Reference guide

What is CUI? Controlled unclassified information explained

Identify CUI using the government connection, CUI Registry, contract and markings, then trace what protection the information requires.

Reviewed · Deep Fathom

Wide tables scroll sideways to show all columns.

Controlled unclassified information is government-connected information for which applicable law, regulation, or government-wide policy requires or permits safeguarding or dissemination controls, excluding classified information. The definition covers information the government creates or possesses and information an entity creates or possesses for or on behalf of the government. A sensitive business label alone does not establish CUI status, and the CUI Registry identifies the recognized categories and their authorities. For defense contractors, the next step is to connect the information to contract requirements, including whether it meets DFARS 252.204-7012’s definition of covered defense information.

A drawing arrives with a CUI banner. A second drawing arrives without one. A third is your company’s own product design. Which files belong in the protected environment?

The answer takes more than a filename or a sensitivity judgment. Establish why the information qualifies, who supplied or created it, and what the contract says to do with it.

What makes information CUI?

32 CFR 2002.4 connects CUI to the government and to a legal or policy authority requiring or permitting safeguarding or dissemination controls. It also excludes classified information and information a non-executive-branch entity possesses solely on its own behalf.

Section 2002.4(h) states the exclusion directly:

CUI does not include classified information

That last distinction matters for a supplier’s intellectual property. A company can have confidential information without all of it becoming CUI. Conversely, information developed for government performance may require protection even when it originated inside the contractor’s business.

Use the NARA CUI Registry to identify the category and underlying authority. The registry includes categories such as controlled technical information and export-controlled information. A category name is a research lead rather than permission to label every engineering file CUI.

CUI Basic and CUI Specified

Basic and Specified describe how safeguarding or dissemination requirements are established. Neither is a classified level.

TypeMeaningWhat to examine
CUI BasicThe underlying authority requires or permits controls without specifying the handling or dissemination controlsGovernment-wide CUI requirements and the applicable agreement
CUI SpecifiedThe underlying authority requires or permits specific controls for at least part of the handlingThe cited authority and its specific requirements, alongside applicable general requirements

A single category label doesn’t answer every handling question. Follow its authority into the agreement and the workflow.

NARA’s CUI FAQ explains the government-wide program. For practical marking questions, continue to the CUI banner and markings guide.

A marking is evidence, not the whole determination

A CUI marking communicates handling information. An absent or questionable marking needs investigation rather than an automatic decision that the file is safe to distribute.

DFARS 252.204-7012 defines covered defense information through both the information category and its connection to contract performance. One part of the definition covers information marked or otherwise identified in the contract and provided by or on behalf of DoD. Another covers qualifying information collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of performance.

Read both parts. Focusing only on government-furnished files misses the contractor-developed question.

Our recommended response to ambiguity is a written clarification request through the appropriate contracting channel. Identify the item, contract reference, suspected category, and missing instruction. Avoid copying the information into a general-purpose support ticket to ask whether it’s sensitive.

Three drawings, three different questions

Consider this hypothetical intake review. These examples illustrate an intake method. They do not determine the status of real documents.

ItemEvidence availableNext question
Government-furnished drawing with a CUI markingA government source, marking and contract contextWhich category and handling instructions govern this item?
Drawing developed to perform the contract, with no bannerA performance connection but incomplete designation informationDoes the information fit an authorized category and the contract’s covered-information definition?
Independent commercial design held solely for the company’s own useNo established government-purpose connectionWhat other confidentiality or export duties apply, without assuming CUI status?

The missing banner in the second row doesn’t settle the issue. Neither does the commercial sensitivity of the third drawing.

In Deep Fathom’s view, a useful intake record should preserve the reason for the decision. “Engineering says CUI” is harder to review later than a category, authority, contract reference, and named decision owner.

What does CUI mean under DFARS 7012?

For a defense contractor, DFARS 252.204-7012 addresses covered defense information, safeguarding, cyber incident reporting, and applicable subcontract flowdown. Its requirements need to be read against the information and systems involved.

The clause’s cloud provision matters when an external cloud service stores, processes, or transmits covered defense information. It calls for security requirements equivalent to the FedRAMP Moderate baseline and the relevant incident-reporting and cooperation provisions.

This means the CUI decision should travel into system design and procurement. Identify where the information enters, where copies and backups go, which providers can access it, and how it leaves. The CUI boundary guide turns that inventory into a scope discussion. The DFARS 7012 guide explains the associated contract duties.

How does CMMC fit?

CMMC is the assessment program. As of September 30, 2026, the DoW CIO program page identifies Revision 2’s 110 requirements for Level 2 and says Phase II is suspended while the program remains in Phase I.

CUI identification still has a job to do. The assessment schedule doesn’t identify the files, systems, people, or providers that need protection.

Make the first decision traceable

For each uncertain information set, record the source, government-purpose connection, proposed CUI category, authority, contract reference, and handling instructions. Name the unresolved question and the person or contracting channel responsible for resolving it.

Then follow one representative item through the workflow. Check the actual destinations rather than stopping at the approved diagram. A download, email attachment, support export, or backup deserves an explicit place in the review.

Our editorial recommendation is to settle the information question before treating a software purchase as the answer. For a discussion of the workflow, contact Deep Fathom with a non-sensitive description of the problem. Keep the actual controlled files in their authorized environment.

Sources and what they support
SourceUse on this page
NARA CUI frequently asked questionsGovernment connection, identification and marking questions.
NARA CUI Registry categoriesRecognized categories and underlying authorities.
32 CFR 2002.4, NARA final ruleCUI, CUI Basic and CUI Specified definitions.
DFARS 252.204-7012Contract definitions, safeguarding, reporting, cloud and flowdown.
DoW CIO CMMC program statusDated program status and assessment baseline.

Return to CMMC readiness