, but they don’t come with extra restrictions beyond what the CUI Program already requires. The same is generally true of routine procurement and acquisition materials, like contract proposals or acquisition planning documents, and general financial information tied to a federal contract.
CUI Basic vs. CUI Specified
CUI Specified is the other type of CUI. It adds additional safeguarding or dissemination requirements imposed by a specific federal law, regulation, or government-wide policy. For example, export-controlled technical data under ITAR or EAR. It's CUI, but it also comes with stricter export and access controls that go beyond the CUI Program's baseline.
If you're only handling CUI Basic, the CUI safeguarding controls in NIST SP 800-171 generally cover what’s required. If you're handling CUI Specified, you need to layer additional, source-specific requirements on top of that baseline.
Safeguarding requirements for CUI Basic
The standard CUI safeguarding requirements come from NIST SP 800-171, which includes 110 security controls organized into distinct families.

These control families include:
- Access Control: Limiting who can access CUI Basic to authorized users, and only to the systems and information they need for their role.
- Identification and Authentication: Verifying the identity of users and devices before granting access, often through multi-factor authentication.
- System and Communications Protection: Encrypting CUI Basic both at rest and in transit, and segmenting it from systems that don't need to handle it.
- Audit and Accountability: Logging and monitoring system activity so you can trace who accessed CUI Basic and when.
- Incident Response: Having a documented process for detecting, reporting, and responding to a potential compromise of CUI Basic.
CUI Basic still has to live within a properly scoped, access-controlled, encrypted environment, and your organization needs documentation (like a System Security Plan) showing how each of these controls is implemented. The full set of 110 controls applies regardless of whether the CUI you're handling is Basic or Specified. CUI Specified simply adds requirements on top of this baseline.
CUI Basic also carries dissemination controls, which are rules about who the information can be shared with and how. These typically follow the standard Limited Dissemination Controls (LDCs) set out in the CUI Registry, without any of the additional, source-specific sharing restrictions that come with CUI Specified.
On a document level, CUI Basic is typically marked with the standard CUI banner (CONTROLLED // CUI), without the additional category-specific markings that often accompany CUI Specified information. If you're handling CUI Basic, you generally won't need agency- or category-specific marking guidance beyond the standard banner and any applicable dissemination control marking.
Recommended reading
What Is CUI Specified? When CUI Carries Extra Requirements
Read MoreWhy CUI Basic vs CUI Specified matters for your compliance program
Knowing whether the CUI in your environment is Basic or Specified affects how you scope your safeguarding controls. Treating CUI Specified as if it were CUI Basic risks missing legally required protections. Treating CUI Basic as if it required CUI Specified-level controls isn't a compliance risk in the same way, but it can mean spending time and resources on restrictions that you don’t need.
As you map your CUI boundary, it's important to identify which specific subcategories from the ISOO Registry apply to your environment, since that's what determines whether you're dealing with CUI Basic, CUI Specified, or both.