Skip to content

CUI Identification: What Actually Counts as Controlled Unclassified Information

CUI Graphics_300 x 300
dOES YOUR ORGANIZATION HANDLE CUI?

Most defense contractors don’t realize how often they come across CUI in everyday work. In two minutes, learn if your company may already handle CUI.

Listen: CUI Identification: What Actually Counts as Controlled Unclassified Information
8:06

Executive Brief 

Most defense contractors handle Controlled Unclassified Information (CUI) more often than they realize. 

CUI hides in emails, HR files, project folders, supplier documents, and even meeting notes. Overlooking it is one of the fastest ways to fail a Cybersecurity Maturity Model Certification (CMMC). 

The challenge isn’t just protecting CUI. It’s identifying it correctly. If you can’t spot it, you can’t secure it or track all the places it moves through such as email, shared drives, vendor portals, contract files, engineering tools, and everyday collaboration systems. 

This guide breaks down what actually counts as CUI, addresses common blind spots auditors look for, and provides examples for contractors with questions. Start with a quick self-check: Take the 2-minute CUI Identification Quiz. 


Why CUI Identification Is Difficult 

CUI isn’t always stamped, labeled, or obvious. And many teams assume that if they don’t work with “classified” data, they don’t work with CUI. 

Reality check: 

  • CUI is everywhere — supply chain files, HR paperwork, technical data, procurement documents, emails. 
  • It’s often created accidentally — copying, forwarding, or referencing controlled content makes the new document CUI. 
  • It flows down from primes — your subcontract may not say “CUI,” but the obligation still applies: DFARS 252.204-7012 requires primes to pass CUI protection, incident reporting, and cybersecurity requirements to any subcontractor that handles the information. Check ISI's Prime Tracker to see what major primes like Boeing, Lockheed, and RTX are telling their supply chains about their CUI handling obligations under CMMC.
  • Misidentifying CUI leads to mishandling — and that creates real consequences: assessment findings, contract risk, financial penalties, or reputational damage. 

Before you can protect CUI, you must recognize it.

Examples of Controlled Unclassified Information

The table below connects the CUI categories contractors deal with most often to the documents they show up in. If a file fits one of these, treat it as CUI, even when no one marked it that way.

CUI Category What it looks like in your environment
Controlled Technical Information (CTI) Engineering drawings
Schematics
CAD files
Test results
Specs for Department of Defense systems
Export-Controlled Information (ITAR / EAR) Technical data covered by International Traffic in Arms Regulations or Export Administration Regulations, including anything a prime shares under a controlled program
Proprietary Business Information (PBI, CBI) Non-public pricing, bids
Supplier data packages
Trade-secret material exchanged under contract
Privacy Information (PII and SPII) Staff records carrying Personally Identifiable Information or Sensitive Personally Identifiable Information, such as:
Badge lists
Clearance records
Social Security numbers
Medical or financial details
Financial Records Contract cost data
Non-public invoices
Pricing tied to government deliverables
Legal Documents Litigation holds, privileged contract correspondence, and other legal material tied to a program
Law Enforcement Sensitive (LES) Investigation files or security-incident records connected to a contract or facility
Procurement and Contract Information Statements of Work, performance reports, and non-public deliverables the government hasn’t released
System, Network, and Facility Details Network diagrams
Security configurations
Physical security layouts
Access logs tied to defense work

Remember: copying or forwarding controlled content makes the new file CUI, and a draft counts the moment it references controlled material rather than when it is finalized. Flow-down trips up subcontractors most: under DFARS 252.204-7012, a prime must pass CUI protection and reporting requirements to any subcontractor that stores, processes, or transmits the information, even when the subcontract never uses the word CUI.

Who Defines CUI

CUI isn’t a label any agency invents on its own. It comes from Executive Order 13556, signed in 2010, which replaced a patchwork of agency-specific rules with one government-wide standard for protecting sensitive unclassified information.

The National Archives and Records Administration (NARA) runs the program as its Executive Agent. NARA maintains the CUI Registry, the official catalog of every approved CUI category and the law or policy behind it. 32 CFR Part 2002 is the implementing regulation.

The Department of Defense applies these rules through DoD Instruction 5200.48. For contractors, that instruction is where CUI meets CMMC compliance and the safeguarding requirements in DFARS 252.204-7012. When you need to confirm whether something qualifies, consult the National Archives CUI Registry as the authoritative source; don’t rely on a prime's habit or an internal assumption.

Where Teams Miss CUI Most Often 

Auditors consistently flag the same blind spots: 

  • Email threads 
  • Shared drives with mixed access 
  • File shares copied into SharePoint or Teams 
  • Slide decks built for internal updates 
  • Unlabeled drafts or working documents 
  • Invoices, purchase orders, or shipping docs 

If a document references, summarizes, or quotes CUI in any way, it becomes CUI. That’s why it’s often said that CUI is contagious. 

