800-171 Evidence

October 02, 2026

What Is CUI in Plain Words?

A file arrives marked CUI, and you are unsure what that label requires of you.

CUI means Controlled Unclassified Information.

The plain definition

CUI is government information that needs protection but is not classified. (NIST SP 800-171r3)

A law, regulation, or governmentwide policy sets the controls on it.

Classified national security information is not CUI.

So CUI sits between public information and classified secrets.

Who runs the program

Executive Order 13556 created the CUI program in 2010. (Executive Order 13556)

Before it, every agency used its own labels for sensitive information. The order replaced that patchwork with one governmentwide system.

It named NARA as the Executive Agent. NARA is the National Archives and Records Administration.

The program's federal regulation is 32 CFR Part 2002. (32 CFR Part 2002)

NARA keeps a public CUI Registry of every authorized category. (NARA CUI Registry)

Where contractors meet CUI

The Registry groups categories by subject. Two groupings show up most in defense work.

The Export Control grouping holds Export Controlled and Export Controlled Research. These cover information subject to export control laws.

The Defense grouping holds Controlled Technical Information. DFARS 252.204-7012 defines it as technical information with military or space application. (DFARS 252.204-7012)

DFARS is the Defense Federal Acquisition Regulation Supplement.

Examples include engineering drawings, specifications, and technical reports.

Other groupings include Source Selection and General Proprietary Business Information. Privacy categories cover Health Information and Personnel Records.

The markings tell you what you hold

A document carrying CUI gets a banner marking at the top. (NARA marking guidance)

The banner shows the CUI control marking, the category, and any limited dissemination control.

Two kinds of CUI exist: Basic and Specified. Specified categories carry extra handling requirements set by law.

A limited dissemination control adds sharing limits. NOFORN blocks sharing with anyone outside the United States. FEDCON limits sharing to federal employees and contractors. (NARA limited dissemination controls)

Why it matters for your contract

DFARS 252.204-7012 defines covered defense information using the CUI Registry.

That includes unclassified controlled technical information and other CUI your contract identifies.

The clause requires adequate security on systems that process, store, or transmit it.

The minimum bar it names is NIST SP 800-171. NIST is the National Institute of Standards and Technology. SP stands for Special Publication.

NIST SP 800-171 gives security requirements for CUI in nonfederal systems. (NIST SP 800-171r3)

The government's duty to protect CUI does not change when a contractor holds it.

What to do this week

Ask your contract lead which files in your shop carry CUI markings.

List where each one lives: file shares, inboxes, and cloud drives.

Confirm those systems meet the NIST SP 800-171 requirements in your clause.

Treat anything marked CUI as protected until your contract says otherwise.

Sources

  • Executive Order 13556, Controlled Unclassified Information, November 4, 2010: https://obamawhitehouse.archives.gov/the-press-office/2010/11/04/executive-order-13556-controlled-unclassified-information
  • NARA, Controlled Unclassified Information (CUI) program: https://www.archives.gov/cui
  • NARA CUI Registry, CUI categories: https://www.archives.gov/cui/registry/category-list
  • NARA CUI Registry, limited dissemination controls: https://www.archives.gov/cui/registry/limited-dissemination
  • NARA, Introduction to Marking CUI transcript: https://www.archives.gov/files/cui/documents/intro-to-marking-transcript-201808.pdf
  • 32 CFR Part 2002, Controlled Unclassified Information: https://www.ecfr.gov/current/title-32/subtitle-B/chapter-XX/part-2002
  • NIST SP 800-171r3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r3.pdf
  • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.

Next step

When CUI lives in your cloud, your protections must cover it.

PolicyCortex uses 33 collectors that read live Azure configuration, including conditional access, diagnostic settings, Defender posture, backup, and firewall.

It is evaluated against NIST 800-53 and NIST 800-171.

It builds SSP, SAR, and POA&M output from collected evidence. SSP is the System Security Plan. SAR is the Security Assessment Report. POA&M is the Plan of Action and Milestones.

See how it works.