Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
What is Controlled Unclassified Information (CUI)?
CUI: What is Controlled Unclassified Information (CUI)? Complete Guide for Defense Contractors
Controlled Unclassified Information (CUI) is sensitive government information that requires special protection but is not classified as secret. If you’re a defense contractor working with the Department of Defense (DoD), understanding Controlled Unclassified Information is essential for CMMC compliance and maintaining your eligibility to win government contracts.
CMMC stands for Cybersecurity Maturity Model Certification—the DoD’s program to verify that contractors properly protect government information.
This guide explains everything you need to know about Controlled Unclassified Information, including how to identify it, how to protect it, and your obligations as a defense contractor.
Understanding Controlled Unclassified Information: The Basics
Controlled Unclassified Information is unclassified information that the government creates or owns that requires safeguarding or dissemination controls according to federal laws, regulations, or government-wide policies.
The key word here is unclassified—CUI is NOT classified information like Confidential, Secret, or Top Secret. However, it still needs protection because unauthorized disclosure could harm government operations, national security interests, or individual privacy.
Safeguarding means protecting information from unauthorized access or disclosure. Dissemination controls means rules about who can share the information and how.
The History of Controlled Unclassified Information
Before the CUI program existed, the federal government had a problem: more than 100 different markings were being used across agencies to identify sensitive unclassified information. Each agency created its own labels like “For Official Use Only (FOUO),” “Sensitive But Unclassified (SBU),” and “Law Enforcement Sensitive (LES).” This created confusion and made it difficult to share information securely between agencies.
In November 2010, President Obama signed Executive Order 13556 to standardize how the government handles Controlled Unclassified Information. The order established the CUI Program to create uniform policies across the entire executive branch.
The National Archives and Records Administration (NARA) was designated as the Executive Agent for the CUI Program, meaning NARA oversees implementation and ensures all agencies follow the same rules.
Executive Agent means the organization responsible for managing and overseeing a government-wide program.
In September 2016, NARA published the final rule establishing the official CUI Program policies in 32 CFR Part 2002. These regulations became effective on November 14, 2016, and apply to all federal agencies and contractors who handle Controlled Unclassified Information.
Two Types of Controlled Unclassified Information
The CUI Program divides Controlled Unclassified Information into two subsets:
CUI Basic
CUI Basic is Controlled Unclassified Information where the authorizing law, regulation, or government-wide policy does not specify particular handling or dissemination controls beyond the baseline requirements.
For CUI Basic, you must implement the security requirements in NIST SP 800-171, which contains 110 security controls. This is the foundation of CMMC Level 2 requirements.
NIST stands for National Institute of Standards and Technology—a federal agency that develops cybersecurity standards. NIST SP 800-171 is their guide for “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.”
CUI Specified
CUI Specified is Controlled Unclassified Information where the authorizing law, regulation, or government-wide policy contains specific handling controls that are more stringent than, or different from, the baseline CUI Basic controls.
For example, some CUI Specified categories may require additional encryption, limited sharing with foreign nationals, or specific retention and destruction procedures.
The CUI Registry: Your Master Reference
The CUI Registry is NARA’s official online database that lists all approved CUI categories. It’s the authoritative reference for what qualifies as Controlled Unclassified Information.
The CUI Registry currently contains 125 categories organized into 20 organizational index groupings. Each category includes:
- A description of the information type
- The federal law, regulation, or policy that requires its protection
- Whether it’s CUI Basic or CUI Specified
- Applicable markings and handling requirements
- Penalties or sanctions for misuse
Common CUI categories relevant to defense contractors include:
- Controlled Technical Information (CTI) – Technical data with military or space applications subject to export controls
- Critical Infrastructure Security Information – Information about vulnerabilities in critical systems
- Defense – Various defense-related information categories
- Export Control – Information subject to export control laws like ITAR or EAR
- Privacy – Personally Identifiable Information (PII) that requires protection
- Procurement and Acquisition – Sensitive procurement information
ITAR stands for International Traffic in Arms Regulations. EAR stands for Export Administration Regulations. Both control the export of sensitive technical data and defense articles.
