Skip to main content
Category: Controlled Unclassified Information

CUI Basic

Also known as: Controlled Unclassified Information Basic
Simply put

CUI Basic is a category of Controlled Unclassified Information, sensitive but unclassified information the government requires to be protected, where the underlying law, regulation, or government-wide policy identifies the information as controlled but does not spell out specific handling rules. In these cases, the standard, uniform safeguarding and dissemination requirements of the CUI Program apply by default. It is generally distinguished from CUI Specified, where the authorizing source prescribes particular controls beyond the baseline.

Formal definition

Per the National Archives CUI Registry, CUI Basic is the subset of Controlled Unclassified Information for which the authorizing law, regulation, or government-wide policy does not set out specific handling or dissemination controls. As a result, CUI Basic is handled according to the uniform, baseline safeguarding and dissemination controls established by the CUI Program, in contrast to CUI Specified, whose authorizing source prescribes different or more specific requirements. CUI itself is defined as information that law, regulation, or government-wide policy requires to have safeguarding or disseminating controls, excluding classified information. Practitioners should note that the CUI Program is administered under authorities overseen by the Information Security Oversight Office (ISOO) at the National Archives, that agency-specific implementations and category-level requirements may vary, and that the precise handling obligations, contractual requirements (for example under DFARS or related clauses), and technical safeguarding baselines are out of scope for this definition and must be verified against current authoritative sources.

Why it matters

The CUI Basic designation is foundational to how the government and its contractors decide which safeguarding and dissemination rules apply to sensitive but unclassified information. Because CUI Basic covers information whose authorizing law, regulation, or government-wide policy does not spell out specific handling controls, it defaults to the uniform baseline safeguarding and dissemination requirements of the CUI Program. Correctly identifying information as CUI Basic, rather than CUI Specified, which carries source-prescribed controls, determines whether an organization applies the standard baseline or a more particular set of requirements. Misclassification in either direction can lead to under-protecting sensitive data or over-controlling information in ways that impede legitimate sharing.

The stakes are especially significant in the defense and public sector context. CUI Basic can include information tied to military systems and components, defense supply chains, and procurement and acquisition activities, where compromise can directly harm national security interests. For government contractors, correctly recognizing CUI Basic in their environments is a prerequisite to applying the appropriate protections and to meeting contractual obligations that may reference the CUI Program.

Practitioners should treat the CUI Basic versus CUI Specified distinction as a starting point for analysis, not a complete answer. The category tells you which default rules apply, but the precise handling obligations, contractual requirements (for example under DFARS or related clauses), and technical safeguarding baselines are out of scope for the designation itself and must be verified against current authoritative sources. Applying the CUI Program's baseline is not the same as satisfying every applicable security or contractual requirement, and agency-specific implementations may add further expectations.

Who it's relevant to

Government Contractors and Defense Suppliers
Contractors handling information tied to military systems and components, defense supply chains, and procurement and acquisition need to recognize CUI Basic in their environments so they can apply the CUI Program's baseline safeguarding and dissemination controls. Because compromise of such data can directly harm national security interests, correct identification is a prerequisite to protection, though contractors should verify their specific contractual and technical obligations, which are out of scope for this designation, against current authoritative sources such as applicable DFARS or related clauses.
Compliance Officers and Information System Security Managers
These practitioners must distinguish CUI Basic from CUI Specified to determine whether default baseline controls or source-prescribed controls apply to a given data type. This affects how they scope protections and document handling decisions. They should treat the CUI Registry and agency-specific implementations as the governing references, since category-level requirements may vary.
Authorizing Officials and Auditors
Those responsible for authorizing systems or assessing compliance rely on accurate CUI categorization to evaluate whether the correct safeguarding and dissemination requirements have been applied. When reviewing environments containing CUI Basic, they should confirm that classifications trace back to an authorizing law, regulation, or government-wide policy, and that the applicable baseline controls, rather than more specific CUI Specified controls, are appropriate for the information at hand.
Agency Program Personnel
Personnel implementing the CUI Program within their agencies use the CUI Basic distinction to apply uniform baseline controls consistently. Because the program is administered under ISOO authorities at the National Archives and agency-specific implementations may differ, these staff should reconcile their internal policies with the current CUI Registry and verify any category-specific handling obligations.

Inside CUI Basic

Baseline Safeguarding Standard
CUI Basic is the subset of Controlled Unclassified Information for which the underlying law, regulation, or government-wide policy (LRGWP) establishes control requirements but does not set out specific or enhanced handling procedures beyond the uniform baseline. Handling therefore defaults to the standard safeguarding and dissemination controls prescribed by the CUI Program, generally administered by the National Archives and Records Administration (NARA) as the CUI Executive Agent.
Distinction from CUI Specified
CUI Basic is defined by contrast with CUI Specified. CUI Specified applies when the authorizing LRGWP prescribes particular controls (such as specific dissemination limits or safeguarding measures) that differ from or add to the baseline. CUI Basic covers the residual category where no such specific controls are directed, so the general CUI baseline applies.
Uniform Marking and Dissemination Controls
Information designated CUI Basic is generally subject to the standard CUI markings and dissemination controls set by the CUI Program rather than category-specific ones. Practitioners should verify current marking conventions against the applicable NARA CUI guidance, as marking requirements are governed by that program.
Relationship to Safeguarding Requirements for Nonfederal Systems
When CUI Basic resides in nonfederal information systems, protection is commonly implemented through the security requirements associated with the CUI Program (for example, the requirements many agencies map to NIST SP 800-171 for nonfederal systems). The precise applicable requirements depend on the contract, agency direction, and the governing authority, which the reader must confirm.

