Skip to main content

Free Compliance Guide

What Is CUI? The Framework Behind Every CUI Obligation

Controlled Unclassified Information explained in plain terms: Executive Order 13556, 32 CFR 2002, and the NARA Registry, the foundation your whole program rests on.

You keep hearing CUI Basic versus CUI Specified, and the difference has never quite landed

If you are new to a contract with CUI obligations, the requirements feel scattered on purpose. They live across 32 CFR 2002, NIST 800-171 and 172, DFARS, FAR, and the NARA Registry, and no single source tells you where to begin. Before you can mark, safeguard, or share anything, you have to know what actually qualifies as CUI in your environment, and how it differs from FCI and classified information. This guide gives you that framework straight, before you build anything on top of it.

The scope of what a CUI program has to account for

110
NIST SP 800-171 security requirements across 14 control families that CUI Basic defaults to on nonfederal systems.
35
Additional NIST SP 800-172 enhanced requirements that apply to high-value CUI.
20
Index groupings organize every approved CUI category in the NARA CUI Registry.
72 hrs
The DFARS 252.204-7012 window to report a cyber incident to DoD, starting at discovery.

Why getting identification right decides everything downstream

Most programs fail at the first step: they either treat everything as CUI and grind operations to a halt, or cast the net too narrow and miss categories an assessor flags immediately. Two systems handling the same CUI category can fail an assessment for opposite reasons, one for being over-scoped and the other for being undocumented. The guide starts where the confusion starts, so the marking, safeguarding, and governance you build later rest on a defensible foundation instead of a guess.

What is inside the guide

Eight chapters covering the full CUI lifecycle

CUI Basic vs. CUI Specified, and why the distinction has direct operational consequences
How to map your data to the NARA CUI Registry and cite the specific governing authority
The common DIB categories: SP-CTI, PRVCY, SP-EXPT, PROCURE, and INTEL
Distinguishing CUI from FCI (FAR 52.204-21) and from classified information
How contracts drive designations, and why the same data type varies contract to contract
Building a CUI inventory tied to systems as the foundation of your SSP
Copy-ready banner, portion, and LDC marking formats, plus destruction methods by media type
Eight chapters covering the full lifecycle: identify, mark, safeguard, share, destroy, report, and govern

Free 22-Page Compliance Guide

Get instant access to the guide

Copy-ready marking formats, tables, and checklists inside.
  • CUI Basic vs. CUI Specified explained
  • CUI vs. FCI vs. classified comparison table
  • How to map data to the NARA CUI Registry
CUI Program Buildout Guide

Download the guide

We'll email you the guide right away.

Verifying you're human...

What you can do after reading it

Explain the difference with confidence

Walk into any conversation able to say why a category is CUI Basic or CUI Specified and what that changes about handling.

Scope your environment accurately

Identify what qualifies as CUI in your specific operational context without over-scoping operations or leaving gaps for an assessor to find.

Trace every designation to an authority

Tie each data category to a NARA Registry entry and the law or contract that drives it, so your inventory holds up under review.

Fix the gaps assessors flag first

Understand the boundary ambiguities and documentation failures that produce the most common findings before an audit surfaces them.

Grounded in the primary authorities, not interpretation

Primary authorities cited throughout

Executive Order 13556, 32 CFR Part 2002, NIST SP 800-171, 800-172, and 800-88, DFARS 252.204-7012, FAR 52.204-21, CMMC (32 CFR Part 170), and FedRAMP.

The NARA CUI Registry

References archives.gov/cui as the authoritative source for approved CUI categories and subcategories.

Named controls and families

Specific NIST 800-171 controls including 3.1.1, 3.5.3, 3.8.3, 3.13.8, and 3.13.11.

CMMC Level 2 practices

Cites AC.L2-3.1.3, AT.L2-3.2.1, and AT.L2-3.2.2.

Real tables you can copy

A framework comparison table, marking-format tables, and a destruction-method-by-media-type table.

Current through 2026

Reflects the suspended CMMC Phase 2 posture, the FIPS 140-2 historical-list move, and NIST 800-171 Rev 2 obligations.

Frequently asked questions

No. CUI does not require a clearance to access, but it does require a lawful government purpose and proper access controls. Treating it as classified creates unnecessary friction; treating it as ordinary business data creates regulatory and national security exposure. The guide includes a table comparing FCI, CUI Basic, CUI Specified, and classified information side by side.

Get the framework straight before you build anything

Copy-ready marking formats, tables, and checklists inside. Free 22-page guide.