What Is CUI? A Plain-English Guide for Contractors 

If you do business with the government, or you’re hoping to, you’ve probably run into the term CUI. Controlled Unclassified Information (CUI) sounds like the kind of phrase that belongs in a legal footnote. In practice, it’s something every contractor working toward CMMC needs to understand, because it determines what data you’re allowed to touch, how you’re required to protect it, and whether you’re even eligible to bid on certain contracts.

Our Senior Cybersecurity Analyst, David Stuttard, walked through the basics in a short video [insert hyperlink or embed video]. This piece builds on that foundation with more context on where CUI came from, what it looks like when you encounter it, and what your organization needs to do about it.

What is CUI?

The government’s definition, straight from 32 CFR Part 2002, is dense: CUI is information the government creates or possesses, or that a contractor creates or possesses on the government’s behalf, that a law, regulation, or government-wide policy requires to be safeguarded.
Here’s the shorter version. CUI is any information the government says is CUI. That’s not a dodge. It’s the actual test. There’s no independent judgment call your team gets to make about whether a piece of data feels sensitive. If an agency has designated it CUI, it’s CUI, and it comes with obligations.

Where the Term CUI Came From

The label itself is relatively young. Before 2010, different agencies used their own shorthand for sensitive-but-not-classified information: FOUO (For Official Use Only), SBU (Sensitive But Unclassified), LES (Law Enforcement Sensitive), and others. Every agency had its own system, which made interagency work and contractor compliance a mess of overlapping, inconsistent rules.

Executive Order 13556, signed in 2010, consolidated all of that under one name: Controlled Unclassified Information. One label, one framework, applied government-wide. It’s taken over a decade for the requirements built on top of that order to fully reach contractors, which is part of why CUI and CMMC are only now becoming a front-and-center issue for small and mid-sized businesses.

Why CUI Exists Between “Public” and “Classified”

CUI sits in a middle tier. It’s not classified. A single piece of CUI, on its own, usually isn’t damaging. The concern is aggregation. David’s example in the video is a good one: a government order for 500 chairs shipped to a specific location in the desert doesn’t mean much by itself. But if an adversary collects enough of those small, unclassified data points, they can piece together a much bigger picture, like the existence of a new base.

That’s the logic behind CUI. It’s information ordinary businesses need to be able to handle and share in the course of doing government work, but it still warrants a defined layer of protection so that individually harmless data can’t be added up to something more meaningful.

Identifying CUI in Documentation

In practice, CUI shows up marked. You’ll see it in email headers and footers, and more importantly, in a designation indicator block, usually at the bottom of a document. That block tells you:

  • What category of CUI you’re dealing with
  • Which agency created or controls it
  • Who to contact with questions
  • Whether any dissemination restrictions apply, such as no foreign nationals

That last point matters more than it might seem. A dissemination restriction can apply even to employees who are lawfully present and working in the U.S. but hold citizenship elsewhere. A green card holder or dual citizen might be fully authorized to work on a contract generally and still be restricted from a specific piece of CUI marked with a no-foreign-dissemination control.

How to Know What Category of CUI You’re Dealing With

The National Archives (NARA) maintains the official CUI Registry, built from questionnaires sent to every federal agency asking what kinds of sensitive information they handle. If you search the registry for a category, like NNPI (Naval Nuclear Propulsion Information), you’ll get the specifics on what that category covers and who controls it.

One thing that trips people up: some CUI categories overlap with information you might not think of as government-controlled at all, like Social Security numbers or birth dates. That data can be classified as CUI depending on the contract. A defense contractor’s employee working on a submarine program is a good example. Their personal information may be treated as CUI in that context, even though the same data type wouldn’t be CUI in a different setting.

Where CMMC Fits Into the CUI Conversation

CUI tells you what data requires protection. CMMC (Cybersecurity Maturity Model Certification) is the framework that verifies your organization is capable of protecting it.

CMMC requirements for CUI are built on NIST Special Publication 800-171, a set of 110 security controls spanning IT, physical security, and personnel practices.

These controls exist so the government has confidence that handing your organization CUI won’t turn into a breach and, by extension, a national security problem.