Common questions

Answers to the questions practitioners most commonly ask about CUI Basic.

Is CUI Basic protected at a lower level than CUI Specified because it is called 'Basic'?
No. The 'Basic' designation does not indicate a lower or optional level of protection. CUI Basic refers to CUI for which the authorizing law, regulation, or government-wide policy does not set out specific handling or dissemination controls beyond the baseline safeguarding and dissemination requirements established by the CUI Program. CUI Specified, by contrast, is CUI whose governing authority prescribes additional specific controls. Both categories require protection; the distinction concerns whether extra category-specific requirements apply, not whether the information is more or less sensitive in the abstract. Confirm the applicable requirements against the current CUI Registry and the governing authority for the specific information.
Does labeling information as CUI Basic mean it is being handled securely and that compliance obligations are met?
Not by itself. Applying a CUI Basic marking identifies information that is subject to safeguarding and dissemination requirements, but marking is not the same as implementing those protections. Compliance and security are distinct: correctly categorizing and marking information is one step, while actually applying the required safeguarding controls, limiting dissemination, and meeting any contractual or regulatory handling obligations is what provides protection. Readers should verify which specific safeguarding requirements apply to their environment and confirm them against current official sources.
How do we determine whether a given piece of information is CUI Basic rather than CUI Specified?
Determination generally begins with identifying the law, regulation, or government-wide policy that designates the information as CUI, then checking whether that authority prescribes specific handling or dissemination controls. If the authority establishes such specific controls, the information is generally treated as CUI Specified for those aspects; if it does not, the information is generally handled as CUI Basic under the program's baseline requirements. Because categorization depends on the specific governing authority, this should be confirmed against the current CUI Registry and the applicable authority rather than assumed from the information's subject matter alone.
How should CUI Basic be marked on documents and other media?
Marking generally follows the conventions established by the CUI Program's marking guidance, which typically includes a designation indicator and a banner or portion marking identifying the information as CUI. The specific format, category markings, and any limited dissemination controls can vary by authority and agency implementation, so the exact marking conventions should be confirmed against current official CUI marking guidance and any agency-specific instructions applicable to your organization. This entry does not cover the full set of marking mechanics, which readers must verify against authoritative sources.
What safeguarding controls typically apply to CUI Basic in a contractor environment?
For CUI residing in or transiting nonfederal systems, safeguarding requirements are commonly associated with the security requirements referenced by applicable federal acquisition provisions and the related NIST guidance for protecting CUI in nonfederal systems, subject to the current revision and any contract-specific tailoring. The precise controls, their applicability, and any assessment obligations depend on the terms of the specific contract and the current authoritative requirements. Because these obligations change across revisions and vary by contract, verify the exact controls and their scope against current official guidance and your contractual terms.
Who is responsible for designating information as CUI Basic within an organization?
In most implementations, the authority to designate information as CUI derives from the law, regulation, or government-wide policy that categorizes it, and the responsibility to apply that designation generally falls to the personnel or roles identified in the applicable agency's CUI program implementation. Organizational assignment of designation responsibilities can vary by agency and by contract, so specific roles and delegation should be confirmed against the governing agency's CUI policy and any contractual requirements rather than assumed to be uniform across organizations.

Common misconceptions

CUI Basic is a less sensitive or lower-value type of information that needs weaker protection.
CUI Basic refers to how control requirements are derived, not to a reduced sensitivity level. It designates CUI whose governing law, regulation, or policy does not prescribe specific handling controls, so the standard CUI baseline applies. It still requires safeguarding consistent with the CUI Program, and the level of protection should not be assumed to be discretionary.
CUI Basic and CUI Specified are agency-chosen labels applied at the handler's discretion.
Whether information is CUI Basic or CUI Specified is determined by the underlying law, regulation, or government-wide policy that authorizes the designation, not by an individual's preference. If that authority directs specific controls it is CUI Specified; otherwise the baseline treatment associated with CUI Basic applies. Confirm the governing authority for any given category against current NARA CUI Registry guidance.
Handling CUI Basic correctly means an organization is fully compliant and secure.
Applying the correct CUI category is a compliance determination, not a guarantee of security, and does not by itself satisfy contractual, assessment, or authorization obligations. Compliance with marking and safeguarding requirements should be treated as distinct from an overall security posture, and applicable requirements can change across revisions of governing guidance.

Best practices

Determine the CUI Basic versus CUI Specified status of information by tracing back to the specific law, regulation, or government-wide policy that authorizes the CUI designation, rather than assuming a default.
Consult the current NARA CUI Registry and applicable agency guidance to confirm the category, marking conventions, and any dissemination controls, since these are governed by the CUI Program and may be revised.
Apply the standard CUI baseline safeguarding and dissemination controls to CUI Basic, and document the authority relied upon for the determination.
For CUI Basic residing on nonfederal systems, verify the safeguarding requirements imposed by the applicable contract and agency direction rather than assuming a single control set applies.
Maintain separation in documentation between the compliance determination (correct categorization and marking) and the broader security controls protecting the information, and do not treat correct categorization as equivalent to full compliance or security.
Re-verify category status and applicable requirements when guidance, contracts, or governing authorities are updated, because baselines and requirements can change across revisions.