CUI Registry
The CUI Registry is the government-wide online repository that lists the official categories of Controlled Unclassified Information (CUI) and provides the federal-level guidance, policy, and handling requirements for that information. It is maintained by the National Archives and Records Administration (NARA), which serves as the CUI Executive Agent. Anyone trying to understand what qualifies as CUI and how it must be handled generally starts with this resource.
The CUI Registry is the authoritative, publicly accessible online repository maintained by NARA as the CUI Executive Agent, consolidating federal-level guidance, policy, and requirements for identifying, categorizing, marking, and handling Controlled Unclassified Information. It enumerates approved CUI categories and subcategories and, for CUI Specified, indicates the underlying laws, regulations, and government-wide policies that impose specific handling controls (distinguishing CUI Specified from CUI Basic). The Registry defines what information falls within the CUI program but does not by itself specify implementation-level security controls for information systems; practitioners should confirm applicable safeguarding requirements against the current authoritative text and any agency-specific tailoring, and verify the Registry's category listings, which are periodically updated.
Why it matters
The CUI Registry addresses a foundational problem in information handling: before the CUI program, agencies used dozens of inconsistent, ad hoc markings and handling regimes for sensitive-but-unclassified information, which created confusion about what needed protection and how. The Registry establishes a single government-wide reference point, maintained by NARA as the CUI Executive Agent, that enumerates the official categories and subcategories of CUI and consolidates the federal-level guidance and policy governing that information. For compliance officers, contractors, and system security personnel, it is generally the starting point for determining whether information they hold qualifies as CUI at all.
The Registry also matters because it distinguishes CUI Basic from CUI Specified. For CUI Specified, the Registry indicates which underlying laws, regulations, and government-wide policies impose specific handling controls, meaning that safeguarding obligations can vary by category rather than following a single uniform standard. Misreading this distinction can lead an organization to under-protect information that carries statutory handling requirements, or to apply the wrong controls entirely.
A critical caveat that experts insist on: the Registry defines and categorizes CUI, but it does not by itself specify the implementation-level security controls for information systems. Identifying information as CUI in the Registry is a categorization step, not a compliance solution. Practitioners must map any applicable safeguarding requirements (for example, those flowing from NIST guidance or contractual clauses) against the current authoritative text and any agency-specific tailoring, and should verify the Registry's category listings, which are periodically updated.
Who it's relevant to
Inside CUI Registry
Common questions
Answers to the questions practitioners most commonly ask about CUI Registry.