Skip to main content
Category: Controlled Unclassified Information

CUI Registry

Also known as: Controlled Unclassified Information Registry
Simply put

The CUI Registry is the government-wide online repository that lists the official categories of Controlled Unclassified Information (CUI) and provides the federal-level guidance, policy, and handling requirements for that information. It is maintained by the National Archives and Records Administration (NARA), which serves as the CUI Executive Agent. Anyone trying to understand what qualifies as CUI and how it must be handled generally starts with this resource.

Formal definition

The CUI Registry is the authoritative, publicly accessible online repository maintained by NARA as the CUI Executive Agent, consolidating federal-level guidance, policy, and requirements for identifying, categorizing, marking, and handling Controlled Unclassified Information. It enumerates approved CUI categories and subcategories and, for CUI Specified, indicates the underlying laws, regulations, and government-wide policies that impose specific handling controls (distinguishing CUI Specified from CUI Basic). The Registry defines what information falls within the CUI program but does not by itself specify implementation-level security controls for information systems; practitioners should confirm applicable safeguarding requirements against the current authoritative text and any agency-specific tailoring, and verify the Registry's category listings, which are periodically updated.

Why it matters

The CUI Registry addresses a foundational problem in information handling: before the CUI program, agencies used dozens of inconsistent, ad hoc markings and handling regimes for sensitive-but-unclassified information, which created confusion about what needed protection and how. The Registry establishes a single government-wide reference point, maintained by NARA as the CUI Executive Agent, that enumerates the official categories and subcategories of CUI and consolidates the federal-level guidance and policy governing that information. For compliance officers, contractors, and system security personnel, it is generally the starting point for determining whether information they hold qualifies as CUI at all.

The Registry also matters because it distinguishes CUI Basic from CUI Specified. For CUI Specified, the Registry indicates which underlying laws, regulations, and government-wide policies impose specific handling controls, meaning that safeguarding obligations can vary by category rather than following a single uniform standard. Misreading this distinction can lead an organization to under-protect information that carries statutory handling requirements, or to apply the wrong controls entirely.

A critical caveat that experts insist on: the Registry defines and categorizes CUI, but it does not by itself specify the implementation-level security controls for information systems. Identifying information as CUI in the Registry is a categorization step, not a compliance solution. Practitioners must map any applicable safeguarding requirements (for example, those flowing from NIST guidance or contractual clauses) against the current authoritative text and any agency-specific tailoring, and should verify the Registry's category listings, which are periodically updated.

Who it's relevant to

Government Contractors and Subcontractors
Organizations that receive, create, or store CUI in the course of federal contracts generally begin with the Registry to determine whether the information they handle qualifies as CUI and which category applies. The Registry helps distinguish CUI Basic from CUI Specified, but contractors must separately confirm the safeguarding and contractual requirements that apply to their systems, which the Registry does not by itself specify.
Compliance Officers and Information System Security Managers
Personnel responsible for information handling and safeguarding programs use the Registry to categorize information consistently with government-wide policy and to identify, for CUI Specified categories, the underlying laws, regulations, and policies that impose specific controls. They should treat categorization via the Registry as distinct from selecting and implementing system security controls, which must be determined from the applicable authoritative guidance.
Records Managers and Data Governance Staff
Those managing the marking, storage, and lifecycle of sensitive information rely on the Registry as the authoritative catalog of approved CUI categories and subcategories. Because the listings are maintained by NARA and periodically updated, these staff should verify current entries rather than relying on prior versions.
Auditors and Assessors
Personnel evaluating whether an organization correctly identifies and handles CUI can use the Registry as a reference for approved categories and for the distinction between CUI Basic and CUI Specified. Assessors should remember that confirming Registry-based categorization is separate from verifying that appropriate system safeguards are in place, and should reference the current authoritative text and any agency-specific tailoring.

Inside CUI Registry

CUI Categories and Subcategories
An organized listing of the information types that qualify as Controlled Unclassified Information, generally grouped into categories (for example, categories related to privacy, law enforcement, or export control) with more granular subcategories. The precise set of categories is maintained by the CUI Executive Agent and may be updated over time, so practitioners should verify the current listing against the official registry.
Authority Citations
References to the laws, federal regulations, or government-wide policies that establish safeguarding or dissemination controls for each CUI category. These citations distinguish CUI (which requires an underlying legal or policy authority) from information that an agency simply prefers to protect.
Marking Guidance
Standardized guidance on how CUI is to be marked, including banner markings, category markings, and any limited dissemination control markings. This promotes consistency across federal agencies and their contractors, though agency-specific implementation details may still apply.
Limited Dissemination Controls
Approved controls that restrict or specify how CUI may be shared or further distributed. These are intended to be applied only when authorized, rather than as ad hoc restrictions created by individual users or offices.
Executive Agent Role
Identification of the CUI program's Executive Agent responsibility, which oversees and maintains the registry as the authoritative government-wide reference. Because responsibilities and content are subject to update, the reader should confirm the current authoritative source.

