Skip to main content
Category: Controlled Unclassified Information

CUI Specified

Also known as: Specified CUI
Simply put

CUI Specified is a subset of Controlled Unclassified Information (CUI) for which the underlying law, regulation, or government-wide policy spells out specific handling or dissemination controls, rather than leaving the protections to standard baseline safeguards. It is not a higher level of protection than CUI Basic; the distinction lies in whether the governing authority itself dictates particular controls. Because these requirements come directly from the authorizing source, handlers generally must consult that specific authority to apply the correct controls.

Formal definition

Per the CUI Registry maintained by the National Archives and Records Administration (NARA) through the Information Security Oversight Office (ISOO), CUI Specified is the subset of CUI in which the authorizing law, regulation, or government-wide policy contains specific handling controls that differ from or supplement the standard CUI Basic safeguarding requirements. An authority qualifies as a Specified authority when it does more than require or permit protection or dissemination restriction; it also prescribes particular controls for the information. CUI Basic and CUI Specified do not represent different levels of protection, the differentiator is whether the governing authority itself enumerates handling controls (Specified) or relies on the uniform baseline (Basic). Practitioners should identify the applicable Specified authority via the CUI Registry and apply its controls; note that this entry addresses the definitional distinction and does not cover agency-specific implementation, DoD-specific policy under the DoD CUI Program, or contractual safeguarding obligations, which should be confirmed against the current authoritative texts.

Why it matters

The distinction between CUI Basic and CUI Specified matters because a common and consequential mistake is to assume that all CUI is protected the same way, by a single uniform baseline. For CUI Specified, the authorizing law, regulation, or government-wide policy itself prescribes particular handling or dissemination controls that may differ from or supplement the standard baseline safeguarding requirements. A handler who applies only the generic CUI Basic safeguards to information that is actually CUI Specified may fail to meet the controls mandated by the governing authority, creating a compliance gap even where the organization believed it was fully protecting the information.

An equally important correction is that CUI Specified is not a higher level of protection than CUI Basic. As the Information Security Oversight Office (ISOO) emphasizes, the two are not different levels of protection; the difference lies solely in whether the governing authority enumerates specific controls (Specified) or relies on the uniform baseline (Basic). Treating Specified as inherently "more sensitive" can lead to over-restriction, inconsistent marking, or misallocation of resources, while treating it as identical to Basic can lead to under-protection relative to what the underlying authority requires.

Because the specific controls for CUI Specified originate directly from the authorizing source, they cannot be inferred from general CUI practice alone. Practitioners must trace each category back to its governing authority to apply the correct controls, a step that is easy to overlook when categories are handled through standardized processes. This entry addresses the definitional distinction only; it does not resolve agency-specific implementation, DoD-specific policy under the DoD CUI Program, or contractual safeguarding obligations, all of which should be confirmed against current authoritative texts.

Who it's relevant to

Compliance officers and CUI program managers
Those responsible for CUI programs must ensure their organizations correctly distinguish CUI Basic from CUI Specified and route Specified categories to the specific controls their authorizing sources prescribe. Relying on a single uniform safeguarding approach for all CUI risks missing category-specific requirements.
Information system security managers and data handlers
Personnel who mark, store, transmit, or disseminate CUI need to consult the CUI Registry to identify whether a category is Specified and, if so, apply the handling and dissemination controls dictated by its governing authority rather than assuming baseline protections are sufficient.
Government contractors handling CUI
Contractors processing CUI should recognize that Specified categories may carry controls beyond the standard baseline. This entry covers only the definitional distinction; contractors must confirm contractual safeguarding obligations and any DoD-specific requirements under the DoD CUI Program against the current authoritative texts.
Auditors and assessors
Those evaluating CUI handling should verify that an organization has traced each CUI category to its governing authority and applied Specified controls where applicable, while avoiding the error of treating Specified as a higher protection tier than Basic when the two are not different levels of protection.

Inside CUI Specified

CUI Specified Category
A subset of Controlled Unclassified Information for which a law, regulation, or government-wide policy specifies particular handling, safeguarding, or dissemination controls beyond the baseline applied to CUI Basic. The specific requirements are dictated by the underlying authority rather than a single uniform standard.
Underlying Authority
The law, regulation, or government-wide policy (as identified in the CUI Registry maintained by the National Archives and Records Administration's Information Security Oversight Office) that establishes the specific controls for a given category. Practitioners should verify the governing authority for each category against the current Registry.
Distinction from CUI Basic
CUI Basic is protected under the uniform baseline safeguarding and dissemination controls, while CUI Specified carries additional or differing requirements drawn from its source authority. A given piece of information may be designated as one or the other depending on the applicable category.
Marking Considerations
CUI Specified generally involves marking that reflects the applicable category, and the associated authority may impose limited dissemination controls. Exact marking conventions should be confirmed against current NARA CUI Program guidance.

