Quick answer
Controlled Unclassified Information is government-designated sensitive information that is not classified but requires safeguarding controls and access restrictions by contractors.
Controlled Unclassified Information (CUI) is information the federal government designates as requiring safeguarding or dissemination controls under law, regulation, or policy, but which does not meet the standards for classification under Executive Order 13526 or its predecessors.
What is CUI?
CUI was established by Executive Order 13556 in 2010 to consolidate a fragmented landscape of government-defined sensitive information categories - formerly labeled with inconsistent designations like FOUO (For Official Use Only), Sensitive But Unclassified (SBU), Law Enforcement Sensitive (LES), and dozens of others. The National Archives and Records Administration (NARA) manages the CUI Program and maintains the CUI Registry, which defines authorized CUI categories and subcategories, each tied to a specific law, regulation, or government-wide policy that requires the information's protection.
Common CUI categories relevant to federal contractors include: Controlled Technical Information (CTI, covering export-controlled technical data under ITAR and EAR), Privacy (personally identifiable information protected under the Privacy Act), Law Enforcement (investigative records protected under various statutes), and Financial (contractor financial and tax information). The specific CUI category is designated by the government when information is created or shared, and the designation determines which handling controls apply.
For contractors, CUI triggers specific contractual obligations. DFARS 252.204-7012 requires contractors whose systems process, store, or transmit CUI to implement the 110 security requirements in NIST SP 800-171, report cyber incidents within 72 hours, preserve affected images, and provide access to equipment for damage assessment. CUI also cannot be stored on systems below the required security baseline - storing CUI on personal devices or uncontrolled cloud systems is a contract compliance violation.
Why CUI matters for government contractors
CUI designation is the trigger for CMMC Level 2 requirements and NIST SP 800-171 compliance. Contractors who do not know whether the information they receive from the government qualifies as CUI face significant compliance risk - either from unknowingly mishandling CUI (creating liability) or from misidentifying non-CUI as CUI and unnecessarily implementing expensive controls. Understanding the CUI Registry categories and working with contracting officers to clarify which specific information in a contract is designated CUI is a prerequisite for accurate compliance program scoping.
Example
A defense engineering firm receives a contract to provide technical analysis support for a DoD weapons system. The contract identifies the technical data packages and performance specifications being shared as Controlled Technical Information (CTI) under CUI. The firm's compliance team implements NIST SP 800-171 controls on the systems that will access these materials, marks any documents they generate containing CTI with the required CUI marking headers and footers, establishes access controls to limit CTI access to cleared and need-to-know personnel, and ensures the firm's incident response procedures meet the 72-hour reporting requirement. The firm's CUI handling procedures are documented in its System Security Plan.
Frequently Asked Questions
How do I know if information I receive from the government is CUI?
Government agencies are supposed to mark CUI with a specific designation block when transmitting it to contractors. The marking typically includes the CUI category, any required handling language, and the office of origin. However, not all agencies mark CUI consistently. If you receive government information that may be sensitive but is not marked, contact your contracting officer or program manager to ask whether the information requires CUI handling. When in doubt, treat it as CUI until clarified.
What is the difference between CUI and classified information?
Classified information (Confidential, Secret, Top Secret) is information that the government has formally designated as requiring protection in the national security interest under Executive Order 13526. Access requires a security clearance. CUI is unclassified information that requires protection under law or policy for reasons other than national security - privacy, law enforcement sensitivity, export controls, etc. No security clearance is required to access CUI, but specific handling controls apply.
What is the difference between CUI and FCI?
Federal Contract Information (FCI) is a related but distinct category: information provided by or generated for the government under contract that is not intended for public release. FCI triggers CMMC Level 1 requirements (17 basic practices). CUI is a subset of more sensitive government information that triggers CMMC Level 2 requirements (110 NIST SP 800-171 controls). All CUI is FCI, but not all FCI is CUI. Understanding which category applies to your contract determines your compliance obligations.
What marking format is required on CUI documents?
Documents containing CUI must be marked with the CUI designation block in the header and footer of each page. The block includes the word "CUI" (or the specific CUI category designation), any applicable limited dissemination controls, and the agency that designated the information. The CUI Program's marking handbook and the 32 CFR Part 2002 implementing regulations specify exact marking requirements. Improperly marked CUI - missing the required markings - is a compliance finding.
How Bidovate helps
Bidovate puts Controlled Unclassified Information (CUI) to work inside your capture and proposal workflow.
Federal contractingSee Bidovate in action
Book a demo and we will show you the platform using your actual contract data.
Related terms
NIST SP 800-171
NIST SP 800-171 is the federal cybersecurity standard defining 110 security controls that contractors must implement to protect Controlled Unclassified Information in non-federal systems.
ViewCybersecurity Maturity Model Certification (CMMC)
CMMC is the DoD's mandatory cybersecurity certification framework requiring defense contractors to demonstrate compliance with NIST security controls before receiving contracts.
ViewFedRAMP (Federal Risk and Authorization Management Program)
FedRAMP is the federal government's standardized security authorization program for cloud services, enabling agencies to use cloud products that have been pre-approved for federal use.
ViewFederal Contract Information (FCI)
Federal Contract Information is information provided by or generated for the government under contract that is not intended for public release, triggering basic cybersecurity requirements.
View