Skip to main content
Category: Controlled Unclassified Information

Controlled Unclassified Information

Also known as:
Simply put

Controlled Unclassified Information (CUI) is sensitive government information that is not classified but still requires protection or restrictions on how it is shared. The requirement to safeguard or control the dissemination of this information comes from law, regulation, or governmentwide policy. The CUI Program standardizes how the executive branch handles this kind of information.

Formal definition

CUI is information that a law, regulation, or governmentwide policy requires to have safeguarding or dissemination controls, excluding information that is classified. It is sensitive information that does not meet the criteria for classification but must still be protected. The CUI Program, associated with the National Archives and Records Administration (NARA) CUI Registry, standardizes the way the executive branch handles unclassified information requiring safeguarding or dissemination controls. Within the Department of Defense, CUI handling and personnel training obligations are governed by DoD policy; readers should verify specific safeguarding requirements, categories, and training cadence against current authoritative sources such as the NARA CUI Registry and applicable DoD issuances.

Why it matters

CUI represents the vast middle ground of government information: too sensitive to release freely, but not classified. Because the requirement to protect it flows from law, regulation, or governmentwide policy rather than from a single agency's discretion, mishandling CUI can carry legal and contractual consequences even though the information is unclassified. For government contractors and agencies alike, CUI is the pivot point around which much of the modern safeguarding regime turns, and it is frequently the specific type of information that safeguarding requirements are written to protect.

A common and consequential mistake is treating CUI as informal or low-priority simply because it lacks a classification marking. The CUI Program was established precisely to end the patchwork of inconsistent, agency-invented markings (such as legacy labels like "For Official Use Only") that preceded it, replacing them with a standardized, governmentwide approach anchored to the NARA CUI Registry. Readers should not assume that a given piece of information is or is not CUI based on habit or local practice; the determination is tied to an authoritative category in the Registry and the underlying law, regulation, or policy that requires protection.

Scope also matters. CUI handling obligations differ across the executive branch, and within the Department of Defense they are governed by specific DoD policy, including safeguarding and personnel training requirements. Because categories, safeguarding expectations, and training cadence can change and can be interpreted differently across agencies, compliance officers should verify current requirements against authoritative sources such as the NARA CUI Registry and applicable DoD issuances rather than relying on general summaries.

Who it's relevant to

Government Contractors
Contractors that receive, create, or handle CUI on behalf of the government must understand what qualifies as CUI and how it must be safeguarded and marked. Because the obligation to protect CUI stems from law, regulation, or governmentwide policy, contractors should confirm applicable categories against the NARA CUI Registry and verify contract-specific safeguarding requirements against current authoritative sources rather than assuming unclassified means unrestricted.
DoD Personnel and Security Managers
DoD personnel who handle CUI are subject to CUI handling and training obligations governed by DoD policy. Security managers should ensure that personnel complete required initial training, the CDSE CUI course is identified as the official DoD training for this purpose, and satisfy refresher training obligations on the cadence prescribed by current DoD issuances, which should be verified directly against the governing policy.
Compliance Officers and Auditors
Those responsible for verifying compliance need to confirm that CUI is being correctly identified, marked, and protected in line with the standardized CUI Program. Auditors should anchor their reviews to authoritative sources such as the NARA CUI Registry and applicable agency or DoD issuances, and should treat locally invented or legacy markings as red flags warranting closer review.
Federal Agency Program Managers
Program managers across the executive branch are responsible for applying the standardized CUI approach to unclassified information that requires safeguarding or dissemination controls. Because interpretations and requirements can differ by agency and evolve over time, program managers should periodically reconcile their practices with the current CUI Registry and their agency's implementing policy.

Inside CUI

Executive Order and Governing Authority
CUI is a category of unclassified information established by Executive Order 13556 and implemented governmentwide through 32 CFR Part 2002, with the National Archives and Records Administration (NARA) Information Security Oversight Office (ISOO) serving as the Executive Agent that maintains the CUI Registry. The DoD implements CUI internally through DoD Instruction 5200.48. Readers should verify the current text of each authority against official sources.
CUI Registry and Categories
The CUI Registry, maintained by NARA/ISOO, is the authoritative catalog of approved CUI categories and their associated markings, and it identifies the law, regulation, or governmentwide policy (LRGWP) that authorizes protection of each category. Categories are generally divided into CUI Basic and CUI Specified.
CUI Basic vs. CUI Specified
CUI Basic is protected under the baseline safeguarding and dissemination controls of the governing framework. CUI Specified applies when the authorizing law, regulation, or governmentwide policy imposes specific handling requirements beyond the baseline. The distinction determines which additional controls apply, so practitioners should confirm the category in the CUI Registry.
Marking Requirements
CUI generally requires markings that identify the information as CUI, including a designation indicator and, where applicable, category markings and limited dissemination controls. Marking conventions are drawn from the CUI Registry and DoD-specific guidance; specifics may vary by category and should be verified against current authoritative marking guidance.
Safeguarding Controls for Nonfederal Systems
When CUI resides in or transits nonfederal information systems, protection is commonly implemented using the security requirements in NIST SP 800-171, as invoked through mechanisms such as DFARS clause 252.204-7012 for defense contractors. NIST SP 800-171 is issued by NIST and is distinct from NIST SP 800-53, which generally applies to federal information systems. Applicable revisions and contractual specifics should be confirmed.
Scope Relationship to Classified Information
CUI is unclassified information that requires safeguarding or dissemination controls; it is not classified national security information. Classified information is governed separately, and for classified systems the NISPOM and related authorities apply rather than the CUI program.