How to Identify Controlled Unclassified Information
Determining whether information is Controlled Unclassified Information can be challenging. Here’s a practical approach:
Ask these three questions:
- Created – Was this data originally created by the government and provided to you under the contract?
- Used – Will this data be used to deliver your contractual responsibilities to the government?
- Identified – Can this data type be identified within the categories listed in the CUI Registry?
If the answer is “yes” to these questions, the information is likely Controlled Unclassified Information.
Who Designates Information as CUI?
The federal agency that owns or creates the information is responsible for designating it as Controlled Unclassified Information. The “authorized holder” (the person with legitimate access to the information) makes this determination at the time the information is created or received.
Authorized holder means a person who has official access to Controlled Unclassified Information as part of their job duties.
As a contractor, you are not responsible for deciding what is or isn’t CUI—that’s the government’s job. However, you ARE responsible for properly protecting any information the government designates as Controlled Unclassified Information.
CUI Marking Requirements
Controlled Unclassified Information must be marked with specific designations to indicate that it requires protection.
Banner Markings
All CUI documents must have a banner marking at the top of each page. The banner marking appears in all capital letters and follows this format:
- CUI (for CUI Basic)
- CUI//SP-[Category] (for CUI Specified)
For example:
- CUI
- CUI//SP-EXPT (for export-controlled information)
- CUI//SP-CTI (for Controlled Technical Information)
The banner marking tells you immediately that the document contains Controlled Unclassified Information and requires special handling.
Portion Markings
When a document contains both CUI and unclassified information that doesn’t require protection, portion markings may be used to identify which specific paragraphs or sections contain Controlled Unclassified Information.
Portion markings appear at the beginning of each paragraph and use abbreviations like:
- (CUI)
- (U) for unclassified sections
Legacy Markings
You may still encounter older documents with legacy markings like FOUO (For Official Use Only) or SBU (Sensitive But Unclassified). These legacy markings are being phased out, but documents with these markings should generally be treated as Controlled Unclassified Information until properly reviewed and remarketed.
How to Protect Controlled Unclassified Information
The CUI Program requires that Controlled Unclassified Information be protected at the FISMA Moderate confidentiality baseline.
FISMA stands for Federal Information Security Modernization Act—a law that sets information security requirements for federal agencies and contractors.
For defense contractors, this means you must implement the 110 security requirements in NIST SP 800-171 Revision 2. These requirements cover 14 security domains:
- Access Control (AC) – Limiting who can view or use CUI
- Awareness and Training (AT) – Teaching employees about security
- Audit and Accountability (AU) – Tracking who accesses what information
- Configuration Management (CM) – Managing system settings and changes
- Identification and Authentication (IA) – Verifying user identities
- Incident Response (IR) – Handling security incidents
- Maintenance (MA) – Keeping systems secure during maintenance
- Media Protection (MP) – Protecting physical and digital media
- Personnel Security (PS) – Screening and monitoring personnel
- Physical Protection (PE) – Securing facilities and equipment
- Risk Assessment (RA) – Identifying and evaluating risks
- Security Assessment (CA) – Testing security controls
- System and Communications Protection (SC) – Protecting systems and networks
- System and Information Integrity (SI) – Detecting and responding to threats
Your Obligations as a Defense Contractor
If your DoD contract involves handling Controlled Unclassified Information, you have several key obligations:
1. CMMC Certification
As of November 10, 2025, you must achieve the appropriate CMMC level to be eligible for contract award. For contracts involving Controlled Unclassified Information, you’ll need [CMMC Level 2 or Level 3 certification](link to your CMMC levels article).
2. System Security Plan (SSP)
You must develop a System Security Plan that documents how your organization implements the NIST SP 800-171 security requirements. The SSP describes your policies, procedures, and technical controls for protecting Controlled Unclassified Information.
A System Security Plan is a formal document that describes how you protect information systems that process, store, or transmit CUI.
3. SPRS Reporting
You must submit your NIST SP 800-171 assessment score to the Supplier Performance Risk System (SPRS). The maximum score is 110, indicating full implementation of all requirements.
SPRS is the DoD’s online database where contractors report their cybersecurity assessment scores.
