Articles

What Is CUI Anyway? Answering FAQs from Government Contractors

Answering frequently asked questions from government contractors around Controlled Unclassified Information (CUI).

  • Brooke Canova

    Content Marketing Manager

Managing sensitive data can be confusing, and questions about Controlled Unclassified Information (CUI) are the most common. The good news: CUI management becomes much more straightforward once you understand the fundamentals. 

In a recent webinar, C3 Chief Growth Officer Bill Wootton was joined by former Fathom Cyber CEO Jim Goepel (now Executive Vice President at Peak InfoSec) for a discussion around understanding CUI, and its role in CMMC compliance.

CUI is unclassified information the government creates or receives, which must be protected because a specific law, regulation, or policy requires it. The official CUI Registry, maintained by the National Archives and Records Administration (NARA), lists exactly what qualifies and how it should be managed. If your organization handles CUI, you’re required to follow National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171. This is the primary set of security requirements for most government contractors.  

A History of Information Protection and Sharing 

The CUI designation traces back to the aftermath of 9/11, when Congress established The National Commission on Terrorist Attacks Upon the United States (also known as the 9-11 Commission) to investigate why the attacks succeeded. The Commission found that federal agencies already had the information needed to stop the attackers but were unwilling to share it due to internal distrust and ‘stovepiping,’ which refers to the presentation of information without proper context.  

As a result, the goal shifted from a need-to-know mindset to promoting sharing of unclassified information among those authorized to access it. To do that, the government needed a new, unified way to handle sensitive information. Several reforms were introduced, culminating in 2010 when President Barack Obama’s Executive Order 13556 formally established the current CUI program, standardizing safeguarding and dissemination requirements across federal agencies and assigning NARA to lead its implementation. 

The CUI program required federal agencies to replace inconsistent legacy markings (such as FOUO, LES, and SBU) with a single, standardized system guided by laws, regulations, and governmentwide policies. As of 2025, over half of federal agencies haven’t yet fully adopted the CUI program. 

CUI, CMMC, and Government Contractors 

CUI, NIST 800-171, and CMMC 

For contractors that store, process or transmit CUI, the technical standard for securing CUI is NIST 800-171, which details the baseline set of technical and administrative security controls required to protect CUI, such as access controls, auditing, and incident response. 

Cybersecurity Maturity Model Certification (CMMC) Level 2 is built directly on NIST 800-171 Rev 2 and its companion publication, NIST SP 800-171A. The difference lies in CMMC’s structured evaluation model, which requires either a self-assessment or, more commonly, a certified third-party assessor organization (C3PAO) to evaluate both the implementation and consistency of these controls and requires documented evidence of ongoing compliance.​ 

CMMC Third-Party Validation 

The new CMMC framework mandates third-party assessments for contractors who touch CUI. Under this model, accredited independent assessors validate that a contractor’s controls not only exist but are effective and documented in practice. This external validation closes a long-standing accountability gap, requiring that suppliers can demonstrate true, continuous compliance, and that CUI is protected throughout the supply chain, not just on paper.​ 

In short, CMMC formalizes and validates the contractor’s responsibility to apply protections to all CUI, with independent verification serving as the “trust but verify” safeguard for the Department of War (DoW) and other government customers. 

Answers to Common CUI Questions

1. How do I know if the information I receive is CUI?

You can identify CUI if it is marked as such, either directly on the document or on the physical/digital container (such as a file cabinet or USB drive) in which the information is stored. In some cases, your contract, often through a Security Classification Guide (SCG), may state what information is to be treated as CUI.

2. What do I do if something looks like CUI but isn’t marked that way?

If you get government information that fits your understanding of CUI (for example, it looks sensitive, refers to a covered contract, or matches NARA’s CUI Registry), but it isn’t marked, don’t mark it as CUI on your own. That authority and responsibility lies solely with the government agency, or in some cases, a prime contractor with delegated authority.

Here’s what to do:

  • Seek agency confirmation. Promptly ask your government point of contact or contract representative to confirm if the information should be designated and marked as CUI.
  • Handle with caution. Don’t share the information internally or externally unless necessary and if you must, flag it for extra care.
  • Document your inquiry and actions. Keep a record of your inquiry (email, letter, or record in your file system) to show you acted diligently.
  • If you don’t get an answer within a reasonable time (typically five business days, unless your contract says otherwise), continue to handle the information cautiously.

3. Where can I find official guidance on marking CUI?

For full details on how to mark documents as Controlled Unclassified Information, refer to the

DoW marking guide or the NARA CUI Marking Handbook. Keep in mind that NARA lets individual agencies, like DoW, NASA, or others, create additional contract-specific or situation-specific marking rules.

4. How should I handle information I create as a contractor?

If your contract or SCG states your deliverable is CUI and your work fits those attributes, mark it as CUI before sharing it with anyone, whether internally, with a partner, or back to the government.

5. How do I protect proprietary information given to the government?

Mark the information as proprietary and, if applicable, add a cover letter requesting CUI designation.​

6. Are there concerns with using the term “confidential”?

Be careful about using the word “confidential,” as it has meaning in classified national security contexts, and misapplying it can cause confusion. Use “proprietary” or “sensitive” as appropriate and defer to agency guidance on official CUI terminology.

7. What do I do about copies and derivative works?

If you copy, extract, or summarize information that makes a document CUI, the new material also becomes CUI and must be marked and protected accordingly. This applies to all copies and derivative works for as long as they contain CUI content. However, if you only use non-sensitive, commercial details, such as a spec for a washer anyone can buy, the new document is not CUI just because the original was.