Common questions

Answers to the questions practitioners most commonly ask about CUI.

Is CUI just a new name for classified information at a lower level?
No. CUI is unclassified information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy, but it is not classified national security information. Classified information (Confidential, Secret, Top Secret) is governed by a separate authority structure, including Executive Order 13526 and, for contractors handling classified material, the NISPOM. CUI does not carry a classification level, and marking, safeguarding, and decontrol procedures for CUI differ from those for classified information. Treating CUI as 'low-level classified' is a common error; the two categories rest on different legal bases and handling regimes. Readers should confirm specific handling requirements against the National Archives CUI Registry and applicable agency policy.
If our organization is FedRAMP authorized, does that mean we automatically meet the requirements for protecting CUI in DoD contracts?
Not necessarily. FedRAMP authorization addresses the security of cloud service offerings used by federal agencies and is administered by the FedRAMP program, but it does not by itself satisfy the contractual requirements for protecting CUI on covered defense contracts. Protection of CUI in the defense context is generally driven by requirements such as DFARS clause 252.204-7012 and the security requirements in NIST SP 800-171, with the DoD CMMC program adding assessment and certification expectations that continue to evolve through its phased rollout and revisions. FedRAMP authorization may support certain cloud-related requirements, but organizations should verify the specific clauses in their contracts and confirm current DoD guidance rather than assuming automatic equivalence.
How do we know whether a given piece of information is CUI?
Designation authority rests with the U.S. Government, not with the contractor. Whether information qualifies as CUI is determined by reference to the categories in the National Archives CUI Registry, which ties each category to an underlying law, regulation, or government-wide policy. In practice, the government designating agency identifies and marks CUI, often reflected in contract documents such as the DoD's Security Classification Guide, the SF 312 context does not apply here, or contract-specific marking instructions. If information appears to meet a CUI category but is unmarked, organizations should generally seek clarification from the contracting agency rather than making an independent determination. Verify specifics against the CUI Registry and applicable agency policy.
What markings are required on CUI documents?
CUI marking practices are governed government-wide by the National Archives as the CUI Executive Agent, and within the DoD by DoDI 5200.48. Markings generally include a CUI banner or designation indicator and may include category markings and limited-dissemination controls where applicable. Marking conventions can vary by category and by agency tailoring, and legacy markings such as 'FOUO' were intended to be phased out in favor of CUI markings. This entry does not substitute for the detailed marking rules; organizations should consult the current CUI Registry marking guidance and DoDI 5200.48 for authoritative and up-to-date marking requirements.
How often must DoD personnel who handle CUI complete refresher training?
Under DoDI 5200.48, DoD personnel who handle CUI are generally required to complete refresher training on an annual basis, in addition to initial training. Requirements for contractor personnel may be established through contract terms and applicable agency policy. Because training requirements can be affected by agency-specific implementation and future policy revisions, organizations should confirm the current cadence and content requirements against DoDI 5200.48 and any contract-specific direction.
What baseline security requirements typically apply to CUI stored or processed on a contractor's own information systems?
For CUI residing in nonfederal systems and organizations, the security requirements in NIST SP 800-171 are commonly the applicable baseline, and for covered defense contracts they are frequently invoked through DFARS clause 252.204-7012. The DoD CMMC program adds assessment and certification expectations that are being introduced through a phased rollout and remain subject to revision. Requirements can differ based on the contracting agency, the specific CUI categories involved, and whether a cloud service is used. This entry does not address implementation details or contract-specific obligations; organizations should verify the applicable revision of NIST SP 800-171, current DFARS clauses, and current CMMC guidance against official sources.

Common misconceptions

CUI is a level of classification, similar to Confidential or Secret.
CUI is unclassified information that requires safeguarding or dissemination controls under law, regulation, or governmentwide policy. It is not a classification level, and it is governed by the CUI program (EO 13556, 32 CFR Part 2002, and DoDI 5200.48 within DoD) rather than by classified information authorities such as the NISPOM.
Any sensitive-looking information can be labeled CUI at an individual's discretion.
Only information falling within a category listed in the NARA/ISOO CUI Registry and authorized by an underlying law, regulation, or governmentwide policy qualifies as CUI. Designation must be tied to an authorizing basis rather than personal judgment, and CUI Specified categories carry additional handling requirements defined by that authority.
Meeting NIST SP 800-171 requirements for CUI means an organization has satisfied all its cybersecurity obligations.
Safeguarding CUI under NIST SP 800-171 addresses one set of requirements and does not by itself equate to overall security or satisfy separate obligations such as those under FISMA, FedRAMP, or DoD RMF authorization. Compliance and security are not the same, and applicable revisions and contractual terms should be verified.

Best practices

Consult the NARA/ISOO CUI Registry to confirm whether specific information is an approved CUI category and whether it is CUI Basic or CUI Specified before designating or marking it.
Apply markings consistent with the CUI Registry and current DoD guidance, including designation indicators and any applicable category or limited dissemination control markings, and verify marking conventions against authoritative sources.
For CUI in nonfederal systems, implement safeguarding requirements from the applicable revision of NIST SP 800-171 as invoked by contract (for example through DFARS clause 252.204-7012), and confirm the specific contractual and revision requirements.
Provide annual CUI refresher training to DoD personnel who handle CUI, consistent with DoDI 5200.48, and document training completion.
Distinguish CUI handling obligations from classified information requirements, and route classified information through the appropriate NISPOM and classified system authorities rather than the CUI program.
Verify all category determinations, markings, control baselines, and contractual clauses against the current official authorities, since CUI categories, marking guidance, and referenced control revisions can change over time.