What Is the CUI Program and Why It Matters

The Controlled Unclassified Information (CUI) Program is the U.S. government-wide framework that standardizes how sensitive but unclassified information is identified, handled, protected, and shared. It was established by Executive Order 13556 in November 2010 and implemented by 32 CFR Part 2002 in 2016, with the National Archives (NARA) as Executive Agent (archives.gov/cui).

The program replaced decades of inconsistent agency markings - "For Official Use Only," "Sensitive But Unclassified," and dozens of others - with defined categories, markings, and safeguarding requirements.

From an IT and cybersecurity perspective, the CUI Program answers one critical question: what data requires protection, and to what standard? Everything downstream - DFARS, NIST SP 800-171, CMMC - depends on getting CUI identification and handling right.

What It Is

CUI is information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy, but is not classified. The program standardizes three things: what counts (categories), how it is labeled (markings), and how it must be handled (safeguarding and dissemination controls).

The CUI Registry, maintained by NARA as Executive Agent, is the official catalog of authorized categories and their controls. If a category is not in the Registry, the information is not CUI.

The program is about identification, marking, and handling - but it directly drives technical security requirements, because the protection standard for CUI on nonfederal systems is NIST SP 800-171. Misidentify the data and every downstream control decision inherits the error.

Who It Applies To

Here the legal structure matters, because it is narrower than most summaries claim.

The CUI Program binds executive branch agencies directly. It does not apply directly to private companies: 32 CFR 2002.1(f) applies the program to non-executive-branch entities indirectly, through incorporation into agreements - contracts, grants, and licenses. A contractor's CUI obligations come from the clauses it signs, such as DFARS 252.204-7012, not from merely possessing the data. /* ⚖️ COUNSEL - applicability framing corrected from "possession = obligation" per fact-check */

That is why reviewing your contract clauses is step zero. In practice, the population handling CUI under agreements includes:

  • Prime defense contractors and their subcontractors and suppliers: the largest group by far.
  • Manufacturers and engineering firms: technical data is the dominant CUI type in defense work.
  • IT, MSP, and cloud providers supporting government work: obligations reach the systems, whoever runs them.
  • Professional services firms handling government data: where their agreements say so.

Company size does not matter. The contract does.

What Information Is Regulated

Common CUI categories include:

  • Defense and military information: including controlled technical information (CTI).
  • Export-controlled technical data: the overlap zone with ITAR and EAR.
  • Procurement and acquisition data: source selection and contract information.
  • Critical infrastructure information: security-relevant details about essential systems.
  • Privacy and personally identifiable information: where law or policy requires control.
  • Law enforcement sensitive data: investigation and enforcement records.
  • Financial and budgetary data: where tied to controlled programs.

/* FLAG: category list matches Registry groupings but was not verified line-by-line against the live Registry index this session - verify wording at archives.gov/cui before publish (fact-check UNVERIFIABLE item) */

The CUI Registry is the authoritative source for categories and handling requirements.

In most organizations, CUI is rarely confined to one system. It lives in email, file shares, cloud storage, collaboration tools, endpoints, and vendor systems. If you do not know where CUI lives, you cannot protect it - and misidentified CUI is one of the most common root causes of DFARS and CMMC failures.

Relation to Other Frameworks

Understanding this chain is essential, and this page is its anchor:

  • CUI Program: defines what data is sensitive and requires protection.
  • NIST SP 800-171: defines how CUI must be protected on nonfederal systems.
  • **DFARS:** makes CUI protection a contractual requirement.
  • **CMMC:** verifies compliance through assessment and affirmation.

CUI is the what. NIST defines the how. DFARS and CMMC enforce it.

If CUI is mis-scoped, everything downstream breaks: the wrong systems get protected, the SSP describes the wrong boundary, and the assessment tests the wrong environment. ITAR runs parallel to this chain - export-controlled technical data is a CUI category, and ITAR separately governs who may access it.

IT Requirements

The CUI Program is about identification, marking, and handling, but it directly drives technical requirements:

  • Data identification and classification: identify CUI accurately, distinguish it from non-CUI data, and understand the applicable handling requirements. This is foundational to every other control.
  • Controlled access and identity: CUI accessible only to authorized users with a lawful government purpose - role-based access, least privilege, strong authentication, and timely revocation.
  • Secure storage and transmission: approved environments, protection from unauthorized access, and secure transmission. Encryption, segmentation, and secure configurations are the working expectation.
  • Data flow awareness: know how CUI moves between systems, where it is shared, and which vendors or partners touch it. Untracked data flows are a major risk.
  • Vendor and third-party controls: vendors handling CUI must meet security requirements, obligations must flow down contractually, and oversight is on you. You are responsible for your supply chain.
  • Documentation and evidence: document where CUI exists, how it is protected, which controls apply, and how risks are managed. This documentation feeds directly into SSPs, POA&Ms, and assessments.