Common questions

Answers to the questions practitioners most commonly ask about CUI Registry.

Does the CUI Registry list every specific piece of information that must be protected?
No. The CUI Registry, maintained by the National Archives and Records Administration (NARA) in its role as the CUI Executive Agent, catalogs the categories and subcategories of information that may qualify as Controlled Unclassified Information, along with associated markings and the legal authorities (laws, regulations, or government-wide policies) that establish each category. It is an authoritative index of categories, not an inventory of individual documents or data elements. Determining whether a particular piece of information falls within a listed category, and how it must be handled, remains the responsibility of the agency or contractor generating or holding the information, and should be verified against the current Registry and applicable agency guidance.
Is inclusion in the CUI Registry the same thing as the specific handling and safeguarding requirements for that information?
No. The Registry identifies categories and the authorities that make information CUI, and it distinguishes CUI Basic from CUI Specified, but it does not by itself constitute the complete set of safeguarding, dissemination, or marking controls that apply. Handling requirements generally derive from the underlying laws, regulations, and government-wide policies cited in the Registry, from the CUI program regulation, and, for information systems, from separately issued security guidance. Readers should treat the Registry as a starting point for identifying categories and their authorities, then confirm the applicable safeguarding requirements against the governing sources and any agency-specific implementation.
How do I use the CUI Registry to determine which category applies to information my organization holds?
In most implementations, you begin by identifying the nature and source of the information, then locate the matching category or subcategory in the Registry and review the sanctioning authority cited for it. Because designation authority generally rests with the agency that originates or controls the information, contractors typically rely on the designating agency's markings and contractual direction rather than independently assigning categories. Where the applicable category is unclear, the reader should consult the designating agency and confirm against the current Registry text rather than relying on assumptions.
What is the practical difference between CUI Basic and CUI Specified as reflected in the Registry?
The Registry generally distinguishes CUI Basic categories, for which baseline handling controls apply, from CUI Specified categories, where the underlying law, regulation, or government-wide policy prescribes specific or more restrictive handling requirements. For CUI Specified, you should refer directly to the authority cited in the Registry to determine those additional controls. Because these distinctions can carry different marking and dissemination obligations, verify the current Registry entry and the referenced authority before establishing handling procedures.
How should CUI markings relate to what appears in the Registry?
The Registry provides the approved category markings and abbreviations, and markings applied to information should align with the categories and formats it establishes. In practice, marking also follows the CUI program's marking guidance and any agency-specific instructions. Because marking conventions can be updated, confirm the current approved markings against the Registry and applicable guidance rather than reusing legacy or ad hoc labels.
How often should we consult the CUI Registry when maintaining a compliance program?
Because categories, subcategories, and cited authorities in the Registry can change over time, it is generally advisable to treat it as a living reference and to check the current version when designating, marking, or handling CUI, and periodically as part of program review. Organizations should avoid relying on a cached or dated copy for authoritative determinations and should confirm the current Registry content and any related agency guidance at the time of use.

Common misconceptions

The CUI Registry is a DoD-specific artifact that governs only defense contractors.
The CUI program is a government-wide framework, and the registry serves as a common reference across federal executive branch agencies. DoD contractual safeguarding obligations (such as those flowing through DFARS clauses) reference CUI but are distinct from the registry itself, and civilian agency obligations under FISMA-related guidance may be implemented differently. State, local, tribal, and territorial obligations may also differ.
Any sensitive or internal information an agency wants to protect automatically qualifies as CUI listed in the registry.
CUI generally requires an underlying law, regulation, or government-wide policy authorizing its protection, and the registry ties each category to such an authority. Information without a qualifying authority is generally not CUI, and agencies are not supposed to invent protection categories outside the registry's framework.
Following the CUI Registry's marking guidance means an organization is fully compliant and secure.
The registry addresses categorization, authorities, and marking, but it does not by itself establish the technical safeguarding controls an organization must implement. Handling and protecting CUI typically involves separate control requirements (for example, those referenced in applicable NIST guidance), and marking correctly is not the same as securing the information. Compliance with marking rules is not equivalent to security.

Best practices

Consult the current official CUI Registry maintained by the CUI Executive Agent rather than relying on internal copies or memory, since categories, authorities, and markings can be updated over time.
Confirm that any information you designate as CUI maps to a specific category and its cited legal or policy authority, and avoid applying CUI protections to information lacking a qualifying authority.
Apply banner, category, and limited dissemination control markings consistently with the registry's guidance, and reconcile that guidance with any agency-specific or contract-specific implementation instructions that apply to your systems.
Treat the registry as the categorization reference and separately identify and implement the safeguarding controls required for the CUI you handle, recognizing that marking guidance does not establish technical protections.
For defense contractors, verify how CUI obligations flow through applicable contract clauses and program requirements rather than assuming the registry alone defines your contractual duties.
Establish a periodic review process to check the registry for changes and to re-validate that your organization's categorizations and markings remain aligned with the current authoritative text.