CUI Specified
CUI Specified is a subset of Controlled Unclassified Information (CUI) for which the underlying law, regulation, or government-wide policy spells out specific handling or dissemination controls, rather than leaving the protections to standard baseline safeguards. It is not a higher level of protection than CUI Basic; the distinction lies in whether the governing authority itself dictates particular controls. Because these requirements come directly from the authorizing source, handlers generally must consult that specific authority to apply the correct controls.
Per the CUI Registry maintained by the National Archives and Records Administration (NARA) through the Information Security Oversight Office (ISOO), CUI Specified is the subset of CUI in which the authorizing law, regulation, or government-wide policy contains specific handling controls that differ from or supplement the standard CUI Basic safeguarding requirements. An authority qualifies as a Specified authority when it does more than require or permit protection or dissemination restriction; it also prescribes particular controls for the information. CUI Basic and CUI Specified do not represent different levels of protection, the differentiator is whether the governing authority itself enumerates handling controls (Specified) or relies on the uniform baseline (Basic). Practitioners should identify the applicable Specified authority via the CUI Registry and apply its controls; note that this entry addresses the definitional distinction and does not cover agency-specific implementation, DoD-specific policy under the DoD CUI Program, or contractual safeguarding obligations, which should be confirmed against the current authoritative texts.
Why it matters
The distinction between CUI Basic and CUI Specified matters because a common and consequential mistake is to assume that all CUI is protected the same way, by a single uniform baseline. For CUI Specified, the authorizing law, regulation, or government-wide policy itself prescribes particular handling or dissemination controls that may differ from or supplement the standard baseline safeguarding requirements. A handler who applies only the generic CUI Basic safeguards to information that is actually CUI Specified may fail to meet the controls mandated by the governing authority, creating a compliance gap even where the organization believed it was fully protecting the information.
An equally important correction is that CUI Specified is not a higher level of protection than CUI Basic. As the Information Security Oversight Office (ISOO) emphasizes, the two are not different levels of protection; the difference lies solely in whether the governing authority enumerates specific controls (Specified) or relies on the uniform baseline (Basic). Treating Specified as inherently "more sensitive" can lead to over-restriction, inconsistent marking, or misallocation of resources, while treating it as identical to Basic can lead to under-protection relative to what the underlying authority requires.
Because the specific controls for CUI Specified originate directly from the authorizing source, they cannot be inferred from general CUI practice alone. Practitioners must trace each category back to its governing authority to apply the correct controls, a step that is easy to overlook when categories are handled through standardized processes. This entry addresses the definitional distinction only; it does not resolve agency-specific implementation, DoD-specific policy under the DoD CUI Program, or contractual safeguarding obligations, all of which should be confirmed against current authoritative texts.
Who it's relevant to
Inside CUI Specified
Common questions
Answers to the questions practitioners most commonly ask about CUI Specified.