32 CFR Part 2002
32 CFR Part 2002 is the federal regulation that created the government-wide program for handling Controlled Unclassified Information (CUI), sensitive information that is not classified but still needs protection. It sets the rules that executive branch agencies follow when they identify, label, safeguard, and share this kind of information. It was issued to bring consistency to how agencies treat sensitive-but-unclassified data.
32 CFR Part 2002, titled "Controlled Unclassified Information," is the codified rule issued by the Information Security Oversight Office (ISOO) that describes the executive branch's CUI Program and establishes policy for designating, safeguarding, disseminating, marking, decontrolling, and disposing of CUI, as well as related self-inspection and oversight responsibilities. Per the evidence, the term "CUI" is defined in § 2002.4 (Definitions), while safeguarding-related requirements are addressed in other sections such as § 2002.14; practitioners should not conflate the definitions section with the safeguarding provisions. The rule applies to executive branch agencies as defined therein and governs information the government (or an entity acting for or on behalf of the government) creates or possesses when a law, regulation, or government-wide policy requires or permits safeguarding or dissemination controls. This entry addresses the scope and purpose of the rule and does not cover the specific technical safeguarding controls (which are generally addressed through separate NIST guidance and contractual mechanisms) or agency-specific tailoring; readers should verify the current text at the authoritative sources cited.
Why it matters
Before 32 CFR Part 2002, executive branch agencies handled sensitive-but-unclassified information under a patchwork of inconsistent, agency-specific markings and safeguarding practices, labels and handling caveats that varied widely from one department to another. This inconsistency made it difficult to share information reliably across the government and to hold contractors and agencies to a common standard. The rule, issued by the Information Security Oversight Office (ISOO), established a single government-wide CUI Program to bring uniformity to how such information is designated, safeguarded, disseminated, marked, decontrolled, and disposed of.
For compliance officers, ISSMs, and government contractors, the rule is foundational because it defines the regulatory basis of the CUI category itself. Many downstream obligations, including contractual safeguarding requirements and separate NIST guidance for protecting CUI, trace back to the program this rule created. Understanding the rule's scope helps practitioners avoid a common error: treating CUI as though it were classified information, or conversely, assuming that because information is unclassified it carries no protection obligations at all.
A further point of caution is that 32 CFR Part 2002 sets policy for the program and defines terms, but it does not itself prescribe the specific technical safeguarding controls an organization must implement. Those are generally addressed through separate NIST guidance and contractual mechanisms. Readers should not assume that reading this rule alone tells them how to configure their systems; the rule establishes the framework, while implementation details live elsewhere and are subject to agency tailoring.
Who it's relevant to
Inside 32 CFR Part 2002
Common questions
Answers to the questions practitioners most commonly ask about 32 CFR Part 2002.