Skip to main content

CMMC Pause: What DoW & Primes Still Require

background

What Is CUI Specified? When CUI Carries Extra Requirements

  • cui
  • What Is CUI Specified? When CUI Carries Extra Requirements

If you handle Controlled Unclassified Information (CUI) as a defense contractor, it’s important to know that not all CUI is treated the same way. Some types of CUI come with extra safeguarding requirements because a specific federal law or policy also applies. 

What is CUI Specified?

CUI Specified is CUI that requires safeguarding or dissemination controls beyond the standard baseline set out in 32 CFR Part 2002 and the CUI Registry

Every piece of CUI Specified is still CUI, and it still falls under one of the categories in the ISOO CUI Registry. The difference is that a specific federal law, regulation, or government-wide policy layers extra rules on top of the CUI Program's baseline, covering things like who can access it, how it can be shared, or what additional handling steps are required.

A common example is export-controlled technical data, which is CUI that is also governed by ITAR or EAR. In addition to CUI safeguards, this information also requires an export license before it can be shared outside the US or with foreign nationals. This requirement comes directly from export control law rather than from the CUI Program itself.

CUI Specified vs. CUI Basic

CUI Basic follows the CUI Program's standard safeguarding and dissemination rules, full stop. CUI Specified follows those same standard rules as a floor, then adds requirements from whatever law or policy makes that particular category sensitive enough to warrant extra protection.

The same 110 NIST 800-171 controls that apply to CUI Basic also apply to CUI Specified. What changes is what gets layered on top: additional access restrictions, specific marking requirements, or handling procedures defined by the source authority.

Examples of CUI Specified

Beyond export-controlled technical data, other examples of CUI Specified you may encounter as a defense contractor include:

  • Naval Nuclear Propulsion Information (NNPI). The registry lists both Basic and Specified authorities for NNPI; information controlled under 50 USC 2511 is CUI Specified and carries the CUI//SP-NNPI banner. Separately from its registry status, DoD and Navy policy impose strict handling requirements on NNPI, including NOFORN marking, access limited to U.S. persons with a demonstrated need to know, and approval from the Chief of Naval Operations before related IT systems or media leave the U.S.
  • Unclassified Controlled Nuclear Information, which spans two registry categories (Defense and Energy). Each includes a Specified authority, 32 CFR 223 for the Defense category and 10 CFR 1017 for Energy, carrying the CUI//SP-DCNI and CUI//SP-UCNI banners respectively, alongside Basic authorities.

Notice the pattern: even in categories known for strict handling, whether a given document is Basic or Specified depends on the specific authority governing it, not the category name.

Dissemination and marking requirements for CUI Specified

CUI Specified carries its own dissemination control markings on top of the standard CUI banner. Where CUI Basic typically uses the standard banner (CONTROLLED // CUI) with at most a basic dissemination control marking, CUI Specified often requires additional markings tied to the source authority, like NOFORN (Not Releasable to Foreign Nationals) for export-controlled information, or other limited dissemination controls specific to that category.

Recommended reading

CUI Marking Requirements: Banner Markings, Designation Indicators, and DoD Rules

Read More

Why this matters for your compliance program

Getting the Basic vs. Specified determination right protects you in both directions. Treating CUI Specified as if it were CUI Basic risks missing legally required protections, like export licensing or category-specific access restrictions, which can carry real legal and contractual consequences. Treating CUI Basic as if it required CUI Specified-level controls isn't a compliance risk in the same way, but it can slow your team down with restrictions that aren't actually required and create unnecessary friction for people who should have access.

As you map your CUI boundary, identify which specific subcategories from the ISOO Registry apply to your environment. That determination tells you not just whether something is CUI, but exactly which additional requirements you need to build into your cybersecurity program.

Loading...