What is CUI?
Controlled Unclassified Information (CUI) is information the government creates or possesses, or that a contractor creates for the government, that a law, regulation or government-wide policy requires to be safeguarded, but that is not classified. For defense contractors, holding CUI is what triggers DFARS 252.204-7012, the 110 requirements of NIST SP 800-171 Rev 2 and CMMC Level 2.
Where the definition comes from
Executive Order 13556 of November 4, 2010 created a single CUI program for the executive branch. Its implementing regulation, 32 CFR Part 2002, was published September 14, 2016. The National Archives (NARA) is the Executive Agent, with its Information Security Oversight Office running day-to-day oversight.
Part 2002 binds agencies directly. It reaches your company indirectly, through the contracts, grants and agreements under which an agency shares CUI with you. The CUI Registry at archives.gov lists every approved category, its legal basis and the required markings.
CUI Basic and CUI Specified
CUI Basic is information whose authorizing law or policy does not spell out specific handling rules, so the uniform controls in Part 2002 and the Registry apply. CUI Specified is information whose authority sets its own handling controls, which may be stricter or simply different. The Registry shows which is which.
Designators must mark CUI with a banner that uses either the word CONTROLLED or the acronym CUI. Defense work commonly involves categories such as controlled technical information and export-controlled data.
How CUI shows up in a defense contract
DFARS 252.204-7012 calls it covered defense information: CUI that is either marked or otherwise identified in your contract and provided by or for DoD, or collected, developed, received, used or stored by your company in support of the contract. That second branch matters. Drawings and data your engineers create for a DoD program can be CUI even if nobody stamped them.
Not everything is CUI. Part 2002 excludes information a non-government entity holds in its own systems that did not come from, and was not created for, an executive branch agency.
What you must do once you have it
- Protect every system that processes, stores or transmits it with the 110 requirements of NIST SP 800-171 Rev 2.
- Use only cloud services that meet FedRAMP Moderate-equivalent requirements and the clause's incident terms.
- Report cyber incidents affecting it to DoD within 72 hours of discovery.
- Meet CMMC Level 2. Since the July 13, 2026 memo suspended Phase 2, new solicitations may call only for Level 2 (Self), and DFARS 252.204-7012 remains in effect.
How to find your CUI
Read each contract for CUI markings and for the 7012 clause, list the drawings, specifications and data you receive from the government or your prime, and trace where those files travel: email, file shares, engineering workstations, the shop floor and outside vendors. When a document looks controlled but is unmarked, ask your contracting officer or prime in writing. That map becomes the boundary for your SSP and your CMMC assessment.
Common follow-up questions
Is Federal Contract Information (FCI) the same as CUI?
No. FCI is any non-public information provided by or generated for the government under a contract, protected by the 15 basic safeguarding requirements and CMMC Level 1. CUI is a narrower, more sensitive set that requires NIST SP 800-171 Rev 2 and CMMC Level 2.
What if the documents I receive are not marked?
Covered defense information includes information otherwise identified in the contract and information you develop in support of it, so missing markings do not settle the question. Ask your contracting officer or prime contractor in writing and treat the data as CUI until they answer.
Is export-controlled technical data CUI?
The CUI Registry includes export control categories, so ITAR or EAR technical data you hold for a federal contract is typically CUI as well. Export rules add their own obligations on who may access the data, which often shapes your choice of cloud environment.
LAN Service Group's ISSO-led CMMC practice helps defense suppliers identify where CUI lives, define the assessment boundary and document it in the System Security Plan.
Talk to LAN Service Group (888) 281-7243Sources
- National Archives: About Controlled Unclassified Information (CUI)
- 32 CFR Part 2002, Controlled Unclassified Information (eCFR)
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- Under Secretary of War memo: Implementing Suspension of CMMC Phase 2 Requirements (Jul 13, 2026)