Skip to content

How to Find Your CUI: Why “I Don’t Think We Have Much” Is Usually Wrong

Listen: How to Find Your CUI: Why “I Don’t Think We Have Much” Is Usually Wrong
7:10

Executive Brief

“We don’t think we handle much Controlled Unclassified Information (CUI).” It’s one of the most common things we hear from defense contractors, and it’s usually a misconception.

CUI doesn’t announce itself. It shows up in places contractors don’t expect, often mixed in with data nobody flagged as sensitive.

  • Most organizations underestimate where CUI lives across their environment
  • CUI hides in unmarked files, shared drives, and everyday business records, not just technical data
  • Your CUI footprint determines your Cybersecurity Maturity Model Certification (CMMC) assessment scope, so missed CUI means expanded scope or a failed assessment
  • Assessors are trained to find what a rushed internal review miss
  • Contract requirements to protect CUI apply even if you haven't handled a single CUI document yet

Dig deeper below to learn more.


Why “We Don’t Have Much” Is a Risky Assumption

This assumption is common, and it usually comes from good intentions rather than carelessness. Most organizations simply haven’t looked closely enough yet.

  • Contract language often uses general terms like “technical data” or “contract deliverables” instead of explicitly saying “CUI”
  • Teams often assume only engineering or program teams touch sensitive data
  • CUI status is defined by the government and your contract, not by whether your team labeled something sensitive
  • Once CUI enters your environment, it can spread through email, shared drives, and everyday collaboration without anyone noticing

The result: organizations scope their environment based on where they assume CUI lives, not the systems or people it currently flows through.

Where CUI Actually Hides

CUI shows up well beyond the files people expect. Common places include:

  • Technical drawings, specifications, and engineering data
  • Statements of work, contract deliverables, and program schedules
  • Test reports, maintenance manuals, and quality records
  • Export-controlled technical data shared with subcontractors or partners
  • Personnel information tied to specific contract performance
  • Financial data and invoices connected to a covered contract
  • Email threads and attachments discussing any of the above

If you want a deeper breakdown of what qualifies, see our related post: CUI Identification: What Actually Counts as Controlled Unclassified Information.

Common Blind Spots

Even organizations that have done some CUI mappings tend to miss the same handful of places:

  • Shared drives and email attachments that were never re-reviewed after a project ended
  • Legacy systems and archived project folders from closed-out contracts
  • Subcontractor and vendor exchanges, especially over unmanaged channels
  • Personal devices or unsanctioned tools used for convenience such as USB drives, external hard drives, and possibly CDs/other removable media
  • Printed documents, physical files, and offsite storage
  • Helpdesk tickets and IT support attachments

Any one of these can put CUI outside your defined boundary without anyone realizing it.

How to Actually Find Your CUI

Finding your CUI is a process, not a one-time checklist. Here’s where to start:

Start with your contracts, not your IT environment

  • Review contract clauses, including those tied to DFARS 252.204-7012, for language pointing to sensitive data
  • Talk to your contracts and program management teams about what each contract requires you to produce, store, or exchange

Map how data moves

  • Identify where CUI enters your environment, including email, portals, and contract deliverables
  • Track where it moves, including file shares, laptops, and cloud storage
  • Confirm where it leaves, including exchanges with subcontractors or delivery to the government
  • Build a data flow diagram detailed enough to trace CUI from where it enters to where it leaves; this is often the clearest way to see the full picture

Talk to the people doing the work

  • Engineers, program managers, and contracts staff often know where sensitive data lives even when it isn’t documented anywhere
  • A quick conversation frequently surfaces more than a document review does

Look beyond the obvious departments

  • Human Resources, finance, and quality assurance can all touch CUI without realizing it
  • Don’t limit your review to IT and engineering alone

Document what you find

  • Your findings become the foundation of your CMMC scope and your System Security Plan (SSP)
  • Treat this as a living record, not a one-time exercise

Why Getting This Right Matters

Your CUI footprint sets the boundary for your CMMC Level 2 assessment. If that boundary is wrong, everything built on top of it is at risk.

  • Under-scoping can leave CUI outside your protected environment, which assessors are trained to look for
  • Over-scoping can add unnecessary cost and complexity to systems that never needed to be in scope for third-party and self-assessments
  • Your scope directly shapes what goes into your SSP, and an inaccurate SSP creates downstream risk

ISI Insight: Treat CUI discovery as an ongoing conversation across departments, not a one-time survey. New contracts, new tools, and new subcontractor relationships can all introduce CUI you haven’t accounted for yet. 

For more on what a strong SSP should include once your scope is defined, see:

And for how documented gaps factor into your assessment outcome:

A Simple Way to Start

If a full scoping exercise feels like a lot to take on right away, start small:

  • Ask each department head one question: “What information do we handle that’s tied to a government contract?”
  • Take our quick self-check to see whether your organization may already handle CUI:
  • Do You Handle CUI? Take the 2-Minute Quiz
  • Use the answers as a starting point for a more formal scoping conversation with your compliance team

FAQs

We’ve never handled classified information. Could we still have CUI?

Yes. CUI is unclassified by definition. It includes categories like export-controlled technical data, certain personnel information, and other sensitive but unclassified data tied to a covered contract. Many organizations that have never touched classified systems still handle CUI.

Who is responsible for figuring out where our CUI lives?

It’s a shared responsibility. IT can’t identify CUI on its own because much of it lives in business processes, not just systems. Contracts, program management, HR, and finance teams all need to be part of the conversation. For more on how responsibility is typically divided, see: Who Is Responsible for Protecting CUI?

How often should we revisit our CUI scope?

Treat it as an ongoing process rather than a one-time project. New contracts, new subcontractor relationships, and new tools can all introduce CUI into your environment. Many organizations revisit scope whenever a new contract is signed and at least once a year otherwise.


 Helpful ISI Links

Related Posts