Skip to main content
Category: Governance Roles

CUI Executive Agent

Also known as: CUI EA, Controlled Unclassified Information Executive Agent
Simply put

The CUI Executive Agent is the federal authority responsible for running the government-wide program that manages Controlled Unclassified Information (CUI) across the executive branch. This role is carried out by the National Archives and Records Administration (NARA), through its Information Security Oversight Office (ISOO), which issues guidance, oversees agency compliance, and maintains the national CUI Registry. In practice, it sets the rules for how federal agencies identify, mark, and safeguard sensitive but unclassified information.

Formal definition

The CUI Executive Agent is the National Archives and Records Administration (NARA), which implements the executive branch-wide CUI Program and oversees federal agency actions related to Controlled Unclassified Information. NARA generally exercises this function through the Information Security Oversight Office (ISOO), which issues guidance to federal agencies on the safeguarding and marking of CUI and maintains the national CUI Registry (located at archives.gov/cui). The CUI EA also works with agencies to align pre-existing authorities within the CUI framework, including transitioning certain authorities between CUI categories (for example, from Specified to Basic). Note that this entry addresses the CUI EA's oversight and program-management role and does not cover agency-specific tailoring, contractual flow-down requirements (such as those imposed on defense contractors), or the technical control requirements referenced in related NIST publications, which readers should verify against current authoritative sources.

Why it matters

The CUI Executive Agent provides the single, government-wide authority that keeps the handling of Controlled Unclassified Information consistent across the executive branch. Before a centralized program existed, individual agencies applied a patchwork of ad hoc markings and safeguarding practices to sensitive but unclassified information, which created confusion over what protection any given document actually required. By vesting this function in the National Archives and Records Administration (NARA), through its Information Security Oversight Office (ISOO), the executive branch established a common set of rules for identifying, marking, and safeguarding CUI, along with a single authoritative reference point in the national CUI Registry.

For compliance officers, ISSMs, and contractors, understanding who the CUI EA is matters because it determines where authoritative guidance and the definitive category list originate. When questions arise about what qualifies as CUI, how a category should be marked, or how a pre-existing authority maps into the CUI framework, the CUI EA's guidance and the CUI Registry are the primary points of reference. The CUI EA also actively works with agencies to align pre-existing authorities within the framework, including transitioning certain authorities between CUI categories (for example, from Specified to Basic), which means the applicable categorization for a given type of information can evolve over time and should be verified against current registry entries.

A common mistake is to treat the CUI EA's oversight role as if it directly imposes contractual or technical obligations on a specific organization. It does not. The CUI EA sets the government-wide program rules and maintains the registry, but agency-specific tailoring, contractual flow-down requirements imposed on contractors, and the technical control requirements referenced in related NIST publications are separate matters that readers must confirm against current authoritative sources.

Who it's relevant to

Compliance Officers and Program Managers
Those responsible for organizational CUI programs rely on the CUI EA's guidance and the national CUI Registry to determine what information qualifies as CUI and how it should be categorized and marked. Because the CUI EA may transition authorities between categories such as Specified and Basic, compliance staff should periodically verify current registry entries rather than assume a category assignment is static.
Information System Security Managers (ISSMs)
ISSMs use the CUI EA's marking and safeguarding guidance as the government-wide baseline for handling CUI within their systems. This entry addresses the CUI EA's oversight and program-management role; the specific technical control requirements referenced in related NIST publications are separate and should be verified against current authoritative sources.
Government Contractors
Contractors handling CUI should understand that the CUI EA sets the executive branch-wide program rules and maintains the registry, but that agency-specific tailoring and contractual flow-down requirements are distinct obligations. The CUI EA's role does not by itself define a contractor's contractual duties, which must be confirmed against the applicable contract and current authoritative sources.
Auditors and Oversight Personnel
Auditors reviewing CUI handling can trace authoritative requirements back to ISOO guidance and the national CUI Registry as the government-wide reference points. Because guidance and category assignments can evolve, auditors should confirm that the version of guidance being applied reflects the current authoritative text.

Inside CUI EA

Designated CUI Executive Agent
The National Archives and Records Administration (NARA) serves as the CUI Executive Agent under Executive Order 13556, responsible for overseeing and implementing the governmentwide CUI Program across executive branch agencies. Readers should verify the current authority and any delegations against official NARA and Information Security Oversight Office (ISOO) sources.
Information Security Oversight Office (ISOO)
ISOO, operating within NARA, generally carries out the CUI Executive Agent functions on a day-to-day basis, including issuing policy guidance and maintaining program oversight. The precise division of responsibilities may evolve, so confirm against current issuances.
CUI Registry
The CUI Executive Agent maintains the online CUI Registry, which identifies approved categories of Controlled Unclassified Information, associated markings, and the authorities that permit safeguarding or dissemination controls. The Registry is the authoritative reference for what qualifies as CUI, though agency-specific handling procedures may add detail.
Governmentwide Policy Development
The Executive Agent role includes developing and issuing uniform policy for designating, marking, safeguarding, disseminating, decontrolling, and disposing of CUI, intended to replace the prior patchwork of agency-specific control markings. Implementation timelines and agency tailoring vary.
Oversight and Compliance Monitoring
As Executive Agent, NARA generally monitors executive branch agency implementation of the CUI Program and may report on compliance. This oversight role is distinct from any individual agency's internal control assessments or authorization decisions.
Relationship to Implementing Regulations
The CUI Executive Agent's policies are operationalized through the CUI federal regulation (32 CFR Part 2002) and, for the protection of CUI in nonfederal systems, through NIST SP 800-171. The Executive Agent role should not be conflated with the bodies that maintain those technical control sets (NIST) or with contractual mechanisms such as DFARS clauses (DoD).

