Most defense contractors handle Controlled Unclassified Information (CUI) more often than they realize.
CUI hides in emails, HR files, project folders, supplier documents, and even meeting notes. Overlooking it is one of the fastest ways to fail a Cybersecurity Maturity Model Certification (CMMC).
The challenge isn’t just protecting CUI. It’s identifying it correctly. If you can’t spot it, you can’t secure it or track all the places it moves through such as email, shared drives, vendor portals, contract files, engineering tools, and everyday collaboration systems.
This guide breaks down what actually counts as CUI, addresses common blind spots auditors look for, and provides examples for contractors with questions. Start with a quick self-check: Take the 2-minute CUI Identification Quiz.
CUI isn’t always stamped, labeled, or obvious. And many teams assume that if they don’t work with “classified” data, they don’t work with CUI.
Reality check:
Before you can protect CUI, you must recognize it.
The table below connects the CUI categories contractors deal with most often to the documents they show up in. If a file fits one of these, treat it as CUI, even when no one marked it that way.
| CUI Category | What it looks like in your environment |
| Controlled Technical Information (CTI) | Engineering drawings Schematics CAD files Test results Specs for Department of Defense systems |
| Export-Controlled Information (ITAR / EAR) | Technical data covered by International Traffic in Arms Regulations or Export Administration Regulations, including anything a prime shares under a controlled program |
| Proprietary Business Information (PBI, CBI) | Non-public pricing, bids Supplier data packages Trade-secret material exchanged under contract |
| Privacy Information (PII and SPII) | Staff records carrying Personally Identifiable Information or Sensitive Personally Identifiable Information, such as: Badge lists Clearance records Social Security numbers Medical or financial details |
| Financial Records | Contract cost data Non-public invoices Pricing tied to government deliverables |
| Legal Documents | Litigation holds, privileged contract correspondence, and other legal material tied to a program |
| Law Enforcement Sensitive (LES) | Investigation files or security-incident records connected to a contract or facility |
| Procurement and Contract Information | Statements of Work, performance reports, and non-public deliverables the government hasn’t released |
| System, Network, and Facility Details | Network diagrams Security configurations Physical security layouts Access logs tied to defense work |
Remember: copying or forwarding controlled content makes the new file CUI, and a draft counts the moment it references controlled material rather than when it is finalized. Flow-down trips up subcontractors most: under DFARS 252.204-7012, a prime must pass CUI protection and reporting requirements to any subcontractor that stores, processes, or transmits the information, even when the subcontract never uses the word CUI.
CUI isn’t a label any agency invents on its own. It comes from Executive Order 13556, signed in 2010, which replaced a patchwork of agency-specific rules with one government-wide standard for protecting sensitive unclassified information.
The National Archives and Records Administration (NARA) runs the program as its Executive Agent. NARA maintains the CUI Registry, the official catalog of every approved CUI category and the law or policy behind it. 32 CFR Part 2002 is the implementing regulation.
The Department of Defense applies these rules through DoD Instruction 5200.48. For contractors, that instruction is where CUI meets CMMC compliance and the safeguarding requirements in DFARS 252.204-7012. When you need to confirm whether something qualifies, consult the National Archives CUI Registry as the authoritative source; don’t rely on a prime's habit or an internal assumption.
Auditors consistently flag the same blind spots:
If a document references, summarizes, or quotes CUI in any way, it becomes CUI. That’s why it’s often said that CUI is contagious.
CUI replaced older markings like For Official Use Only (FOUO) and Sensitive But Unclassified (SBU). If you still see those on legacy documents, treat the content as CUI and re-mark it under the current standard.
Every piece of CUI falls into one of two levels:
A complete marking has a banner across the top of the document and a designation indicator naming the office responsible for it. It may also carry limited dissemination controls that restrict who can receive it. Access stays limited to people with a lawful government purpose, meaning a real need tied to a contract or mission.
Marking happens at the point of creation. Whoever creates or generates the document is responsible for identifying it as CUI and applying the correct banner, which is why identification has to happen early rather than at audit time.
Misidentifying CUI isn’t a minor issue; it’s a compliance failure.
Knowing what counts as CUI is the first line of defense.
You don’t need a catalog memorized; you need awareness.
And step one: know whether you’re handling CUI in the first place.
Most contractors are surprised by how much CUI already exists in their systems.
Use our new quick-check tool to find out whether your organization is already handling CUI today:
You’ll learn:
Before you invest in remediation or policy updates, start with clarity.
No. Not all government data is CUI.
CUI is a specific subset of unclassified information that federal agencies designate as requiring protection under laws, regulations, or government-wide policies. Examples include technical data, export-controlled information, sensitive personnel information, and program-specific details.
Government data that is public, purely administrative, or not tied to a protected category is not CUI.
No. Labeling mistakes are common, and primes expect subcontractors to recognize CUI even when it arrives mislabeled or unlabeled.
Under DFARS 252.204-7012, subs must safeguard CUI whenever they receive or generate it — regardless of whether the prime marked it correctly.
If the content fits a CUI category (technical drawings, controlled technical information, sensitive program data, procurement-sensitive info), treat it as CUI and seek clarification if needed.
Yes. Drafts must be protected the same way as final documents if they contain CUI or reference it.
That includes emails, early versions of drawings, redlines, change orders, design iterations, lab notes, and working spreadsheets.
CUI doesn’t become “CUI” only when finalized, it’s CUI the moment it is created, transmitted, or stored.
FCI is information provided by or generated for the government under a contract and not meant for public release. It requires basic safeguarding under FAR 52.204-21.
CUI is more sensitive. It includes technical data, drawings, specifications, personnel information, supply chain details, and other categories governed by federal law or DoD marking rules. CUI requires full implementation of all 110 NIST SP 800-171 controls and often triggers CMMC Level 2.
Many contractors think they’re only handling FCI, but everyday files such as engineering snippets, subcontractor packages, HR data tied to programs or even change orders can contain CUI. Misclassification is one of the top reasons contractors fail assessments.