Skip to main content
Category: Laws & Executive Orders

Executive Order 13556

Also known as: EO 13556, Controlled Unclassified Information (Executive Order), CUI Executive Order
Simply put

Executive Order 13556 is a presidential directive issued on November 4, 2010, that created a single, government-wide program for handling unclassified information that still needs to be safeguarded or have limits placed on how it is shared. Before this order, agencies across the executive branch used inconsistent labels and rules for this kind of sensitive-but-unclassified information. The order aimed to standardize how the federal executive branch marks, protects, and disseminates such information under the term Controlled Unclassified Information (CUI).

Formal definition

Executive Order 13556, titled 'Controlled Unclassified Information' and signed November 4, 2010, established an open and uniform, executive-branch-wide program for managing information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies. It created the CUI Program to standardize the handling of unclassified information across the executive branch, under which only categories of information formally listed in the CUI Registry are treated as CUI. The National Archives and Records Administration (NARA) serves as the Executive Agent for the program and maintains the CUI Registry. As a foundational policy authority, EO 13556 establishes the framework but does not itself specify technical safeguarding controls; practitioners should note that implementation details, such as marking requirements, protection standards (for example, those referenced in associated NARA regulation and NIST guidance), and agency- or contract-specific obligations, including DoD-specific implementation, derive from separate implementing publications that readers must confirm against current authoritative sources.

Why it matters

Before Executive Order 13556, agencies across the federal executive branch used inconsistent labels and rules for unclassified information that still required safeguarding or limits on how it was shared. This patchwork created confusion about how sensitive-but-unclassified information should be marked, protected, and disseminated, both within government and among the contractors and partners who handle such information. EO 13556 matters because it replaced that fragmented landscape with a single, government-wide framework under the term Controlled Unclassified Information (CUI), giving agencies a common foundation for handling this category of information.

For compliance officers, information system security managers, and government contractors, the order is the upstream policy authority that ultimately shapes many downstream obligations. Because only categories of information formally listed in the CUI Registry are treated as CUI, the order also establishes discipline around what does and does not qualify, reducing over-marking and inconsistent designation. Understanding that EO 13556 is the originating directive helps practitioners trace their specific safeguarding, marking, and contractual duties back to a coherent starting point rather than to ad hoc agency practices.

A critical point for experts to emphasize is that EO 13556 is a foundational policy authority, not a technical control set. The order establishes the framework and program but does not itself specify how to safeguard CUI in a given system. Treating the executive order as if it directly imposes technical protection requirements is a common misunderstanding; the actual marking requirements, protection standards, and agency- or contract-specific obligations derive from separate implementing publications that readers must confirm against current authoritative sources.

Who it's relevant to

Compliance Officers and Program Managers
Those responsible for organizational compliance need to recognize EO 13556 as the originating authority for the government-wide CUI Program. It provides the policy basis for identifying which information qualifies as CUI, namely, only categories listed in the CUI Registry, and helps compliance teams distinguish the foundational directive from the separate implementing regulations and guidance that specify actual handling obligations.
Information System Security Managers (ISSMs)
ISSMs should understand that EO 13556 establishes the framework but does not itself specify technical safeguarding controls. Protection standards for CUI derive from separate implementing publications, such as associated NARA regulation and NIST guidance, which must be confirmed against current authoritative sources. The order helps ISSMs understand where their protection requirements ultimately originate without mistaking the directive for a control set.
Government Contractors
Contractors who receive or generate CUI operate downstream of the framework EO 13556 created. Their specific marking, protection, and contractual obligations flow from separate implementing publications, including DoD-specific implementation where applicable, rather than from the executive order directly. Contractors should verify their applicable requirements against current authoritative sources and the terms of their specific agreements.
Authorizing Officials and Auditors
Authorizing officials and auditors benefit from understanding that the CUI Program is government-wide and administered with NARA as the Executive Agent maintaining the CUI Registry. This context supports consistent evaluation of how unclassified information is designated and handled, while recognizing that assessment against specific safeguarding requirements must reference the applicable implementing publications rather than the executive order alone.

Inside EO 13556

Establishment of the CUI Program
Executive Order 13556, signed in 2010, established a government-wide Controlled Unclassified Information (CUI) Program to standardize the way the executive branch handles unclassified information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy. Readers should verify the exact signing date and text against the official source.
Executive Agent Designation
The order designated the National Archives and Records Administration (NARA) as the Executive Agent responsible for implementing and overseeing the CUI Program, including issuing implementing guidance and maintaining the CUI Registry.
Replacement of Ad Hoc Markings
The order was intended to replace the prior patchwork of agency-specific markings and handling designations (such as various 'For Official Use Only' and 'Sensitive But Unclassified' labels) with a standardized, uniform CUI framework across the executive branch.
Relationship to Downstream Guidance
The order provides the policy foundation that is later operationalized through implementing regulation and technical guidance, including NARA's 32 CFR Part 2002 and the safeguarding requirements described in NIST SP 800-171 for CUI residing in nonfederal systems. The order itself does not specify security controls; those derive from separate authorities and should be confirmed against current text.

