DFARS Readiness Checklists and guides for DFARS readiness.

Guides / October 09, 2026

What Is CUI and How Do I Know If I Have It?

You signed a defense contract and keep seeing the letters CUI. Nobody told you whether the files on your server count.

CUI stands for Controlled Unclassified Information. It is the most misunderstood label in defense contracting. This article explains what it means in plain words, and how you find out whether your company has any.

What does CUI actually mean?

CUI is government-created or owned information. It is unclassified. A law, regulation, or government-wide policy requires the government to protect it with safeguarding or dissemination controls. That definition comes from the National Archives rule that runs the CUI program. (32 CFR 2002.4)

Executive Order 13556 set up the program in 2010. Before that order, agencies used their own labels and their own rules. The order replaced that patchwork with one uniform system. (Executive Order 13556)

The order named the kinds of information agencies were already marking on their own. Privacy data, security information, proprietary business interests, and law enforcement investigations were on the list. CUI replaced old labels such as FOUO and SBU. FOUO stands for For Official Use Only. SBU stands for Sensitive But Unclassified. (DCSA CUI info sheet)

Is CUI the same as classified information?

No. CUI is never classified. Classified means Confidential, Secret, or Top Secret. Those markings come from a different order, Executive Order 13526. EO 13556 says classified information is excluded from the CUI program. (Executive Order 13556)

Mixing them up causes real trouble. People either underprotect CUI or overreact to it. Treat CUI as sensitive but unclassified. It needs real protection. It does not need a classified facility.

What kinds of information count as CUI?

The law decides, not you. Information becomes CUI only when a law, regulation, or government-wide policy says so. You cannot invent your own CUI category.

The approved categories live in one official list, the CUI Registry. It is run by NARA. NARA stands for the National Archives and Records Administration. The registry lists every approved category and subcategory. Agencies may use only those. (32 CFR 2002.12)

Common examples for contractors include export-controlled technical data and proprietary business information. Export control laws require protection for the first kind. Trade secret and commercial rules cover the second.

There are two flavors. CUI Basic is the subset where the underlying law sets no specific handling controls. You handle it under the uniform CUI rules. CUI Specified is the subset where the underlying law sets its own controls. Check the registry entry for your category to see which one applies. (32 CFR 2002.4)

How do I know if my company has CUI?

For defense contractors, the contract answers this. Check these signals in order.

First, look for DFARS (Defense Federal Acquisition Regulation Supplement) clause 252.204-7012 in your contract. That clause defines CDI (covered defense information). CDI is unclassified technical information or other information described in the CUI Registry that needs safeguarding controls. (DFARS 252.204-7012)

Information is CDI when the contract marks it as CUI and DoD gives it to you. DoD stands for the Department of Defense. Information you create, collect, or store while doing the contract work also counts. That covers drawings, test reports, process sheets, and code your team produces. (DFARS 252.204-7012)

Second, look at the documents you receive. For DoD work, CUI documents carry CUI at the top and bottom of each page. They also carry a designation indicator block on the first page or cover. That block names the controlling office, the category, and a point of contact. (DoD CUI marking training)

Third, check your contract data requirements list. Contractors call this the CDRL. CDRL stands for contract data requirements list. Each line item sits on a DD Form 1423. If a line item delivers technical data to DoD, expect it to be CUI or CDI. Check the statement of work too. That section describes what you must do under the contract.

Fourth, when in doubt, ask your contracting officer. Only the contracting officer can settle what your contract requires. Write your question down and keep the written answer. If you cannot get an answer fast, protect the data anyway. Treating it as CUI until told otherwise is the safer move. You can relax controls later. You cannot undo a disclosure.

What should I do first if I have CUI?

Do these three things in order.

One, find where it lives. List every system that stores, processes, or transmits CUI. Include laptops, shared drives, email, backups, and personal devices if they touch the work. You cannot protect what you have not found.

Two, protect it to the NIST SP 800-171 baseline. NIST stands for the National Institute of Standards and Technology. SP 800-171 is its guide for protecting CUI on nonfederal systems. DFARS 252.204-7012 names this guide as the minimum bar. (DFARS 252.204-7012) Write an SSP (system security plan) that lists your controls and your gaps.

Three, be ready to report a cyber incident. The clause requires reporting to DoD within 72 hours of discovery. "Rapidly" is defined that way in the clause text. (DFARS 252.204-7012) Set up your DoD-approved reporting access before you need it. Practice beats panic when the clock is running.

Sources

Next step

You now know how to tell whether you hold CUI.

See how PolicyCortex collects NIST 800-171 evidence from live Azure configuration, so your proof is ready when it is needed.