Common questions

Answers to the questions practitioners most commonly ask about CUI EA.

Is the CUI Executive Agent the same body that issues the security controls agencies must apply to CUI?
No. The CUI Executive Agent (the National Archives and Records Administration, acting through its Information Security Oversight Office) oversees and implements the government-wide CUI Program and maintains the CUI Registry, but it does not author the technical control catalogs. Security control frameworks such as NIST SP 800-53 and the safeguarding requirements referenced for CUI in non-federal systems (commonly associated with NIST SP 800-171) are developed and maintained by NIST, a separate body. The Executive Agent's role is program oversight, policy, and registry management rather than issuing the control baselines themselves. Readers should verify current allocation of responsibilities against the governing executive order and implementing regulation.
Does the CUI Executive Agent decide what information each agency treats as CUI?
Not on an item-by-item basis. The Executive Agent establishes the government-wide framework and maintains the CUI Registry of approved categories, but the authority to designate specific information as CUI generally rests with the originating agency and its designating officials, consistent with the laws, regulations, or government-wide policies that authorize the category. The Executive Agent provides oversight and consistency across the executive branch rather than making individual designation decisions. Agency-specific interpretations may exist, so confirm designation practices against your agency's implementing policy.
Where should I look to confirm that a category or marking I am using is a recognized CUI category?
The CUI Registry maintained by the Executive Agent is the authoritative reference for approved CUI categories and associated markings. Because categories and their handling requirements can be updated, treat the online Registry as the current source rather than relying on cached or printed copies, and confirm the applicable version at the time of use.
How does the Executive Agent's oversight role affect a contractor handling CUI under a federal contract?
The Executive Agent sets the government-wide CUI framework, but a contractor's specific obligations generally flow from the contract terms and the applicable regulations incorporated into that contract, which may reference safeguarding and marking requirements. The Executive Agent does not typically administer individual contracts. Contractors should confirm their handling, marking, and safeguarding duties against the contract language and the responsible contracting agency's guidance, and note that defense contract requirements may differ from those of civilian agencies.
If we already follow FISMA and NIST SP 800-53 for our systems, do we automatically satisfy CUI Program requirements?
Not necessarily. Implementing FISMA-driven controls addresses information system security obligations, but the CUI Program also involves designation, marking, dissemination controls, decontrol, and consistent handling practices established under the Executive Agent's framework. Compliance with a security control baseline is not the same as compliance with CUI Program policy. Confirm both the applicable safeguarding requirements and the CUI handling requirements against current authoritative sources.
Does an agency need its own internal policy if the Executive Agent already runs a government-wide program?
In most implementations, yes. The Executive Agent provides government-wide oversight and the framework, but individual agencies generally are expected to issue implementing policy that operationalizes CUI handling within their own environments, including training, designation procedures, and marking practices consistent with the Registry. Because agency-specific interpretations vary, verify your organization's implementing policy and its alignment with the governing regulation.

Common misconceptions

The CUI Executive Agent (NARA) writes the security controls that contractors must implement to protect CUI.
NARA as CUI Executive Agent sets governmentwide CUI policy and maintains the CUI Registry, but the technical security requirements for protecting CUI in nonfederal information systems are generally drawn from NIST SP 800-171, which is issued and maintained by NIST. These are distinct authorities and should not be treated as interchangeable.
Because NARA is the CUI Executive Agent, its policies govern all CUI across federal, defense, and classified environments identically.
The CUI Program addresses unclassified information requiring safeguarding or dissemination controls. Classified national security information is governed by separate authorities (for example, the NISPOM for contractors), and DoD applies additional contractual and RMF-based requirements. Agency-specific interpretations and category-specific handling requirements may also apply, so scope boundaries must be confirmed.
Appearing on or complying with the CUI Registry categories is equivalent to being compliant or authorized to handle CUI.
The CUI Registry identifies what constitutes CUI and its markings; it does not by itself confer compliance or authorization. Safeguarding obligations must still be implemented per the applicable regulation, contract terms, and technical requirements, and compliance with markings should not be equated with achieving adequate security.

Best practices

Treat the CUI Registry maintained by the CUI Executive Agent as the authoritative source for identifying CUI categories and approved markings, and verify categories against the current online version rather than relying on legacy or agency-specific labels.
Clearly distinguish the CUI Executive Agent's policy role (NARA/ISOO) from the technical control sources (NIST SP 800-171), the implementing regulation (32 CFR Part 2002), and any DoD contractual mechanisms, so responsibilities are correctly attributed in your compliance documentation.
Confirm which specific handling, marking, and safeguarding requirements apply to your environment, since agency-specific and category-specific interpretations may add obligations beyond the baseline CUI policy.
Do not assume CUI marking compliance equates to adequate security; pair correct designation and marking with implementation of the applicable safeguarding requirements and independent verification.
Monitor for revisions to CUI policy, the CUI Registry, and referenced NIST publications, and cross-check any effective dates, category names, or citations against current official NARA, ISOO, and NIST sources before relying on them.
Coordinate with contracting and legal stakeholders to reconcile CUI Program policy obligations with contract-specific and defense-specific requirements, rather than assuming one framework automatically satisfies another.