Why It Matters

Most organizations fail at the CUI level before any technical control is tested:

  • No data classification: nobody has decided what is CUI, so nothing is scoped.
  • Over- or under-classification: both are expensive - one buys controls you do not need, the other leaves obligations unmet.
  • Assuming IT vendors handle compliance: they run systems; they do not own your data obligations.
  • Poor visibility into cloud and collaboration tools: CUI spreads wherever sharing is easy.
  • Informal data-sharing practices: the untracked email attachment is the classic failure.

These failures cascade directly into DFARS and CMMC findings. A CUI-level mistake is never contained at the CUI level.

How It Fits Into Cyber Risk Management

The CUI Program aligns closely with the NIST Cybersecurity Framework, NIST SP 800-171 and 800-53, ISO 27001, and zero trust and least-privilege models.

Organizations that understand and manage their CUI well typically have strong overall security posture, not just defense compliance. Data-level clarity is the same discipline that makes every other framework cheaper.

How We Help With CUI Program Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment starts where defense compliance starts - identifying your CUI, mapping where it flows, and matching it to the controls your contracts actually require.

How to Prepare

  1. 01Identify and inventory your CUI

    Document what information qualifies as CUI, the applicable Registry categories, where the data is stored, and how it is accessed and shared. Start from your contract clauses - they define what you owe.

  2. 02Map CUI data flows

    Understand system-to-system movement, external sharing, vendor involvement, and cloud usage. The flows you have not mapped are the ones that fail assessments.

  3. 03Implement access and security controls

    Restrict access to those with a need, secure storage environments, encrypt in transit and at rest, and monitor and log access to controlled data.

  4. 04Align systems with NIST SP 800-171

    Systems handling CUI need to meet the required controls, including MFA, endpoint security, configuration management, and incident response. This is where the CUI Program becomes engineering work.

  5. 05Document and maintain evidence

    Prepare System Security Plans, data flow diagrams, access control documentation, and POA&Ms for gaps. The documentation is what assessments and contract officers actually read.

Frequently Asked Questions

How do I know if we have CUI?

Start with your contracts, not your file shares. CUI obligations reach private companies through contract clauses - DFARS 252.204-7012 is the common one - and the contract identifies covered information. Then check the data itself against the CUI Registry categories at archives.gov/cui. Technical drawings, export-controlled data, and defense program information are the usual suspects.

Does the CUI Program apply to private companies?

Indirectly, and the mechanism matters. 32 CFR Part 2002 binds executive branch agencies directly; it reaches contractors through incorporation into agreements. Your obligations come from the clauses you sign, not from merely holding the data. That is also why the answer changes contract by contract.

What is the difference between CUI and FCI?

Federal Contract Information is the broader, lower tier - information provided by or generated for the government and not for public release, safeguarded under FAR 52.204-21. CUI is the sensitive subset requiring specific controls under law, regulation, or government-wide policy, protected to NIST SP 800-171. FCI points to CMMC Level 1; CUI points to Level 2.

Who decides what counts as CUI?

The government, through the CUI Registry maintained by the National Archives as Executive Agent. Agencies mark CUI based on Registry categories; contractors do not get to decide categories, but they do have to recognize and handle what they receive - and flag anything unmarked that plainly should be.

How does the CUI Program relate to NIST 800-171, DFARS, and CMMC?

It is the first link in the chain. The CUI Program defines what data needs protection. NIST SP 800-171 defines how. DFARS makes it contractual. CMMC verifies it. Mis-scope the CUI and every later step inherits the mistake.

What happens if we mishandle CUI?

The consequences arrive through your contracts: findings, corrective demands, lost eligibility, or termination - and misrepresenting compliance creates legal risk beyond the contract. Mishandling also cascades into DFARS incident reporting obligations if the mishandling becomes an incident.

What does CUI compliance cost?

It depends almost entirely on scoping - how much CUI you hold and how contained it is. We publish no pricing; you get a firm quote before any work begins, and the conversation costs nothing. Tight scoping is the single biggest cost lever.

Where do we start?

Inventory first: what CUI you hold, under which contracts, in which systems. Everything else - controls, SSPs, assessments - depends on that answer being right. Our Cyber Risk & Compliance Gap Assessment begins exactly there.

Official source

Official source: National Archives (NARA), CUI Executive Agent

Secondary source: eCFR, 32 CFR Part 2002

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25