CUI Basic
CUI Basic is a category of Controlled Unclassified Information, sensitive but unclassified information the government requires to be protected, where the underlying law, regulation, or government-wide policy identifies the information as controlled but does not spell out specific handling rules. In these cases, the standard, uniform safeguarding and dissemination requirements of the CUI Program apply by default. It is generally distinguished from CUI Specified, where the authorizing source prescribes particular controls beyond the baseline.
Per the National Archives CUI Registry, CUI Basic is the subset of Controlled Unclassified Information for which the authorizing law, regulation, or government-wide policy does not set out specific handling or dissemination controls. As a result, CUI Basic is handled according to the uniform, baseline safeguarding and dissemination controls established by the CUI Program, in contrast to CUI Specified, whose authorizing source prescribes different or more specific requirements. CUI itself is defined as information that law, regulation, or government-wide policy requires to have safeguarding or disseminating controls, excluding classified information. Practitioners should note that the CUI Program is administered under authorities overseen by the Information Security Oversight Office (ISOO) at the National Archives, that agency-specific implementations and category-level requirements may vary, and that the precise handling obligations, contractual requirements (for example under DFARS or related clauses), and technical safeguarding baselines are out of scope for this definition and must be verified against current authoritative sources.
Why it matters
The CUI Basic designation is foundational to how the government and its contractors decide which safeguarding and dissemination rules apply to sensitive but unclassified information. Because CUI Basic covers information whose authorizing law, regulation, or government-wide policy does not spell out specific handling controls, it defaults to the uniform baseline safeguarding and dissemination requirements of the CUI Program. Correctly identifying information as CUI Basic, rather than CUI Specified, which carries source-prescribed controls, determines whether an organization applies the standard baseline or a more particular set of requirements. Misclassification in either direction can lead to under-protecting sensitive data or over-controlling information in ways that impede legitimate sharing.
The stakes are especially significant in the defense and public sector context. CUI Basic can include information tied to military systems and components, defense supply chains, and procurement and acquisition activities, where compromise can directly harm national security interests. For government contractors, correctly recognizing CUI Basic in their environments is a prerequisite to applying the appropriate protections and to meeting contractual obligations that may reference the CUI Program.
Practitioners should treat the CUI Basic versus CUI Specified distinction as a starting point for analysis, not a complete answer. The category tells you which default rules apply, but the precise handling obligations, contractual requirements (for example under DFARS or related clauses), and technical safeguarding baselines are out of scope for the designation itself and must be verified against current authoritative sources. Applying the CUI Program's baseline is not the same as satisfying every applicable security or contractual requirement, and agency-specific implementations may add further expectations.
Who it's relevant to
Inside CUI Basic
Common questions
Answers to the questions practitioners most commonly ask about CUI Basic.