A Framework in Transition

Right now, most CMMC-related work references NIST 800-171 Revision 2, which contains 320 assessment objectives across its 110 controls. A move to Revision 3 is already in planning phase, per the Unified Agenda, with 422 assessment objectives, a meaningfully more rigorous bar. Defense contracts have generally stuck with Revision 2 for consistency, while agencies outside the Department of Defense are moving toward Revision 3 more quickly.

The certification process is also evolving. The CMMC framework was designed to address a critical vulnerability: the widespread failure of contractors to properly protect CUI under the legacy, unverified self-attestation model. The Federal Register’s 32 CFR CMMC Rule finalized the programmatic layout, followed by the landmark Crowell & Moring CMMC Clause Rule under 48 CFR. These combined rulings, often referred to as the CMMC Program Final Rule, meant that contracting officers could legally require verified cybersecurity metrics in new DoD solicitations starting in late 2025.

The Original 4-Phase Rollout Plan

To minimize sudden market disruption, the Pentagon originally scheduled a multi-year, staggered implementation:

Phase 1 (November 10, 2025): Introduced mandatory Level 1 (17 controls) and Level 2 (110 controls) self-assessments, requiring contractors to upload their scores directly to the Supplier Performance Risk System (SPRS).

Phase 2 (Originally November 10, 2026): The “big cliff” where third-party validation was supposed to trigger. Most Level 2 contractors were to be forced to pass an independent audit from a CMMC Third-Party Assessor Organization (C3PAO) before winning contract awards.

Phase 3 & 4 (2027–2028): Phased introduction of elite government-led Level 3 assessments, scaling to full, un-waivable inclusion across all sensitive solicitations by November 2028.

The July 2026 Suspension of C3PAO Audits

In July 2026, the DoD issued a shocking policy pivot, freezing the Phase 2 C3PAO assessment requirement and all subsequent implementation milestones indefinitely. The main driver of this decision was the Pentagon’s recognition that mandatory third-party assessments proved costly and threatened to force vital small and mid-sized businesses completely out of the defense market. For the foreseeable future, self-certification against 800-171 Revision 2 is what’s required to be contract-eligible under the federal program
If you’re navigating this shift and want a partner who can help translate where the requirements stand today into what it means for your bid eligibility, our team is ready to help.

How to Know if CMMC Level 2 Compliance Requirements Apply to You

If you’re bidding on Department of Defense contracts, look for DFARS clauses (Defense Federal Acquisition Regulation Supplement), particularly DFARS 252.204-7025. That clause is a strong signal that CUI and CMMC requirements are baked into the contract. Outside the DoD, other agencies are more likely to reference NIST 800-171 directly rather than DFARS language, but the underlying expectation is the same: if the contract involves CUI, your organization’s security posture needs to meet the bar.

Where to Go Deeper

For anyone who wants to go beyond this overview, three sources are worth bookmarking:

The Bottom Line: Protecting CUI Takes Time, Strategy, and Effort

CUI isn’t classified information, but it’s not public information either, and treating it casually is one of the fastest ways to jeopardize a contract or an entire bidding relationship. Understanding what CUI is, how to recognize it within a contract award, and what CMMC requires of your organization is foundational work, not a compliance afterthought.

The organizations that struggle most with CMMC aren’t the ones missing a specific control. They’re the ones who didn’t ask these questions early enough, when there was still time to build the right systems instead of scrambling to backfill them once a contract was already on the table. CMMC Level 2 compliance in particular isn’t something you can compress into a few weeks before a bid deadline; it takes significant time to plan for, implement, and validate, which is why knowing how long the process takes matters before you’re up against a contract clock.

If your team is working through what these requirements mean for your specific contracts, or you’re trying to figure out where you stand against 800-171, don’t wait for a solicitation deadline to find out you have gaps. Reach out to us to schedule a Q&A call with a certified CMMC expert. We’ll walk through your contracts, your current posture, and exactly what needs to happen between here and full compliance.

Visit our CMMC Compliance page to learn more about the ways we can help.

Date Published
Share This Content

Share with Your Network

Download the "How Strong is Your Cybersecurity Culture?" Checklist!