What is Controlled Unclassified Information (CUI)?
Lightbridge Cloud defines Controlled Unclassified Information, or CUI, as government-created or government-owned information that requires safeguarding or dissemination controls under law, regulation, or policy, yet is not classified. Established by Executive Order 13556 and governed by 32 CFR Part 2002, CUI is standardized across federal agencies through a single program the National Archives administers.
Controlled Unclassified Information is a single federal standard for sensitive-but-unclassified data.
Controlled Unclassified Information, abbreviated CUI, is information the federal government creates or possesses, or that an entity creates or possesses for the government, that a law, regulation, or government-wide policy requires to be safeguarded or to have its dissemination controlled. Crucially, CUI is not classified information: it sits below national security classification yet still demands consistent protection. The program exists to replace the patchwork of legacy labels such as For Official Use Only with one government-wide framework.
The legal foundation is clear. Executive Order 13556 established the CUI Program in 2010, and 32 CFR Part 2002 is the implementing regulation that binds executive branch agencies. The National Archives and Records Administration, NARA, is the designated executive agent that oversees the program and maintains its authoritative list of categories. Together these instruments turn a once-inconsistent practice into a documented standard that contractors and agencies can follow.
Lightbridge Cloud is an independent advisory firm, not a government authority. This guide describes the CUI program as the public record sets it out, so that organizations can orient themselves before mapping the requirements to their own systems. The controlling detail always lives in the official sources, and exact dates and program specifics should be verified against the NARA CUI Registry and the issuing agency.
CUI categories live in the NARA CUI Registry, grouped by organizational index.
The NARA CUI Registry is the public, authoritative catalog of approved CUI categories. Categories are arranged into organizational index groupings, and each carries the law, regulation, or policy that makes the information controlled. The groupings below are representative, not exhaustive: the Registry is the definitive list, and it is updated over time, so confirm any category against it directly.
Defense
Information tied to military operations, controlled technical information, naval nuclear propulsion, and unclassified controlled nuclear information. Defense contractors most often encounter CUI in this grouping when handling design data and technical specifications.
Export Control
Information governed by export regimes such as ITAR and the EAR. Export-controlled CUI carries its own statutory handling duties layered on top of the broader CUI program, so it is frequently marked as CUI Specified.
Financial and Procurement
Budget, contract, and source-selection information, along with procurement-sensitive material that must not be disclosed before or during an acquisition. This grouping overlaps with FAR and DFARS handling expectations for contractor systems.
Privacy
Personally identifiable information and related records that agencies and contractors must protect. Privacy CUI commonly intersects with separate privacy statutes that add specified controls beyond the CUI baseline.
Critical Infrastructure
Information about systems and assets whose disruption would harm security, the economy, or public health. Several subcategories here are CUI Specified, with safeguarding rules drawn from the underlying authorities.
Law Enforcement and Intelligence
Investigative records, certain intelligence-related material, and similar sensitive information. The NARA CUI Registry is the authoritative list of these and other organizational index groupings and their constituent categories.
CUI is handled as Basic or Specified, and it travels with its markings.
Every CUI category is one of two types, and the type determines which controls apply. Marking then carries that determination to every person and system that touches the information. Getting both right is the foundation of correct handling, and the precise rules are set by agency guidance and the NARA CUI Registry.
CUI Basic
The default level. When a law, regulation, or government-wide policy designates information as CUI but sets no specific handling controls, it is CUI Basic and follows the program baseline, including safeguarding aligned to NIST SP 800-171 on nonfederal systems.
CUI Specified
Applies when the underlying authority prescribes specific controls that differ from the baseline, for example tighter dissemination or marking rules. Specified categories require reading the cited authority, because its controls govern, not the general default.
Marking and dissemination
CUI is identified with a designation indicator and banner markings, optionally with category markings and limited dissemination controls. Markings tell every downstream handler what protections apply. Verify current marking conventions against the NARA CUI Registry and agency guidance.
Marking conventions, decontrol rules, and limited dissemination controls are periodically updated. Validate the current format against the NARA CUI Registry and the guidance issued by your contracting agency before you mark or transmit any document.
Safeguarding CUI on contractor systems maps to NIST 800-171, DFARS, and CMMC.
For organizations that handle CUI on nonfederal systems, the protection standard is NIST Special Publication 800-171. For defense contractors the obligation is contractual: DFARS clause 252.204-7012 requires safeguarding of covered defense information by implementing the NIST 800-171 security requirements, and the Cybersecurity Maturity Model Certification, CMMC, is the framework the Department of Defense uses to verify those protections. The logic is straightforward: CUI says what to protect, NIST 800-171 says how, and CMMC verifies it.
These pieces fit together as one readiness program. The Lightbridge Cloud guide to DFARS and NIST 800-171 walks through the safeguarding requirements and how to assess against them, and CMMC compliance covers the path to assessment readiness. Clause numbers, control counts, assessment levels, and implementation timelines do change, so verify the current specifics against acquisition.gov, the DoD CIO, NIST, and DCSA before you commit to a plan.
CUI obligations flow down the federal supply chain to contractors and subcontractors.
Federal agencies are required to run the CUI Program, and the duty to handle CUI correctly extends to any organization that receives, creates, stores, or transmits it for the government. In practice that obligation arrives through contract clauses and flows down: a prime contractor passes the requirement to subcontractors and suppliers, and each one that touches CUI carries the same handling responsibility. Export-controlled CUI adds another layer, because regimes such as ITAR and the EAR impose statutory duties enforced by DDTC and BIS.
The exact scope of an organization's obligations depends on its contracts and the agencies involved, so the controlling clauses and the contracting officer determine what applies. Lightbridge Cloud helps organizations map where CUI actually lives across their environment, which is the first practical step before any safeguarding work begins.
