Skip to main content
Category: Controlled Unclassified Information

DoD CUI Registry

Also known as: Department of Defense CUI Registry, DoD Controlled Unclassified Information Registry
Simply put

The DoD CUI Registry is the Department of Defense's reference source that identifies the categories of Controlled Unclassified Information (CUI) relevant to defense work and the handling requirements associated with them. For personnel and contractors working under DoD contracts, it generally serves as the authoritative source for CUI requirements. It is distinct from the Government-wide CUI Registry maintained separately, and readers should confirm current guidance against the applicable official source.

Formal definition

The DoD CUI Registry is a Department of Defense repository that identifies CUI categories and associated handling, marking, and safeguarding guidance applicable to DoD personnel and contractors. In most implementations affecting DoD contracts, it is treated as the authoritative source for defense-specific CUI requirements, and should be distinguished from the Government-wide CUI Registry maintained by the National Archives and Records Administration (NARA) through its Information Security Oversight Office (ISOO), which serves as the Federal-level online repository for CUI policy and practice. The two registries are related but not interchangeable; the Government-wide registry provides Federal-level category guidance, while the DoD registry addresses defense-specific application. This entry does not cover the specific contents, category listings, or contractual and CMMC implementation obligations tied to particular CUI categories, which the reader must verify against the current authoritative registry text.

Why it matters

For organizations working under Department of Defense contracts, correctly identifying whether information qualifies as CUI and which handling requirements apply is a foundational compliance obligation. The DoD CUI Registry generally serves as the authoritative source for defense-specific CUI requirements, so relying on it, rather than assuming a category or marking based on general knowledge, helps personnel and contractors apply the correct safeguarding, marking, and handling expectations tied to their work.

A common and consequential mistake is conflating the DoD CUI Registry with the Government-wide CUI Registry maintained by the National Archives and Records Administration (NARA) through its Information Security Oversight Office (ISOO). The two are related but not interchangeable: the Government-wide registry is the Federal-level online repository for CUI policy and practice, while the DoD registry addresses defense-specific application. Treating one as a substitute for the other can lead to misidentifying categories or applying the wrong handling guidance, which in a defense context can carry contractual and compliance consequences.

Because CUI identification underpins broader obligations, including safeguarding requirements referenced in DoD contracts and CMMC assessments, getting the registry reference right is a prerequisite, not a formality. Identifying information as CUI is only the starting point; it does not by itself satisfy the associated safeguarding, contractual, or assessment requirements, which must be verified against current authoritative sources.

Who it's relevant to

DoD Contractors and Their Compliance Teams
Organizations performing under DoD contracts generally treat the DoD CUI Registry as the authoritative source for defense-specific CUI requirements. Compliance staff use it to identify applicable CUI categories and associated handling expectations, but should verify current category listings and contractual obligations against the authoritative registry text rather than relying on general assumptions.
DoD Personnel Handling CUI
Department of Defense personnel who create, receive, or handle CUI reference the registry to apply defense-specific marking, handling, and safeguarding guidance. Completing the official DoD CUI training course is generally required to fulfill the initial training obligation, and personnel should distinguish the DoD registry from the Government-wide registry maintained by NARA/ISOO.
Information System Security Managers and Auditors
ISSMs and auditors assessing CUI safeguarding in defense environments use the registry as a reference point for confirming which categories apply. They should note that identifying information as CUI is distinct from meeting the associated safeguarding and assessment requirements, including those tied to CMMC, which must be verified separately against current authoritative sources.

Inside DoD CUI Registry

CUI Categories and Subcategories
Listings that identify types of information designated as Controlled Unclassified Information, generally organized by category (such as those grouped under organizational index groupings), with each category tied to the law, regulation, or government-wide policy that authorizes its protection.
Authorizing Basis References
For each category, references to the underlying law, federal regulation, or government-wide policy that establishes the information as CUI, reflecting the fact that CUI is defined by legal and policy authority rather than by agency preference.
CUI Basic and CUI Specified Distinctions
Indications of whether a category is handled as CUI Basic (protected under uniform baseline safeguarding controls) or CUI Specified (subject to specific handling, dissemination, or safeguarding requirements set by the authorizing source). Practitioners should verify the applicable handling treatment against the current authoritative text.
Marking and Dissemination Guidance
Information relevant to marking CUI and applying limited dissemination controls, supporting consistent labeling of covered information within the DoD context. Detailed marking mechanics should be confirmed against current DoD and government-wide CUI guidance.

Common questions

Answers to the questions practitioners most commonly ask about DoD CUI Registry.