Common questions

Answers to the questions practitioners most commonly ask about EO 13556.

Does Executive Order 13556 by itself create the specific security controls I must apply to Controlled Unclassified Information?
No. Executive Order 13556 establishes the CUI Program and designates a governing executive agent to standardize how the executive branch handles unclassified information requiring safeguarding or dissemination controls, but the order itself does not enumerate technical or operational security controls. The specific safeguarding requirements are set out in separate authorities and implementing guidance rather than in the text of the order. Readers should verify the current controls and their sources against the applicable official publications, because these can change across revisions and may be tailored by agency.
Is Executive Order 13556 the same thing as the CUI regulation and the associated NIST guidance?
No. Executive Order 13556 is the presidential directive that created the CUI Program and assigned responsibility for its oversight, while the implementing federal regulation and the related NIST guidance are distinct instruments issued by different bodies to operationalize the program. The order provides the policy foundation; the regulation and technical guidance carry it into practice. Treating them as interchangeable can lead to citing the wrong authority. Confirm which document governs a particular obligation by consulting the current authoritative texts.
How does Executive Order 13556 relate to the day-to-day handling of CUI in my organization?
The order provides the top-level policy basis for treating certain unclassified information as CUI across the executive branch, aiming to replace inconsistent agency-specific markings and handling practices with a standardized approach. Operationally, personnel generally follow the implementing regulation, agency-specific policies, and any applicable technical guidance rather than the order itself. Because agency interpretation and tailoring can differ, verify your specific handling, marking, and safeguarding obligations against current official sources and your agency's or contract's requirements.
Does Executive Order 13556 apply to state, local, tribal, and territorial organizations or to contractors?
The order is directed at the executive branch and its handling of covered information. Obligations that reach non-federal entities, including contractors and state, local, tribal, and territorial partners, generally flow through implementing regulations, contract clauses, and agreements rather than directly from the order. Whether and how these obligations apply in a given case depends on the governing instruments involved. This entry does not cover contractual or legal specifics, which a reader must confirm against the current applicable requirements.
What should I reference when marking or safeguarding CUI, given that Executive Order 13556 established the program?
For practical marking and safeguarding decisions, personnel generally rely on the implementing regulation, the executive agent's guidance and registries, and applicable agency policy rather than the order's text, since these sources provide the operational detail. Because categories, markings, and handling expectations may be updated and can be subject to agency-specific interpretation, confirm the current requirements against the authoritative official sources before applying them.
How should I account for changes over time when relying on Executive Order 13556 as an authority?
The order provides an enduring policy foundation, but the instruments that implement it, including regulations and technical guidance, can be revised, and agencies may tailor their approaches. When citing the order as part of a compliance rationale, pair it with verification of the current implementing documents rather than assuming that associated requirements are static. This entry does not track specific revision histories or effective dates, so the reader should confirm the latest authoritative versions.

Common misconceptions

Executive Order 13556 itself defines the technical security controls organizations must implement to protect CUI.
The order established the CUI Program and designated NARA as Executive Agent, but it does not specify security controls. Safeguarding requirements are addressed through separate instruments, such as NARA's implementing regulation (32 CFR Part 2002) and NIST SP 800-171 for nonfederal systems. Practitioners should trace control obligations to those governing documents, not to the order alone.
CUI is a classification level comparable to Confidential, Secret, or Top Secret.
CUI is not classified national security information. It is unclassified information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy. Classified information is governed by a separate authority and handling regime, and conflating the two is a common error.
The order immediately eliminated all legacy markings like 'For Official Use Only' across the government.
The order set the policy direction to standardize markings, but implementation occurs over time through NARA guidance and agency transition efforts. Legacy markings may persist during transition, and agency-specific practices should be verified against current official implementation guidance.

Best practices

Treat Executive Order 13556 as the foundational policy authority and trace specific safeguarding obligations to the downstream implementing regulation (32 CFR Part 2002) and applicable NIST guidance rather than to the order itself.
Consult the CUI Registry maintained by NARA as the Executive Agent to identify approved CUI categories and applicable handling requirements before applying markings.
Distinguish CUI handling requirements from classified information requirements, and confirm which authority governs each information type in your environment.
For CUI residing in or transiting nonfederal systems, review the applicable revision of NIST SP 800-171 and any contractual clauses that invoke it, verifying the current version against official sources.
Establish a transition plan to phase out legacy markings such as 'For Official Use Only' in favor of standardized CUI markings, consistent with current NARA and agency implementation guidance.
Periodically re-verify the order's text, effective dates, and implementing guidance against authoritative sources, since agency interpretations and downstream requirements may evolve.