8. How can I verify that another individual or organization can appropriately handle CUI?

CUI can only be accessed by authorized holders: individuals or organizations with a lawful government purpose directly tied to contract performance, government direction, or a clearly legitimate federal purpose. Technical access is not enough: someone is only authorized if they need the CUI for their government contract work, support role, or official government duty.

To ensure only authorized holders gain access:

  • Use strict contracts, NDAs, and flow-down requirements to define who can access CUI and require reporting of any suspected unauthorized access.
  • Implement logical segmentation, strong authentication, role-based access, and clear separation between teams to prevent unnecessary CUI exposure.
  • Evaluate supply chain readiness by requesting CMMC assessments, SPRS scores, or other independent validation; questionnaires and self-attestation can help but are less reliable for higher risk work.
  • Protect physical CUI with locked storage, access-controlled rooms, visitor policies, and clean desk practices—supported by documented procedures for handling and destruction.
  • Log and review system access regularly, audit permissions, and ensure all CUI handlers are trained on responsibilities and incident response.
  • Require a contract-based justification for any access request and document each decision.

9. Does CUI have any limitations around only being handled by US citizens?

Some CUI data is subject to additional handling rules, most notably those subject to export controls like the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR). If the CUI includes export-controlled details or is marked with a limited dissemination control such as No Foreign (NOFORN), then only properly authorized individuals, usually US citizens with the appropriate clearance, can access it. Note that in many cases, export controlled data must also reside in the US.

In these cases, preventing access by non-US persons is a strict legal requirement.

10. Is contractor-generated information considered CUI, or is it just proprietary? How does this work?

Contractor-generated information, such as your company’s System Security Plan (SSP) or your employees’ Social Security numbers, is not considered CUI unless it was created specifically for, or on behalf of, the government under contract. Even if you maintain that data for business reasons, it remains proprietary, not CUI, as long as it is not required by contract deliverable or government submission. However, once you provide information to the DoW (such as the SSP) and it meets applicable government criteria, it may become CUI while in DoW’s possession.

11. What do I do if CUI is spilled or mishandled?

Right now, there’s no comprehensive, government-wide protocol for handling a CUI spill, meaning a situation where CUI is exposed or shared inappropriately. If you find yourself in this position, the best practice is to reach out immediately to your government point of contact or contracting officer, describe the situation as clearly as you can, and request direct guidance.

Many contracts or agency-specific requirements may call for some level of incident reporting or response, especially if mishandling triggers breach notification laws or falls under contract-specific information security clauses. For example, DFARS 252.204-7012 requires notification to the government within 72 hours of discovery of a breach. Always check your contract language and agency guidance for detailed guidance.

12. How should I approach scoping and boundaries?

  • Avoid the blanket assumption that all data is CUI.
  • Map out exactly how CUI flows through your organization, both in the physical world (like office space and access controls) and digitally (servers, networks, and apps).
  • Draw CMMC compliance boundaries around anything that stores, processes, or transits CUI.
  • If CUI is a small slice of your data, you may be able to keep it in dedicated folders or systems. If most of your contract work involves CUI, it is typically simpler to hold everything in that workspace to the stricter CUI standard.
  • Put up physical separations when needed, so your CUI areas aren’t mingling with public or general business information.
  • Minimize scope by avoiding mixing CUI into any non-essential environments.

13. What about treating all contract info, PII, and other data, as CUI?

Treating all contract-related information, personally identifiable information (PII), and similar records as CUI can help create a consistent compliance and security baseline. If your protections are commensurate with risk, erring on the side of caution is always a good thing in cybersecurity.​

14. Can you push back if you believe something is just FCI, not CUI?

It’s good practice to respond and ask for the law, regulation, or government-wide policy that makes the information CUI. Agencies and contracting officers must be able to point to a clear legal basis for the designation. If someone tries to argue that your proprietary data is CUI just because it’s in the contract, you can (and should) clarify that only the agency can make that call, and only with proper authority.

If you’re selling Commercial Off-The-Shelf (COTS) products and the letter or data in question contains only federal contract information (FCI), that just means it’s non-public, unclassified contract info. In such cases, you only have to comply with CMMC Level 1, which requires the 15 basic safeguarding requirements in Federal Acquisition Regulation (FAR) 52.204-21 and is much less burdensome than the CMMC Level 2 compliance required for CUI.​ That said, COTS products that require integration, configuration, custom software, or special services may still require CMMC Level 2, so be cautious.

15. What happens if requirements change how my product is made, tested, or documented?

If you create special testing, new paperwork, or custom specs for the government, err on the side of caution. Treat newly created, contract-specific information as CUI until the government says otherwise.

16. Why do primes and mid-tier suppliers only give me minimal details and slices of data?

Prime contractors and suppliers are supposed to give you only what you need. This keeps you from having more CUI than necessary, which reduces your compliance scope and liability. If you really need more CUI for your work, you probably have a lawful reason to receive it, and they can route it up for authorization.​

17. How do I avoid exposure when passing information along the supply chain?

Be careful not to pass along CUI unintentionally when you’re placing an order or interacting with suppliers. If you’re sharing drawings or details from bigger CUI-marked assemblies, those transmissions could trigger new CUI handling obligations for your supply chain partners.

Under Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7020, you’re required to validate the security of your supply chain. Regular due diligence requires you to know where your subs are on their CMMC journey.​ That means accumulating independent, objective references: validated SPRS scores CMMC certificates, assessment reports, or answers with documentary proof. This evidence shows your supply chain is genuinely compliant.

 

For a more in-depth discussion of this topic, watch the full webinar on demand.

 

Ready to Get Started?

C3 is a trusted CMMC readiness expert, providing guidance to the DIB for over 10 years. If you’re preparing for your own assessment, schedule a consultation today.  

Meet the Author

Brooke Canova

Content Marketing Manager