You keep hearing CUI Basic versus CUI Specified, and the difference has never quite landed
If you are new to a contract with CUI obligations, the requirements feel scattered on purpose. They live across 32 CFR 2002, NIST 800-171 and 172, DFARS, FAR, and the NARA Registry, and no single source tells you where to begin. Before you can mark, safeguard, or share anything, you have to know what actually qualifies as CUI in your environment, and how it differs from FCI and classified information. This guide gives you that framework straight, before you build anything on top of it.
The scope of what a CUI program has to account for
Why getting identification right decides everything downstream
Most programs fail at the first step: they either treat everything as CUI and grind operations to a halt, or cast the net too narrow and miss categories an assessor flags immediately. Two systems handling the same CUI category can fail an assessment for opposite reasons, one for being over-scoped and the other for being undocumented. The guide starts where the confusion starts, so the marking, safeguarding, and governance you build later rest on a defensible foundation instead of a guess.
What is inside the guide
Eight chapters covering the full CUI lifecycle
What you can do after reading it
Explain the difference with confidence
Walk into any conversation able to say why a category is CUI Basic or CUI Specified and what that changes about handling.
Scope your environment accurately
Identify what qualifies as CUI in your specific operational context without over-scoping operations or leaving gaps for an assessor to find.
Trace every designation to an authority
Tie each data category to a NARA Registry entry and the law or contract that drives it, so your inventory holds up under review.
Fix the gaps assessors flag first
Understand the boundary ambiguities and documentation failures that produce the most common findings before an audit surfaces them.
Grounded in the primary authorities, not interpretation
Frequently asked questions
No. CUI does not require a clearance to access, but it does require a lawful government purpose and proper access controls. Treating it as classified creates unnecessary friction; treating it as ordinary business data creates regulatory and national security exposure. The guide includes a table comparing FCI, CUI Basic, CUI Specified, and classified information side by side.
If your contract is silent on CUI designation but includes FAR 52.204-21, you are likely handling Federal Contract Information, which carries a lower but distinct set of requirements. The guide walks through how contracts designate CUI and where to look, including the Statement of Work, a CUI Annex, and DD Form 254.
It is written for a program manager or compliance officer new to a contract with CUI obligations who needs the framework straight before building anything. It begins with the governing authority and identification, then builds outward across the lifecycle.
No. It is provided for general informational and educational purposes and is not a substitute for qualified legal counsel, your contracting officer, or a C3PAO. Authorities change, so verify current requirements against the primary sources. Comply Defense is not affiliated with or endorsed by any government agency or standards body.