Lightbridge Cloud builds CUI handling readiness as an independent advisor.
Lightbridge Cloud is an independent, vendor-neutral advisory firm. It helps organizations identify where CUI resides in their cloud and on-premises environments, map handling and safeguarding requirements to NIST SP 800-171, and prepare for CMMC assessment. Every engagement is framed as readiness and advisory work. Lightbridge Cloud does not issue certifications, is not a CMMC assessor, and is not FedRAMP authorized: it prepares organizations to meet the bar that authorized bodies enforce.
Because the CUI program is set by federal authorities that revise their guidance over time, Lightbridge Cloud ties recommendations back to the official record, including the NARA CUI Registry, acquisition.gov, the DoD CIO, NIST, DCSA, and the export-control authorities at DDTC and BIS. To start, the DFARS and NIST 800-171 guide and the CMMC compliance page set out the readiness path in detail.
This guide is general information, not legal, audit, or accounting advice. CUI categories, marking conventions, regulatory citations, and compliance timelines change over time. Verify the current requirements against the official sources, including the NARA CUI Registry, 32 CFR Part 2002, acquisition.gov, the DoD CIO, NIST, DCSA, and the export-control authorities at DDTC and BIS, and consult qualified counsel for your specific obligations.
Product and program names referenced here, including any vendor cloud platforms, are trademarks of their respective owners. Reference to them does not imply any partnership with or endorsement by those owners or any government agency.
Controlled Unclassified Information: frequently asked questions
- What is Controlled Unclassified Information (CUI) in simple terms?
- Controlled Unclassified Information is sensitive information the federal government creates or owns that must be protected or have its sharing restricted under a law, regulation, or government-wide policy, but that does not meet the bar for national security classification. Executive Order 13556 created the CUI Program in 2010 to replace a sprawl of agency-specific labels with one standard, and 32 CFR Part 2002 sets the governing rules. The National Archives and Records Administration is the executive agent. Lightbridge Cloud is an independent advisory firm that helps organizations build readiness to handle CUI correctly; it does not classify your data for you or replace official guidance.
- Who governs CUI and where do the categories come from?
- The CUI Program was established by Executive Order 13556 and is implemented through 32 CFR Part 2002. The National Archives and Records Administration, NARA, serves as the executive agent and publishes the NARA CUI Registry, which is the authoritative, public list of approved CUI categories grouped into organizational index groupings such as Defense, Privacy, and Export Control. Because categories and their controls can change, the live NARA CUI Registry is the source of truth rather than any third-party summary. Lightbridge Cloud always points clients back to the Registry and agency direction for the controlling detail.
- What is the difference between CUI Basic and CUI Specified?
- CUI Basic is the default category type: the underlying law, regulation, or government-wide policy says the information is controlled but does not spell out specific safeguarding or dissemination rules, so it follows the CUI Program baseline. CUI Specified applies when the underlying authority does prescribe particular controls, such as stricter dissemination limits or specific marking, that differ from the baseline. For Specified information, those authority-defined controls govern. The practical rule is to read the cited authority for any category marked Specified, and to verify the classification against the NARA CUI Registry and the relevant agency.
- How is CUI marked?
- CUI is identified through markings so that anyone who later handles it knows what protections apply. A document typically carries a CUI banner marking at the top, a designation indicator that records who designated it and under what authority, and optionally a category marking and any limited dissemination control markings. The point of marking is consistency: the controls travel with the information. Exact marking conventions are set out in agency guidance and the NARA CUI Registry, and they are periodically updated, so confirm the current format against the official Registry and your contracting agency before applying markings.
- How does CUI relate to DFARS, NIST 800-171, and CMMC?
- For defense contractors the chain is direct. DFARS clause 252.204-7012 requires safeguarding of covered defense information on contractor systems by implementing the security requirements in NIST SP 800-171, and the Cybersecurity Maturity Model Certification, CMMC, is the framework the Department of Defense uses to verify that those protections are in place. In short, CUI defines what must be protected, NIST 800-171 defines how, and CMMC verifies it. See the Lightbridge Cloud guides on DFARS and NIST 800-171 and CMMC compliance for the readiness path. Specific clause numbers, control counts, and timelines change, so confirm them against acquisition.gov and the DoD CIO before relying on them.
- Who has to comply with CUI requirements?
- Federal agencies must run the CUI Program, and any organization that receives, creates, stores, or transmits CUI on the government's behalf inherits handling obligations, usually through contract clauses. That includes prime contractors, subcontractors, suppliers, and research institutions across defense and civilian agencies. Obligations flow down the supply chain, so a subcontractor that touches CUI carries the same handling duty as the prime. Because the exact requirements depend on your contracts and the agencies involved, validate scope against your contracting officer and the controlling clauses rather than assuming.
- How does Lightbridge Cloud help with CUI readiness?
- Lightbridge Cloud is an independent, vendor-neutral advisory firm. It helps organizations scope where CUI lives in their environment, map handling and safeguarding requirements to NIST SP 800-171, and prepare for CMMC assessment, all framed as readiness rather than a certification we issue. Lightbridge Cloud is not a CMMC certifier and is not FedRAMP authorized; it advises and prepares. Because the CUI program is governed by federal authorities that update their guidance, recommendations are always tied back to official sources including the NARA CUI Registry, acquisition.gov, the DoD CIO, NIST, DCSA, and the export-control authorities at DDTC and BIS.
From understanding CUI to handling it correctly.
When the question shifts from what CUI is to how your organization protects it, Lightbridge Cloud maps your requirements to NIST 800-171 and prepares you for CMMC assessment as an independent advisor.