Controlled unclassified information is the category of federal information that is not classified but that a law, regulation or government-wide policy requires or permits an agency to protect — and it is the reason NIST SP 800-171 exists. The definition is in 32 CFR Part 2002, the rule the National Archives issued as CUI Executive Agent under Executive Order 13556; the categories are in the CUI Registry, which lists more than 120 of them across some twenty index groupings; and the obligation for contractors comes when an agency shares the information under a contract that carries the safeguarding requirements.
Most CUI confusion is scoping confusion: what counts, who decides, how it is marked, and where it stops. This guide answers those questions from the regulation — the definition and what it excludes, CUI Basic versus CUI Specified, the marking rules, the safeguarding and dissemination standards, decontrol, and how the defense-contracting terms (covered defense information, controlled technical information) map onto the CUI framework.

What controlled unclassified information is — and is not
32 CFR 2002.4 defines CUI as “information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls.” Three exclusions follow from the same definition and settle most scoping arguments.
| Is it CUI? | Rule | Example |
|---|---|---|
| Classified information | No — classified national security information is governed by EO 13526, not the CUI program | A SECRET technical report |
| Information in your own systems that did not come from, and was not created for, the government | No — the definition excludes information a non-executive-branch entity ‘possesses and maintains in its own systems’ on its own account | Your commercial product designs, HR records, financials |
| Information the government shares with you that a law or policy says to protect | Yes — CUI, in the category the designating agency assigns | Export-controlled technical data; a contractor’s deliverable drawings marked CUI//SP-CTI |
| Information you create for the government under contract that meets a category | Yes — ‘creates or possesses for or on behalf of the Government’ | Test results produced under a DoD contract that fall within Controlled Technical Information |
| Information an agency merely marks ‘for official use only’ without a Registry category | Not properly CUI — legacy markings are discontinued under § 2002.20, and only Registry markings designate CUI | An old FOUO stamp on a routine email |
CUI Basic and CUI Specified
Every category in the Registry is one or the other. CUI Basic is “the subset of CUI for which the authorizing law, regulation, or Government-wide policy does not set out specific handling or dissemination controls”; it is handled under the uniform rules in Part 2002 and the Registry. CUI Specified is the subset where the underlying authority “contains specific handling controls that it requires or permits agencies to use that differ from those for CUI Basic” — export-controlled information under ITAR and EAR is the common example, and its controls may be more stringent than Basic or simply different.
The marking tells you which: a Specified category is marked with “SP-” before the category abbreviation. For safeguarding on systems the floor is the same: § 2002.14(g) requires CUI Basic to be categorized at no less than the moderate confidentiality impact level under FIPS 199, and agencies apply FIPS 200 and SP 800-53 controls accordingly — which is where the SP 800-53 moderate baseline, tailored, becomes NIST SP 800-171 for nonfederal systems.
Marking controlled unclassified information
| Marking element | Rule (32 CFR 2002.20) | Example |
|---|---|---|
| Control marking (mandatory) | The word CONTROLLED or the acronym CUI, at the designator’s discretion; agency policy may require one or the other | CUI |
| Category marking | Category or subcategory markings from the Registry; required for CUI Specified, and for CUI Basic where agency policy requires | CUI//SP-CTI (Controlled Technical Information, a Specified category) |
| Limited dissemination control marking | Aligns with a limited dissemination control approved by the CUI Executive Agent; applied under agency policy | CUI//SP-CTI//NOFORN |
| Portion marking | Agencies are permitted and encouraged to portion mark; the portion control marking must be the acronym CUI, with category and LDC markings as approved | (CUI//SP-CTI) at the start of a paragraph |
| Legacy markings | Discontinued — only markings in the Registry may designate CUI | FOUO, SBU, LES no longer designate CUI |
| Designation indicator (mandatory) | Every document containing CUI carries an indicator of who designated it — at minimum the agency — readily apparent, on the first page or cover at least; a decontrolling date or event is included where feasible | ‘Controlled by: Division 5, Department of Good Works’ — the rule’s own example |
The designator marks; the authorized holder — including a contractor — keeps the markings in place, carries them onto documents it creates that contain the CUI, uses only Registry markings, and must not apply CUI markings to information that does not qualify, which Part 2002 lists as a form of misuse. Agencies are required to give authorized holders a contact for instructions when information arrives unmarked or improperly marked — use it.
Safeguarding, dissemination and decontrol
- Safeguarding (§ 2002.14). Authorized holders “must take reasonable precautions to guard against unauthorized disclosure”, including controlled environments, ensuring unauthorized individuals cannot access or observe CUI or overhear conversations, and keeping CUI under direct control or behind at least one physical barrier. On systems, the moderate confidentiality floor applies, and for nonfederal systems the requirements are those of SP 800-171.
