CUI Identification: What Actually Counts as Controlled Unclassified Information
Executive Brief
Most defense contractors handle Controlled Unclassified Information (CUI) more often than they realize.
CUI hides in emails, HR files, project folders, supplier documents, and even meeting notes. Overlooking it is one of the fastest ways to fail a Cybersecurity Maturity Model Certification (CMMC).
The challenge isn’t just protecting CUI. It’s identifying it correctly. If you can’t spot it, you can’t secure it or track all the places it moves through such as email, shared drives, vendor portals, contract files, engineering tools, and everyday collaboration systems.
This guide breaks down what actually counts as CUI, addresses common blind spots auditors look for, and provides examples for contractors with questions. Start with a quick self-check: Take the 2-minute CUI Identification Quiz.
Why CUI Identification Is Difficult
CUI isn’t always stamped, labeled, or obvious. And many teams assume that if they don’t work with “classified” data, they don’t work with CUI.
Reality check:
- CUI is everywhere — supply chain files, HR paperwork, technical data, procurement documents, emails.
- It’s often created accidentally — copying, forwarding, or referencing controlled content makes the new document CUI.
- It flows down from primes — your subcontract may not say “CUI,” but the obligation still applies: DFARS 252.204-7012 requires primes to pass CUI protection, incident reporting, and cybersecurity requirements to any subcontractor that handles the information. Check ISI's Prime Tracker to see what major primes like Boeing, Lockheed, and RTX are telling their supply chains about their CUI handling obligations under CMMC.
- Misidentifying CUI leads to mishandling — and that creates real consequences: assessment findings, contract risk, financial penalties, or reputational damage.
Before you can protect CUI, you must recognize it.
Examples of Controlled Unclassified Information
The table below connects the CUI categories contractors deal with most often to the documents they show up in. If a file fits one of these, treat it as CUI, even when no one marked it that way.
| CUI Category | What it looks like in your environment |
| Controlled Technical Information (CTI) | Engineering drawings Schematics CAD files Test results Specs for Department of Defense systems |
| Export-Controlled Information (ITAR / EAR) | Technical data covered by International Traffic in Arms Regulations or Export Administration Regulations, including anything a prime shares under a controlled program |
| Proprietary Business Information (PBI, CBI) | Non-public pricing, bids Supplier data packages Trade-secret material exchanged under contract |
| Privacy Information (PII and SPII) | Staff records carrying Personally Identifiable Information or Sensitive Personally Identifiable Information, such as: Badge lists Clearance records Social Security numbers Medical or financial details |
| Financial Records | Contract cost data Non-public invoices Pricing tied to government deliverables |
| Legal Documents | Litigation holds, privileged contract correspondence, and other legal material tied to a program |
| Law Enforcement Sensitive (LES) | Investigation files or security-incident records connected to a contract or facility |
| Procurement and Contract Information | Statements of Work, performance reports, and non-public deliverables the government hasn’t released |
| System, Network, and Facility Details | Network diagrams Security configurations Physical security layouts Access logs tied to defense work |
Remember: copying or forwarding controlled content makes the new file CUI, and a draft counts the moment it references controlled material rather than when it is finalized. Flow-down trips up subcontractors most: under DFARS 252.204-7012, a prime must pass CUI protection and reporting requirements to any subcontractor that stores, processes, or transmits the information, even when the subcontract never uses the word CUI.
Who Defines CUI
CUI isn’t a label any agency invents on its own. It comes from Executive Order 13556, signed in 2010, which replaced a patchwork of agency-specific rules with one government-wide standard for protecting sensitive unclassified information.
The National Archives and Records Administration (NARA) runs the program as its Executive Agent. NARA maintains the CUI Registry, the official catalog of every approved CUI category and the law or policy behind it. 32 CFR Part 2002 is the implementing regulation.
The Department of Defense applies these rules through DoD Instruction 5200.48. For contractors, that instruction is where CUI meets CMMC compliance and the safeguarding requirements in DFARS 252.204-7012. When you need to confirm whether something qualifies, consult the National Archives CUI Registry as the authoritative source; don’t rely on a prime's habit or an internal assumption.
Where Teams Miss CUI Most Often
Auditors consistently flag the same blind spots:
- Email threads
- Shared drives with mixed access
- File shares copied into SharePoint or Teams
- Slide decks built for internal updates
- Unlabeled drafts or working documents
- Invoices, purchase orders, or shipping docs
If a document references, summarizes, or quotes CUI in any way, it becomes CUI. That’s why it’s often said that CUI is contagious.
