Defense contractors who mishandle sensitive government information face contract termination, civil liability, and potential criminal sanctions. What makes this risk particularly acute is that the information triggering those consequences is not classified. It sits in a category that many contractors underestimate: Controlled Unclassified Information(CUI). Understanding what CUI is, how the federal government defines and organizes it, and what proper handling actually requires is no longer optional for any organization operating in the Defense Industrial Base.
What Is Controlled Unclassified Information?
Under 32 CFR Part 2002, Controlled Unclassified Information covers “information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls.” CUI meaning, in practical terms, is sensitive but unclassified data that sits between open public records and classified secrets – not releasable without restriction, but not classified either.
Before 2010, federal agencies used more than 100 different labels for this type of information, with no consistent framework binding them together. The Department of Defense stamped documents “For Official Use Only,” while the Department of Energy used “Official Use Only.” Executive Order 13556, issued in November 2010, established the CUI program and designated the National Archives and Records Administration (NARA) as the CUI Executive Agent, responsible for overseeing the program and publishing government-wide policy.
The categories of information that qualify as CUI are broad, covering Personally Identifiable Information, health records, and controlled technical information related to military systems. Export-controlled data governed by International Traffic in Arms Regulations and Export Administration Regulations (ITAR and EAR), law enforcement records, critical infrastructure details, and sensitive financial data also qualify. If a category does not appear in the CUI Registry, it does not qualify as CUI.
What Is CUI Basic vs. CUI Specified?
The CUI program divides controlled information into two distinct subsets, and the difference between them has real compliance implications.
CUI Basic applies when the authorizing law, regulation, or government-wide policy does not specify particular handling or dissemination controls. For CUI Basic, agencies and contractors follow the uniform baseline requirements established in DoD Instruction 5200.48 and the DoD CUI Registry. Most information that defense contractors encounter in day-to-day operations falls into this category.
CUI Specified applies when the governing law, regulation, or government-wide policy prescribes specific handling controls, either requiring or permitting particular measures beyond the baseline. The handling requirements for CUI Specified are drawn directly from the statute or regulation that created the designation. Contractors who encounter CUI Specified must identify the applicable authority and apply the controls that authority mandates, not just the default CUI requirements.
Understanding which type of CUI is present in a given document or system is a prerequisite for compliant handling. The distinction also affects the organizational index grouping of the information, which in turn influences CMMC Level 2 certification requirements. Contractors handling CUI under the Defense grouping, for example, must complete a third-party assessment by a Certified Third-Party Assessor Organization (C3PAO) to achieve CMMC Level 2 certification.
What Does the ISOO CUI Registry Do?
The Information Security Oversight Office (ISOO) maintains the CUI Registry, the authoritative government-wide catalogue listing every approved category and subcategory of CUI. The registry reflects a compilation of laws, executive orders, and directives that authorize the protection of specific types of information, and ISOO published its first version in 2011.
The registry standardizes definitions across agencies, eliminating the pre-2010 confusion of competing labels. It specifies official markings and banner conventions, links each CUI category to the legal authority that requires its protection, and provides the framework agencies use to mark documents, configure records systems, and design access controls.
NARA also maintains a DoD-specific CUI Registry that mirrors the ISOO version with some differences. The DoD registry excludes immigration information and includes DoD-specific guidance relevant to defense contracts. Both registries are publicly accessible, and contractors who handle CUI should be familiar with both.
Importantly, neither registry grants contractors the authority to designate information as CUI. Only the government, through contracting officers, program managers, or explicit contract markings, can identify what qualifies as CUI in a given contract. Contractors are responsible for protecting what the government identifies and designates, not for making that determination themselves.
Information May Be CUI in Accordance with Which Authority?
A common question among compliance managers is how to determine whether particular information qualifies as CUI when contract language is unclear. The answer traces directly back to the CUI Registry. Information may be CUI in accordance with a specific law, federal regulation, or government-wide policy that appears in the registry as an authorizing authority for a given category, with each entry linking to the statute or directive that created the obligation.
When marking is missing or ambiguous, contractors should not assume the information is or is not CUI based on their own interpretation of the registry. The appropriate steps are to review applicable contract clauses and consult the contracting officer or program manager for clarification. The DoD’s obligation under DoDI 5200.48 is to inform contractors of documents containing CUI, mark those documents, and articulate CUI obligations in contract language. Documented communication with the contracting authority is the contractor’s best protection when that chain breaks down.
Who Can Decontrol CUI?
Decontrol is the formal process of removing CUI designation from information that no longer requires safeguarding or dissemination controls. Under 32 CFR Part 2002 and DoDI 5200.48, this decision belongs to the originator of the information, the Original Classification Authority if the information appears in a security classification guide, or designated offices assigned by the DoD to handle decontrol. For DoD contractors, the operative rule is to treat decontrol authority as residing exclusively with the government unless a contract or agreement explicitly assigns it otherwise.
Decontrol can occur automatically under specific conditions: when laws or regulations no longer require protection of that information category, when the designating agency releases the information publicly, when a Freedom of Information Act disclosure applies, or when a predetermined date or event specified in a decontrol indicator is reached. Positive action by the designating agency, including in response to a formal request from an authorized holder, can also trigger decontrol.
Two important distinctions govern how decontrol interacts with public release. First, decontrol does not equal public release: removing CUI designation relieves the holder from CUI program handling requirements, but a separate pre-publication review under DoDI 5230.09 is still required before any public release. Second, unauthorized disclosure of CUI does not constitute decontrol, meaning the CUI designation remains legally effective after a leak and the contractor remains liable.
CUI Handling as a Foundation for CMMC Compliance
The Cybersecurity Maturity Model Certification program became operational in December 2024, structured around two categories of information: Federal Contract Information and Controlled Unclassified Information. Contractors whose systems process, store, or transmit CUI must achieve CMMC Level 2 at minimum, which requires implementing all 110 security requirements from NIST SP 800-171 and undergoing third-party assessments every three years.
NIST SP 800-171 provides the technical framework for protecting CUI on non-federal systems. Its 110 controls span 14 security families: access control, incident response, configuration management, identification and authentication, and system and communications protection, among others. These controls are binding requirements, not aspirational guidelines. Under DFARS 252.204-7012, compliance with NIST SP 800-171 has been a contractual obligation for any contractor whose systems handle CUI for years.
The January 2025 proposed FAR CUI Rule would extend similar obligations government-wide, beyond DoD contracts, while adding cybersecurity training and incident reporting requirements. Though the rule has not yet been finalized, contractors should expect the underlying compliance obligations to become permanent across federal contracting.
The Department of Justice has escalated False Claims Act enforcement in cybersecurity cases, with contractors who self-attest to compliance without meeting requirements facing substantial civil liability. A contractor handling CUI without proper controls accepts legal, financial, and reputational exposure that a proper compliance program addresses directly.
Getting CUI handling right before pursuing a CMMC assessment is the prerequisite, not an optional preparatory step. Without a clear picture of what CUI exists in a given environment, where it flows, and how it is protected, a System Security Plan [internal link] cannot be accurately scoped, a CMMC assessment cannot be prepared, and certification cannot be achieved.





