The Controlled Unclassified Information (CUI) Program is the U.S. government-wide framework that standardizes how sensitive but unclassified information is identified, handled, protected, and shared. It was established by Executive Order 13556 in November 2010 and implemented by 32 CFR Part 2002 in 2016, with the National Archives (NARA) as Executive Agent (archives.gov/cui).
The program replaced decades of inconsistent agency markings - "For Official Use Only," "Sensitive But Unclassified," and dozens of others - with defined categories, markings, and safeguarding requirements.
From an IT and cybersecurity perspective, the CUI Program answers one critical question: what data requires protection, and to what standard? Everything downstream - DFARS, NIST SP 800-171, CMMC - depends on getting CUI identification and handling right.
CUI is information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy, but is not classified. The program standardizes three things: what counts (categories), how it is labeled (markings), and how it must be handled (safeguarding and dissemination controls).
The CUI Registry, maintained by NARA as Executive Agent, is the official catalog of authorized categories and their controls. If a category is not in the Registry, the information is not CUI.
The program is about identification, marking, and handling - but it directly drives technical security requirements, because the protection standard for CUI on nonfederal systems is NIST SP 800-171. Misidentify the data and every downstream control decision inherits the error.
Here the legal structure matters, because it is narrower than most summaries claim.
The CUI Program binds executive branch agencies directly. It does not apply directly to private companies: 32 CFR 2002.1(f) applies the program to non-executive-branch entities indirectly, through incorporation into agreements - contracts, grants, and licenses. A contractor's CUI obligations come from the clauses it signs, such as DFARS 252.204-7012, not from merely possessing the data. /* ⚖️ COUNSEL - applicability framing corrected from "possession = obligation" per fact-check */
That is why reviewing your contract clauses is step zero. In practice, the population handling CUI under agreements includes:
Company size does not matter. The contract does.
Common CUI categories include:
/* FLAG: category list matches Registry groupings but was not verified line-by-line against the live Registry index this session - verify wording at archives.gov/cui before publish (fact-check UNVERIFIABLE item) */
The CUI Registry is the authoritative source for categories and handling requirements.
In most organizations, CUI is rarely confined to one system. It lives in email, file shares, cloud storage, collaboration tools, endpoints, and vendor systems. If you do not know where CUI lives, you cannot protect it - and misidentified CUI is one of the most common root causes of DFARS and CMMC failures.
Understanding this chain is essential, and this page is its anchor:
CUI is the what. NIST defines the how. DFARS and CMMC enforce it.
If CUI is mis-scoped, everything downstream breaks: the wrong systems get protected, the SSP describes the wrong boundary, and the assessment tests the wrong environment. ITAR runs parallel to this chain - export-controlled technical data is a CUI category, and ITAR separately governs who may access it.
The CUI Program is about identification, marking, and handling, but it directly drives technical requirements:
Most organizations fail at the CUI level before any technical control is tested:
These failures cascade directly into DFARS and CMMC findings. A CUI-level mistake is never contained at the CUI level.
The CUI Program aligns closely with the NIST Cybersecurity Framework, NIST SP 800-171 and 800-53, ISO 27001, and zero trust and least-privilege models.
Organizations that understand and manage their CUI well typically have strong overall security posture, not just defense compliance. Data-level clarity is the same discipline that makes every other framework cheaper.
Here is the key takeaway: if you do not understand your CUI, you cannot be compliant - no matter how good your security tools are.
Most defense compliance failures begin with misidentified or unmanaged CUI, not missing technology. Clarity at the data level changes everything downstream.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment starts where defense compliance starts - identifying your CUI, mapping where it flows, and matching it to the controls your contracts actually require.
Document what information qualifies as CUI, the applicable Registry categories, where the data is stored, and how it is accessed and shared. Start from your contract clauses - they define what you owe.
Understand system-to-system movement, external sharing, vendor involvement, and cloud usage. The flows you have not mapped are the ones that fail assessments.
Restrict access to those with a need, secure storage environments, encrypt in transit and at rest, and monitor and log access to controlled data.
Systems handling CUI need to meet the required controls, including MFA, endpoint security, configuration management, and incident response. This is where the CUI Program becomes engineering work.
Prepare System Security Plans, data flow diagrams, access control documentation, and POA&Ms for gaps. The documentation is what assessments and contract officers actually read.
Start with your contracts, not your file shares. CUI obligations reach private companies through contract clauses - DFARS 252.204-7012 is the common one - and the contract identifies covered information. Then check the data itself against the CUI Registry categories at archives.gov/cui. Technical drawings, export-controlled data, and defense program information are the usual suspects.
Indirectly, and the mechanism matters. 32 CFR Part 2002 binds executive branch agencies directly; it reaches contractors through incorporation into agreements. Your obligations come from the clauses you sign, not from merely holding the data. That is also why the answer changes contract by contract.
Federal Contract Information is the broader, lower tier - information provided by or generated for the government and not for public release, safeguarded under FAR 52.204-21. CUI is the sensitive subset requiring specific controls under law, regulation, or government-wide policy, protected to NIST SP 800-171. FCI points to CMMC Level 1; CUI points to Level 2.
The government, through the CUI Registry maintained by the National Archives as Executive Agent. Agencies mark CUI based on Registry categories; contractors do not get to decide categories, but they do have to recognize and handle what they receive - and flag anything unmarked that plainly should be.
It is the first link in the chain. The CUI Program defines what data needs protection. NIST SP 800-171 defines how. DFARS makes it contractual. CMMC verifies it. Mis-scope the CUI and every later step inherits the mistake.
The consequences arrive through your contracts: findings, corrective demands, lost eligibility, or termination - and misrepresenting compliance creates legal risk beyond the contract. Mishandling also cascades into DFARS incident reporting obligations if the mishandling becomes an incident.
It depends almost entirely on scoping - how much CUI you hold and how contained it is. We publish no pricing; you get a firm quote before any work begins, and the conversation costs nothing. Tight scoping is the single biggest cost lever.
Inventory first: what CUI you hold, under which contracts, in which systems. Everything else - controls, SSPs, assessments - depends on that answer being right. Our Cyber Risk & Compliance Gap Assessment begins exactly there.
Official source: National Archives (NARA), CUI Executive Agent
Secondary source: eCFR, 32 CFR Part 2002
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25