Common questions

Answers to the questions practitioners most commonly ask about CUI Specified.

Is CUI Specified simply a more sensitive or higher-impact version of CUI Basic?
Not quite. The distinction between CUI Specified and CUI Basic is not primarily about sensitivity level or impact rating. CUI Basic is the default category where the safeguarding and dissemination controls come from the general CUI baseline, whereas CUI Specified applies when a law, regulation, or government-wide policy establishes specific handling requirements that differ from or add to that baseline. A CUI Specified item does not automatically carry a higher confidentiality impact; rather, it is governed by the particular authority that designated it. Readers should consult the CUI Registry maintained by the applicable oversight authority to identify the specific handling controls tied to each category, and verify current requirements against official sources.
Does labeling information as CUI Specified change which safeguarding controls I implement on the information system itself?
The CUI Specified designation governs the additional or differing handling, marking, and dissemination controls required by the underlying authority for that category; it does not by itself redefine the baseline of system security controls used to protect the information. Protection of CUI on systems is generally addressed through the applicable control frameworks and requirements (for example, the safeguarding expectations associated with CUI on nonfederal systems), while CUI Specified requirements layer specific dissemination or handling limitations on top. Do not conflate the categorization authority with the security control catalog. Confirm both the categorization requirements and the applicable safeguarding requirements against current authoritative guidance.
How do I determine whether a given piece of information is CUI Specified rather than CUI Basic?
Determination generally begins with identifying the law, regulation, or government-wide policy that designates the information as CUI. If that authority prescribes specific controls for handling, marking, or disseminating the information beyond the general CUI baseline, it is typically treated as CUI Specified. The CUI Registry organizes categories and indicates the governing authorities, so it is a common starting point for making this determination. Because interpretation can be agency-specific and authorities are updated over time, coordinate with your organization's designated CUI officials and verify against the current Registry and applicable agency guidance.
How should CUI Specified information be marked?
Marking for CUI Specified generally includes the standard CUI indicators along with a category marking that reflects the specific authority, and it may require additional dissemination or handling markings prescribed by that authority. Because the precise marking conventions depend on the governing category and evolving guidance, confirm the required format against the current CUI marking guidance from the applicable oversight authority and any agency-specific supplements before applying markings. This entry does not specify exact marking strings, which the reader must verify against official sources.
Do the specific handling rules for a CUI Specified category override my organization's general CUI procedures?
In most implementations, the controls prescribed by the specific authority for a CUI Specified category apply in addition to or in place of the corresponding general CUI baseline controls, to the extent the authority establishes different requirements. Where the specified authority is silent, the general CUI handling procedures typically still apply. Because reconciling baseline and specified requirements can be nuanced and agency-specific, document your handling determinations and confirm precedence questions with your CUI officials and against the governing authority.
What should I do when information falls under more than one CUI Specified authority with differing requirements?
When multiple authorities apply, organizations generally must satisfy the handling and dissemination requirements of each applicable authority, which can mean applying the more restrictive control where they differ. Resolving conflicts or overlaps typically requires consulting the specific governing authorities identified in the CUI Registry and coordinating with designated CUI officials. This entry does not resolve specific multi-authority conflicts; confirm the correct treatment against current official guidance and, where legal interpretation is involved, appropriate counsel.

Common misconceptions

CUI Specified is a higher classification level than CUI Basic.
CUI Specified is not a classification level and does not indicate greater sensitivity in a hierarchical sense. It denotes that a specific law, regulation, or government-wide policy prescribes particular handling controls; the distinction is about the source of controls, not a tier of secrecy. CUI in all forms remains unclassified.
The same safeguarding requirements apply uniformly to all CUI Specified information.
The controls for CUI Specified vary by category because they are derived from the specific underlying authority. Practitioners must consult the authority listed in the CUI Registry for each category rather than assuming a single set of requirements applies across all Specified categories.
Meeting general CUI handling controls automatically satisfies CUI Specified obligations.
Baseline CUI handling may be insufficient where a category's underlying authority imposes additional or differing controls. Compliance should be verified against the specific requirements of that authority, and readers should confirm applicability against current official sources.

Best practices

Consult the NARA/ISOO CUI Registry to identify whether information falls under a CUI Specified category and to locate the governing law, regulation, or government-wide policy.
Trace each CUI Specified designation back to its underlying authority and document the specific safeguarding and dissemination requirements that authority imposes.
Apply markings that accurately reflect the applicable CUI Specified category, verifying conventions against current CUI Program guidance rather than assuming baseline CUI markings suffice.
Avoid treating all CUI uniformly; distinguish CUI Basic from CUI Specified in policies, training, and system handling procedures.
Re-verify category authorities periodically, as the CUI Registry and associated guidance may be updated over time.
Coordinate with the responsible designating authority or organizational CUI program office when uncertainty exists about which controls apply.