- Access and dissemination (§ 2002.16). Agencies should permit access where it furthers a lawful government purpose, abides by the category’s authority and is not restricted by a limited dissemination control. Dissemination controls are to be imposed “judiciously”.
- Decontrol (§ 2002.18). Agencies should decontrol “as soon as practicable” once the information no longer requires protection; decontrol can be automatic — on public release, on a date or event the designator set — or by decision. A contractor does not decontrol; it asks the designating agency.
- Destruction. CUI is destroyed to a degree that makes it unreadable, indecipherable and irrecoverable, using the standards the Registry points to.
Controlled unclassified information in defense contracts
| Term | Where it lives | Relationship to CUI |
|---|---|---|
| Controlled Technical Information (CTI) | CUI Registry, Defense grouping; DFARS 252.204-7012 definition | A CUI Specified category — technical information with military or space application marked with a distribution statement |
| Covered defense information (CDI) | DFARS 252.204-7012 | Unclassified CTI or other information described in the Registry that is marked or identified in the contract and provided to or developed by the contractor for the contract — DoD’s contractual term for the CUI the clause protects |
| Federal contract information (FCI) | FAR 52.204-21 | Not CUI — information not intended for public release, provided or generated under contract; protected by 15 basic safeguards |
| DoD CUI policy | DoDI 5200.48 | How DoD components designate, mark and handle CUI under Part 2002 |
The practical scoping question is which systems process, store or transmit the CDI and which protect them; our guide to CMMC scoping applies the asset categories, and CMMC vs NIST 800-171 covers how the assessment layers on the standard.
A CUI identification routine for contractors
- Read the contract for the information it names. DFARS 7012 contracts identify CDI; civilian agreements name the categories. If nothing is named and nothing arrives marked, ask the contracting officer in writing rather than assuming.
- Inventory what arrives and what you create. Marked documents, data feeds and deliverables you produce that meet a category — the second is the one organizations miss.
- Classify by category and Basic/Specified. The Registry entry gives the authority, the marking and any Specified handling rules.
- Draw the boundary. The systems and people that touch CUI are in scope for SP 800-171; everything else is out, if the segmentation holds.
- Train the handlers. Carrying markings onto new documents, not removing markings, not applying markings to non-CUI, and the physical-barrier rule.
- Record designation and decontrol decisions. Who marked it, under which category, and when the designator said it may be decontrolled.
Frequently asked questions
What is controlled unclassified information?
Information the government creates or possesses, or that an entity creates or possesses for the government, that a law, regulation or government-wide policy requires or permits an agency to protect with safeguarding or dissemination controls — defined in 32 CFR 2002.4, with the categories listed in the CUI Registry.
Is my company’s own data CUI?
No. Information a non-federal entity possesses in its own systems that did not come from, and was not created for, the government is excluded by the definition. CUI is the government’s information in your hands.
What is the difference between CUI Basic and CUI Specified?
Basic categories have no specific handling rules in their underlying authority and use Part 2002’s uniform controls; Specified categories have handling rules the authority itself sets, which may be stricter or different, and are marked with SP-.
Who marks CUI?
The designating agency. Authorized holders, including contractors, keep the markings, carry them onto documents they create that contain the CUI, and may not apply CUI markings to information that does not qualify.
Which security standard applies to CUI on contractor systems?
NIST SP 800-171, derived from the SP 800-53 moderate baseline that Part 2002 sets as the floor for CUI Basic. DoD contracts apply Revision 2 through DFARS 252.204-7012 and CMMC.
Where this leaves you
Scope controlled unclassified information from the definition outward: government information a law or policy protects, in a Registry category, marked by the designating agency, excluding your own commercial data and anything classified. Identify what arrives and what you create, draw the system boundary around it, and protect it to SP 800-171 — because the moderate confidentiality floor in Part 2002 is where the 110 requirements come from.
References
- 32 CFR Part 2002 — Controlled Unclassified Information (eCFR) — The CUI rule: definitions (§ 2002.4), safeguarding (§ 2002.14), access and dissemination (§ 2002.16), decontrol (§ 2002.18), marking (§ 2002.20).
- NARA CUI Registry — categories list — The approved categories by index grouping, with markings and authorities.
- NIST SP 800-171 Rev. 3 — The security requirements for CUI in nonfederal systems.
More on NIST SP 800-171
- Controlled unclassified information — you are here
- NIST SP 800-171: the complete guide
- CMMC scoping: what is in the assessment
- CMMC vs NIST 800-171
- NIST 800-171 Rev 3 vs Rev 2
- NIST 800-171A: the assessment objectives
The CUI identification and scoping workbook, the CUI handling and marking procedure, the System Security Plan and the control-family policies are in the NIST SP 800-171 CUI Protection Toolkit, or start with the free templates.