Skip to main content
Category: Laws & Executive Orders

32 CFR Part 2002

Also known as: 32 CFR Part 2002 (Controlled Unclassified Information), CUI Program Rule
Simply put

32 CFR Part 2002 is the federal regulation that created the government-wide program for handling Controlled Unclassified Information (CUI), sensitive information that is not classified but still needs protection. It sets the rules that executive branch agencies follow when they identify, label, safeguard, and share this kind of information. It was issued to bring consistency to how agencies treat sensitive-but-unclassified data.

Formal definition

32 CFR Part 2002, titled "Controlled Unclassified Information," is the codified rule issued by the Information Security Oversight Office (ISOO) that describes the executive branch's CUI Program and establishes policy for designating, safeguarding, disseminating, marking, decontrolling, and disposing of CUI, as well as related self-inspection and oversight responsibilities. Per the evidence, the term "CUI" is defined in § 2002.4 (Definitions), while safeguarding-related requirements are addressed in other sections such as § 2002.14; practitioners should not conflate the definitions section with the safeguarding provisions. The rule applies to executive branch agencies as defined therein and governs information the government (or an entity acting for or on behalf of the government) creates or possesses when a law, regulation, or government-wide policy requires or permits safeguarding or dissemination controls. This entry addresses the scope and purpose of the rule and does not cover the specific technical safeguarding controls (which are generally addressed through separate NIST guidance and contractual mechanisms) or agency-specific tailoring; readers should verify the current text at the authoritative sources cited.

Why it matters

Before 32 CFR Part 2002, executive branch agencies handled sensitive-but-unclassified information under a patchwork of inconsistent, agency-specific markings and safeguarding practices, labels and handling caveats that varied widely from one department to another. This inconsistency made it difficult to share information reliably across the government and to hold contractors and agencies to a common standard. The rule, issued by the Information Security Oversight Office (ISOO), established a single government-wide CUI Program to bring uniformity to how such information is designated, safeguarded, disseminated, marked, decontrolled, and disposed of.

For compliance officers, ISSMs, and government contractors, the rule is foundational because it defines the regulatory basis of the CUI category itself. Many downstream obligations, including contractual safeguarding requirements and separate NIST guidance for protecting CUI, trace back to the program this rule created. Understanding the rule's scope helps practitioners avoid a common error: treating CUI as though it were classified information, or conversely, assuming that because information is unclassified it carries no protection obligations at all.

A further point of caution is that 32 CFR Part 2002 sets policy for the program and defines terms, but it does not itself prescribe the specific technical safeguarding controls an organization must implement. Those are generally addressed through separate NIST guidance and contractual mechanisms. Readers should not assume that reading this rule alone tells them how to configure their systems; the rule establishes the framework, while implementation details live elsewhere and are subject to agency tailoring.

Who it's relevant to

Compliance officers and program managers
Those responsible for agency or contractor compliance rely on this rule as the regulatory foundation of the CUI Program. It helps them understand what qualifies as CUI, the government-wide policy for handling it, and where their organization's obligations originate, though they must confirm specific safeguarding controls and agency tailoring against current authoritative sources.
Information system security managers (ISSMs)
ISSMs should understand that this rule establishes the program and defines CUI but does not itself prescribe the technical safeguarding controls. Those are generally addressed through separate NIST guidance and contractual mechanisms, so ISSMs need to map program-level policy to the applicable implementation requirements.
Government contractors and entities acting on behalf of the government
Contractors that create or possess information for or on behalf of the government may handle CUI and become subject to associated obligations. This rule clarifies the scope of what CUI is and why protection is required, though the specific contractual and technical requirements are established through separate mechanisms that contractors must verify.
Auditors and oversight personnel
Because the rule addresses self-inspection and oversight responsibilities, auditors use it to assess whether agencies and their partners are correctly designating, marking, safeguarding, and disposing of CUI in accordance with the government-wide program, keeping in mind that agency-specific policies may add interpretation.

Inside 32 CFR Part 2002

Scope and Applicability of the CUI Program
32 CFR Part 2002 establishes a uniform, executive branch-wide program for managing Controlled Unclassified Information (CUI). It implements Executive Order 13556 and applies to executive branch agencies that designate or handle CUI. Note that application to non-executive-branch entities, such as contractors, generally flows through contractual or agreement mechanisms rather than the rule directly; readers should confirm specific applicability against the current regulatory text.
Definitions (§ 2002.4)
The rule's definitions section, § 2002.4, sets out the key terms used throughout Part 2002, including the definition of Controlled Unclassified Information (CUI). Practitioners should anchor terminology to this section rather than assuming colloquial or agency-specific meanings, and verify the current text for precise wording.
Roles and Responsibilities
Part 2002 assigns responsibilities across the CUI program, including the role of the Executive Agent for the CUI Program. The National Archives and Records Administration (NARA), through the Information Security Oversight Office (ISOO), serves as the CUI Executive Agent responsible for oversight and implementation guidance. Agency-level responsibilities for designating and managing CUI are also addressed.
CUI Categories and the CUI Registry
The rule ties CUI designations to categories authorized by law, regulation, or government-wide policy, rather than allowing ad hoc agency markings. These authorized categories are published in the CUI Registry maintained by the Executive Agent. Consult the current Registry to confirm which categories and associated handling requirements apply.
Marking Requirements
Part 2002 addresses how CUI is to be marked so recipients can identify it and apply appropriate handling. Specific marking conventions are further detailed in Executive Agent guidance; verify current marking standards against official sources, as implementation detail may reside outside the rule text itself.
Safeguarding Requirements (§ 2002.14)
Section 2002.14 addresses safeguarding of CUI, covering how CUI is to be protected in various environments. For CUI residing on or transiting information systems, safeguarding generally references applicable NIST guidance; readers should confirm the precise standards and any agency tailoring, and should not conflate the safeguarding section with the definitions section.
Dissemination, Sharing, and Decontrol
The rule addresses controls on disseminating CUI, the principle of information sharing consistent with authorized limitations, and provisions for decontrol when protection is no longer required. Specific decontrol triggers and procedures should be verified against the current regulatory and Registry text.