How CUI Is Marked: Basic vs. Specified
CUI replaced older markings like For Official Use Only (FOUO) and Sensitive But Unclassified (SBU). If you still see those on legacy documents, treat the content as CUI and re-mark it under the current standard.
Every piece of CUI falls into one of two levels:
- CUI Basic is the default. It covers most controlled information and follows the baseline safeguarding rules in 32 CFR 2002 and NIST SP 800-171. A Basic document carries a simple banner marking that reads CUI.
- CUI Specified applies when the underlying law or policy sets stricter handling or dissemination rules. Controlled Technical Information and some export-controlled data fall here. A Specified document carries category markings in its banner, such as CUI//SP-CTI, so handlers know the extra controls apply.
A complete marking has a banner across the top of the document and a designation indicator naming the office responsible for it. It may also carry limited dissemination controls that restrict who can receive it. Access stays limited to people with a lawful government purpose, meaning a real need tied to a contract or mission.
Marking happens at the point of creation. Whoever creates or generates the document is responsible for identifying it as CUI and applying the correct banner, which is why identification has to happen early rather than at audit time.
The Risks of Getting It Wrong
Misidentifying CUI isn’t a minor issue; it’s a compliance failure.
- Failed assessments - Certified Third-Party Assessment Organizations (C3PAO) and Defense Industrial Base Cybersecurity Assessment Center (DBCAC) expect clear boundaries, consistent labeling, and documented control.
- Lost and delayed contracts - Primes increasingly ask subs to show proof of CUI handling controls before onboarding.
- False Claims Act exposure (FCA) - Mishandling CUI while asserting compliance in your System Security Plan (SSP) or SPRS score can trigger FCA scrutiny.
- Uncontained data spread - Once CUI leaks into emails, shared folders, or personal drives, containment is difficult and expensive.
Knowing what counts as CUI is the first line of defense.
How to Get Better at CUI Identification
You don’t need a catalog memorized; you need awareness.
- Train teams on CUI categories and examples
- Use metadata tagging and sensitivity labels
- Maintain a contract-specific CUI registry
- Review system boundaries and access controls
- Label at the earliest possible point of creation
- Encourage teams to ask, not assume
And step one: know whether you’re handling CUI in the first place.
Start with a 2-Minute Check
Most contractors are surprised by how much CUI already exists in their systems.
Use our new quick-check tool to find out whether your organization is already handling CUI today:
You’ll learn:
- Whether your organization likely handles CUI
- Where it may already live
- What to do next to protect it
- Whether you need to update your SSP, boundaries, or controls
Before you invest in remediation or policy updates, start with clarity.
FAQs
Does all government data count as CUI?
No. Not all government data is CUI.
CUI is a specific subset of unclassified information that federal agencies designate as requiring protection under laws, regulations, or government-wide policies. Examples include technical data, export-controlled information, sensitive personnel information, and program-specific details.
Government data that is public, purely administrative, or not tied to a protected category is not CUI.
If a prime doesn’t label data as CUI, is it safe to treat it as unrestricted?
No. Labeling mistakes are common, and primes expect subcontractors to recognize CUI even when it arrives mislabeled or unlabeled.
Under DFARS 252.204-7012, subs must safeguard CUI whenever they receive or generate it — regardless of whether the prime marked it correctly.
If the content fits a CUI category (technical drawings, controlled technical information, sensitive program data, procurement-sensitive info), treat it as CUI and seek clarification if needed.
Do drafts count as CUI?
Yes. Drafts must be protected the same way as final documents if they contain CUI or reference it.
That includes emails, early versions of drawings, redlines, change orders, design iterations, lab notes, and working spreadsheets.
CUI doesn’t become “CUI” only when finalized, it’s CUI the moment it is created, transmitted, or stored.
What’s the difference between Federal Contract Information (FCI) and CUI?
FCI is information provided by or generated for the government under a contract and not meant for public release. It requires basic safeguarding under FAR 52.204-21.
CUI is more sensitive. It includes technical data, drawings, specifications, personnel information, supply chain details, and other categories governed by federal law or DoD marking rules. CUI requires full implementation of all 110 NIST SP 800-171 controls and often triggers CMMC Level 2.
Many contractors think they’re only handling FCI, but everyday files such as engineering snippets, subcontractor packages, HR data tied to programs or even change orders can contain CUI. Misclassification is one of the top reasons contractors fail assessments.