How CUI Is Marked: Basic vs. Specified

CUI replaced older markings like For Official Use Only (FOUO) and Sensitive But Unclassified (SBU). If you still see those on legacy documents, treat the content as CUI and re-mark it under the current standard.

Every piece of CUI falls into one of two levels:

  • CUI Basic is the default. It covers most controlled information and follows the baseline safeguarding rules in 32 CFR 2002 and NIST SP 800-171. A Basic document carries a simple banner marking that reads CUI.
  • CUI Specified applies when the underlying law or policy sets stricter handling or dissemination rules. Controlled Technical Information and some export-controlled data fall here. A Specified document carries category markings in its banner, such as CUI//SP-CTI, so handlers know the extra controls apply.

A complete marking has a banner across the top of the document and a designation indicator naming the office responsible for it. It may also carry limited dissemination controls that restrict who can receive it. Access stays limited to people with a lawful government purpose, meaning a real need tied to a contract or mission.

Marking happens at the point of creation. Whoever creates or generates the document is responsible for identifying it as CUI and applying the correct banner, which is why identification has to happen early rather than at audit time.

The Risks of Getting It Wrong 

Misidentifying CUI isn’t a minor issue; it’s a compliance failure. 

  • Failed assessments - Certified Third-Party Assessment Organizations (C3PAO) and Defense Industrial Base Cybersecurity Assessment Center (DBCAC) expect clear boundaries, consistent labeling, and documented control. 
  • Lost and delayed contracts - Primes increasingly ask subs to show proof of CUI handling controls before onboarding. 
  • False Claims Act exposure (FCA) - Mishandling CUI while asserting compliance in your System Security Plan (SSP) or SPRS score can trigger FCA scrutiny. 
  • Uncontained data spread - Once CUI leaks into emails, shared folders, or personal drives, containment is difficult and expensive. 

Knowing what counts as CUI is the first line of defense. 

How to Get Better at CUI Identification 

You don’t need a catalog memorized; you need awareness. 

  • Train teams on CUI categories and examples 
  • Use metadata tagging and sensitivity labels 
  • Maintain a contract-specific CUI registry 
  • Review system boundaries and access controls 
  • Label at the earliest possible point of creation 
  • Encourage teams to ask, not assume 

And step one: know whether you’re handling CUI in the first place. 

Start with a 2-Minute Check 

Most contractors are surprised by how much CUI already exists in their systems. 

Use our new quick-check tool to find out whether your organization is already handling CUI today: 

You’ll learn: 

  • Whether your organization likely handles CUI 
  • Where it may already live 
  • What to do next to protect it 
  • Whether you need to update your SSP, boundaries, or controls 

Before you invest in remediation or policy updates, start with clarity. 


FAQs 

Does all government data count as CUI? 

No. Not all government data is CUI. 

CUI is a specific subset of unclassified information that federal agencies designate as requiring protection under laws, regulations, or government-wide policies. Examples include technical data, export-controlled information, sensitive personnel information, and program-specific details. 

Government data that is public, purely administrative, or not tied to a protected category is not CUI. 

If a prime doesn’t label data as CUI, is it safe to treat it as unrestricted? 

No. Labeling mistakes are common, and primes expect subcontractors to recognize CUI even when it arrives mislabeled or unlabeled. 

Under DFARS 252.204-7012, subs must safeguard CUI whenever they receive or generate it — regardless of whether the prime marked it correctly. 

If the content fits a CUI category (technical drawings, controlled technical information, sensitive program data, procurement-sensitive info), treat it as CUI and seek clarification if needed. 

Do drafts count as CUI? 

Yes. Drafts must be protected the same way as final documents if they contain CUI or reference it. 

That includes emails, early versions of drawings, redlines, change orders, design iterations, lab notes, and working spreadsheets.  

CUI doesn’t become “CUI” only when finalized, it’s CUI the moment it is created, transmitted, or stored. 

What’s the difference between Federal Contract Information (FCI) and CUI? 

FCI is information provided by or generated for the government under a contract and not meant for public release. It requires basic safeguarding under FAR 52.204-21. 

CUI is more sensitive. It includes technical data, drawings, specifications, personnel information, supply chain details, and other categories governed by federal law or DoD marking rules. CUI requires full implementation of all 110 NIST SP 800-171 controls and often triggers CMMC Level 2. 

Many contractors think they’re only handling FCI, but everyday files such as engineering snippets, subcontractor packages, HR data tied to programs or even change orders can contain CUI. Misclassification is one of the top reasons contractors fail assessments.


 Internal Links 

Related Posts