Common questions

Answers to the questions practitioners most commonly ask about 32 CFR Part 2002.

Does 32 CFR Part 2002 apply directly to government contractors and impose requirements on their systems?
32 CFR Part 2002 is a regulation issued by the National Archives and Records Administration (NARA), which serves as the CUI Executive Agent, and it establishes the governmentwide CUI Program that applies in the first instance to executive branch agencies. It generally does not, by itself, impose obligations directly on contractors; contractor obligations typically flow through agency agreements, contract clauses, and other authorities that incorporate CUI requirements. Readers should verify the specific contractual and regulatory mechanisms that apply to their situation against current official sources, because the pathway from Part 2002 to a contractor's actual obligations depends on the contracting agency and applicable clauses.
Is 32 CFR Part 2002 the same thing as the security control requirements for protecting CUI?
No. Part 2002 establishes the policy framework for the CUI Program, including how information is designated, marked, safeguarded, and disseminated, but it is distinct from the technical control catalogs and specifications used to protect CUI on information systems. Frameworks such as NIST SP 800-171 (maintained by NIST) are commonly referenced for protecting CUI in nonfederal systems, and these are separate publications from Part 2002. Confirm which specific standards apply in your context, as the relationship among the CUI regulation, agency policy, and control requirements varies by system category and applicable authority.
Where in 32 CFR Part 2002 is 'Controlled Unclassified Information' defined?
The definitions section of the part addresses key terms, including CUI. Readers should consult the definitions provision of the regulation and the current authoritative text on eCFR to confirm the exact wording, because definitions and section organization can be updated. Note that the safeguarding requirements are addressed in a separate section of the part from the definitions.
How should an agency determine what information qualifies as CUI under Part 2002?
Under the CUI Program framework, whether information is CUI generally depends on whether a law, regulation, or governmentwide policy requires or permits it to be safeguarded or subject to dissemination controls. The CUI Registry, maintained by NARA as the CUI Executive Agent, identifies approved categories. Agencies should map their information against the Registry and the underlying authorities rather than making ad hoc determinations, and should verify current Registry entries because categories may be revised.
What safeguarding expectations does the part set for handling CUI?
The part addresses safeguarding of CUI in a dedicated section, generally establishing baseline expectations for protecting CUI throughout its lifecycle. Because the specific safeguarding provisions can be tailored by agency policy and supplemented by separate control standards, implementers should read the safeguarding section together with their agency's CUI policy and any applicable control requirements, and confirm the current text against official sources. This entry does not cover the detailed technical implementation of those safeguards.
How does Part 2002 address marking of CUI?
The part addresses marking as part of the CUI Program so that recipients can identify information subject to controls and understand applicable handling. Marking practices are typically supplemented by CUI Executive Agent guidance and agency-specific implementation. Because marking conventions and supplemental guidance can be updated, readers should verify current marking requirements against the authoritative text and applicable agency policy.
How does Part 2002 relate to an agency's existing information security and records management programs?
Part 2002 establishes a governmentwide, standardized approach intended to replace inconsistent agency-specific control markings and practices, and it operates alongside other information security and records management obligations rather than replacing them. Agencies generally need to integrate CUI Program requirements with their broader compliance obligations, and the precise interaction depends on the authorities governing each system. Confirm how these programs intersect in your environment against current official guidance.

Common misconceptions

The definition of CUI is found in § 2002.14.
The definition of CUI is located in the definitions section, § 2002.4. Section 2002.14 addresses safeguarding requirements for CUI, not definitions. Practitioners citing the rule should reference the correct section for each purpose.
32 CFR Part 2002 and the DoD's CUI/DFARS safeguarding requirements are the same thing.
Part 2002 is the executive branch-wide CUI program rule issued under Executive Order 13556 with NARA/ISOO as Executive Agent. DoD contractual safeguarding obligations, such as those imposed through DFARS clause 252.204-7012 and related NIST SP 800-171 requirements, are distinct mechanisms. Compliance with one does not automatically satisfy the other; verify each against its own governing source.
An agency can create its own CUI categories at will.
Under Part 2002, CUI designations must be grounded in an authorizing law, regulation, or government-wide policy, and authorized categories are reflected in the CUI Registry maintained by the Executive Agent. Ad hoc or legacy markings outside this structure are generally not permitted; confirm categories against the current Registry.

Best practices

Cite Part 2002 by the correct section for each purpose: use § 2002.4 for definitions and § 2002.14 for safeguarding requirements, and verify the current text on eCFR before relying on any provision.
Base CUI designations only on categories authorized by law, regulation, or government-wide policy, and check the current CUI Registry maintained by the Executive Agent (NARA/ISOO) rather than relying on informal or legacy markings.
Treat DoD contractual safeguarding obligations (for example under DFARS 252.204-7012 and NIST SP 800-171) as separate from Part 2002, and confirm each requirement against its own governing authority instead of assuming one satisfies the other.
Coordinate with your agency's designated CUI officials to confirm marking, safeguarding, dissemination, and decontrol procedures, since implementation detail is often carried in Executive Agent guidance beyond the rule text.
Apply information-sharing decisions consistent with the authorized dissemination limitations and decontrol provisions, verifying current triggers before releasing or removing controls on CUI.
Periodically re-verify all category, marking, and safeguarding references against the current regulatory text and Registry, since guidance and authorized categories can change over time.