Is the DoD CUI Registry the same as the National CUI Registry maintained by NARA?
No. These are distinct resources that should not be conflated. The National CUI Registry is maintained by the National Archives and Records Administration (NARA) in its role as the CUI Executive Agent and defines CUI categories governmentwide. A DoD-specific CUI resource generally serves to identify how the Department of Defense implements and applies CUI categories within its own programs and systems. Where a DoD resource exists, it is intended to operate under the governmentwide framework established by NARA rather than to replace it. Readers should verify the current authoritative sources for both the governmentwide registry and any DoD-specific implementation guidance, as the relationship and terminology may evolve.
Does identifying information as CUI in the registry by itself tell me which security controls I must apply?
Not directly. A CUI registry generally functions to identify and categorize information types, not to prescribe the full set of safeguarding controls for a given system. Determining applicable protections typically depends on separate authorities and factors, such as the safeguarding requirements referenced in applicable DFARS clauses, the control expectations associated with NIST SP 800-171 for CUI in nonfederal systems, or the RMF and NIST SP 800-53 baselines for DoD systems. Categorization is one input into that process, not a substitute for it. Confirm the specific safeguarding obligations against the current governing regulations and contract terms.
How do I use the registry to determine whether information I handle qualifies as CUI?
A CUI registry is generally used to compare the information you hold against defined CUI categories and their descriptions to see whether it falls within a recognized category. Because categorization can involve agency-specific interpretation and the underlying law, regulation, or governmentwide policy that authorizes a category, you should trace a candidate category back to its authorizing basis rather than relying on the label alone. When categorization is uncertain, coordinate with your organization's designated CUI or information security authority. Verify category definitions against the current authoritative text, as categories may be added, revised, or retired.
How does the registry relate to CUI marking requirements on documents and media?
A CUI registry generally supports marking by identifying the categories and, in some cases, the associated markings or identifiers that correspond to a given category. However, the specific marking format, banner and portion marking practices, and dissemination controls are typically governed by separate CUI marking guidance rather than established solely by a registry entry. Practitioners should apply markings in accordance with the applicable marking guidance and any contract or agency requirements, and confirm current marking conventions against authoritative sources rather than inferring them from a category listing alone.
If my organization is a contractor, how should I incorporate the registry into my handling procedures?
Contractors generally use a CUI registry as a reference for recognizing and categorizing the information they receive or generate under a contract, but the binding obligations usually flow from the contract itself and its incorporated clauses. In most implementations you would align internal handling, marking, and safeguarding procedures with the contract terms, applicable DFARS provisions, and the relevant CUI policy, using the registry to help identify categories rather than to define your contractual duties. Confirm your specific responsibilities with your contracting officer and against the current contract language, as requirements vary by contract.
How should I account for updates or changes to the registry in my compliance process?
Because CUI categories and their authorizing bases can be added, revised, or retired over time, treating a registry as a static reference is a common mistake. It is generally advisable to check the current version of the authoritative registry when categorizing information rather than relying on a previously retrieved copy, and to build a periodic review into your compliance process so that category determinations and associated procedures remain consistent with the latest published guidance. Verify the applicable version and effective status of any category against the current official source.

Common misconceptions

The DoD CUI Registry defines new categories of protected information on its own authority.
The registry generally reflects categories authorized by existing law, regulation, or government-wide policy, and operates within the broader CUI framework overseen at the government-wide level rather than creating protection authorities independently. The specific relationship between the DoD registry and the government-wide CUI registry should be verified against current authoritative sources.
Because information is CUI, applying NIST SP 800-171 controls is all that is required and equals full compliance.
Identifying information as CUI and applying safeguarding controls does not by itself establish that all contractual, category-specific, or agency-specific requirements are met. CUI Specified categories may carry additional handling requirements, and compliance with a control baseline is not the same as achieving security or satisfying every applicable obligation.
All CUI is handled identically regardless of category.
Handling can differ between CUI Basic and CUI Specified, and Specified categories may impose distinct safeguarding or dissemination requirements drawn from their authorizing sources. Practitioners must confirm the treatment for each specific category rather than assuming a single uniform standard.

Best practices

Confirm each information type against the applicable CUI category and its authorizing law, regulation, or government-wide policy before applying handling or marking decisions, rather than relying on informal labels.
Distinguish CUI Basic from CUI Specified for every category in scope, and apply any additional Specified handling or dissemination requirements identified by the authorizing source.
Verify current category listings, marking guidance, and handling requirements against the authoritative DoD and government-wide CUI sources, since these are subject to revision.
Do not treat application of a safeguarding control baseline as evidence of full compliance; separately track contractual, category-specific, and agency-specific obligations.
Document the mapping between the CUI you hold, the applicable category, and the corresponding safeguarding and dissemination controls to support audits and continuous monitoring.
When requirements are ambiguous or agency-specific, escalate to the responsible authorizing official or program office and confirm interpretation against current official guidance rather than assuming.