4. Cyber Incident Reporting
Under DFARS clause 252.204-7012, you must report cyber incidents affecting Controlled Unclassified Information to the DoD within 72 hours.
DFARS stands for Defense Federal Acquisition Regulation Supplement—the DoD’s supplement to the Federal Acquisition Regulation (FAR) that governs defense contracts.
5. Flow-Down Requirements
If you use subcontractors who will handle Controlled Unclassified Information, you must flow down the same security requirements and ensure your subcontractors also achieve the required CMMC level.
Common Misconceptions About Controlled Unclassified Information
Misconception #1: “CUI is classified information”
FALSE. Controlled Unclassified Information is explicitly NOT classified. It doesn’t meet the damage thresholds for Confidential, Secret, or Top Secret classification under Executive Order 13526. However, it still requires protection.
Misconception #2: “Only the prime contractor needs to protect CUI”
FALSE. Any organization in the supply chain that handles Controlled Unclassified Information must implement the required security controls, including subcontractors at all tiers.
Misconception #3: “If information isn’t marked as CUI, I don’t need to protect it”
FALSE. Sometimes government agencies fail to properly mark Controlled Unclassified Information. If you receive information that meets the CUI definition but isn’t marked, you should treat it as CUI and notify the government agency.
Misconception #4: “I can share CUI with anyone in my company”
FALSE. Access to Controlled Unclassified Information should be limited to authorized personnel who have a “need to know”—a legitimate business reason to access the information to perform their job duties.
Penalties for Mishandling Controlled Unclassified Information
Mishandling Controlled Unclassified Information can result in serious consequences:
- Contract penalties – Loss of current contracts or contract modifications
- Ineligibility for future contracts – Inability to bid on new DoD work
- Administrative sanctions – Formal reprimands or suspension from contract work
- Criminal penalties – For willful unauthorized disclosure, depending on the underlying law protecting the specific CUI category
- False Claims Act liability – If you falsely certify compliance with security requirements
Getting Started with CUI Compliance
If you’re new to handling Controlled Unclassified Information, take these steps:
1. Complete CUI Training
Ensure all employees who may access Controlled Unclassified Information complete CUI awareness training. The DoD and NARA provide free training resources.
2. Review Your Contracts
Identify which contracts involve Controlled Unclassified Information by reviewing contract clauses, specifically:
- FAR clause 52.204-21 (for Federal Contract Information)
- DFARS clause 252.204-7012 (for CUI)
- DFARS clause 252.204-7021 (CMMC requirements)
3. Conduct a Gap Assessment
Compare your current security practices against the 110 NIST SP 800-171 requirements to identify gaps. Consider working with a CMMC Registered Provider Organization (RPO) for expert guidance.
4. Develop Your System Security Plan
Document how you will implement the required security controls in a comprehensive System Security Plan.
5. Implement Security Controls
Close the gaps identified in your assessment by implementing the necessary technical, administrative, and physical security controls.
6. Prepare for CMMC Assessment
Once your controls are in place, schedule your [CMMC Level 2 assessment](link to your assessment process article) with a certified third-party assessor (C3PAO) when required.
Key Takeaway
Controlled Unclassified Information is sensitive government data that defense contractors must protect according to standardized federal requirements. Understanding CUI is essential for CMMC compliance and maintaining your ability to win DoD contracts. The CUI Program creates a uniform framework that replaces the confusing patchwork of legacy markings, making it clearer what information needs protection and how to protect it properly.
For defense contractors, the bottom line is simple: if you handle Controlled Unclassified Information, you must implement NIST SP 800-171 security controls and achieve the appropriate CMMC certification level.
Related Resources:
- NIST SP 800-171 Official Publication
- CUI Registry – National Archives
- 32 CFR Part 2002 – CUI Regulations
Official Sources: This article is based on Executive Order 13556 “Controlled Unclassified Information” (2010), 32 CFR Part 2002 published by the National Archives and Records Administration (NARA), DoDI 5200.48 “Controlled Unclassified Information” (2020), and NIST Special Publication 800-171 Revision 2 published by the National Institute of Standards and Technology.