compli.ai
From the blog

What Counts as CUI? Identification and Scoping Guide

A practitioner's guide to identifying CUI - the 32 CFR 2002 definition, the Registry, Basic vs Specified, what is NOT CUI, and how to scope it into an enclave.

Controlled Unclassified Information (CUI) is government-created or -owned information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy - but is not classified. It is defined in 32 CFR Part 2002, the government-wide CUI rule, and the authoritative list of what qualifies lives in the CUI Registry at the National Archives (archives.gov/cui). Information counts as CUI only if it falls into a category on that Registry - "sensitive" or "confidential" is not enough. CUI comes in two types, Basic and Specified, which differ in how tightly the underlying authority dictates handling. This guide shows you how to identify CUI correctly, avoid the over-scoping mistakes that inflate compliance cost, and draw a defensible boundary around it.

The definition that actually matters

The instinct most people have, that "it feels sensitive, so it must be CUI," is exactly the instinct that gets scoping wrong. CUI has a precise legal definition, and precision here saves money.

Under 32 CFR 2002.4, CUI is information that the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or government-wide policy requires or permits an agency to handle with safeguarding or dissemination controls. Three things follow from that definition:

  • It has to trace to an authority. There must be a law, regulation, or government-wide policy behind it. Company-confidential information, trade secrets you generated for yourself, or "internal use only" data is not CUI just because it is sensitive.
  • It has to match a Registry category. The CUI Registry (archives.gov/cui), maintained by the National Archives' Information Security Oversight Office (ISOO) as the CUI Executive Agent, lists every approved CUI category and subcategory - from Controlled Technical Information to Export Control to Privacy. If your information does not map to a category, it is not CUI.
  • It is unclassified. CUI sits below classified. If information is classified, it is governed by the classification system, not the CUI Program.

That framing (authority, Registry category, unclassified) is your first filter for every document, email, and dataset you assess.

CUI Basic vs CUI Specified

Once you have established that something is CUI, the next question is which type. This distinction drives handling, and it is one of the most-searched CUI questions for a reason - people conflate the two.

CUI BasicCUI Specified
What it isThe default category of CUICUI whose authority prescribes specific controls
Handling sourceThe uniform controls in 32 CFR 2002 / the CUI ProgramThe controls named in the underlying law, regulation, or policy
Who sets the rulesThe CUI Program baselineThe specific authorizing statute or regulation
Example distinctionThe underlying authority says "protect it" but not howThe underlying authority says "protect it this specific way"

Source: 32 CFR Part 2002 and the CUI Registry.

CUI Basic is the floor. When an authority designates information as CUI but does not spell out particular handling or dissemination controls, you protect it using the uniform baseline in 32 CFR 2002 and the CUI Program - the standard safeguarding, marking, and dissemination rules that apply across the board.

CUI Specified is the exception that overrides the floor. When the underlying authority specifies particular handling or dissemination controls beyond the Basic baseline, those specific controls govern. Export-controlled information is a common example: the authority behind it dictates handling that goes past the generic baseline.

The practical rule for practitioners: check the category in the Registry. The Registry tells you whether a category is Basic or Specified and, for Specified categories, points to the controlling authority. Do not assume - look it up.

The Department of War (DoW) flavor: DoDI 5200.48

If you are a defense contractor, most of your CUI questions are really DoW questions, and the Department implements the CUI Program through its own instruction: DoD Instruction 5200.48, Controlled Unclassified Information (CUI).

DoDI 5200.48 establishes DoW's CUI policy and covers the responsibilities, marking, handling, decontrol, and destruction procedures for CUI within the Department. It is the document that operationalizes 32 CFR 2002 for the defense industrial base, so when a DoW contract obligates you to protect CUI, DoDI 5200.48 (together with the DFARS clauses) is where the specifics live. The Department first issued it on March 6, 2020. Check the DoD CUI Program site at dodcui.mil for the current edition and related guidance before you cite a specific version.

For the contractual machinery that ties CUI protection to your DoW contracts, including the safeguarding and reporting obligations, see our breakdown of DFARS 252.204-7012 and the CMMC clause set.

What is NOT CUI (where most people over-scope)

This is the section that saves you the most money, because over-scoping CUI is the most common and costly mistake in defense compliance. Every document you wrongly treat as CUI drags more of your environment into a CMMC assessment. Here is what is not CUI:

  • Your own company-confidential information. Trade secrets, pricing strategy, internal roadmaps, HR records - sensitive, yes; CUI, no. There is no government authority behind them.
  • Publicly releasable information. Anything already approved for public release is not CUI, even if it once was. Public-release review can precede decontrol.
  • Classified information. It is above CUI, governed by the classification system.
  • Information that does not map to a Registry category. If you cannot point to the category, it is not CUI - full stop.
  • FCI that is not also CUI. Federal Contract Information triggers CMMC Level 1 obligations, but FCI and CUI are different things; not all FCI rises to CUI. (See our CMMC levels guide for the FCI-vs-CUI split.)
  • Information from a contract that never involved CUI. The presence of a government contract does not automatically make everything you touch CUI.

A useful discipline: for every dataset you are tempted to mark CUI, write down which authority and which Registry category makes it so. If you cannot fill in both blanks, it probably is not CUI - and you have just kept it out of scope.

The flip side matters too: under-marking is a compliance failure with teeth. Missing CUI markings can mean CUI is handled on unprotected systems. The goal is accuracy in both directions, not minimizing at all costs.

A CUI identification workflow

Put the filters together into a repeatable process. Run every candidate dataset through it:

  1. Is it unclassified? If it is classified, stop - it is not CUI.
  2. Is there a law, regulation, or government-wide policy behind it? If there is no government authority, it is not CUI - it is company-confidential at most.
  3. Does it map to a CUI Registry category? Check archives.gov/cui. No category, no CUI.
  4. Basic or Specified? The Registry entry tells you. For Specified categories, note the controlling authority and its specific handling rules.
  5. Check the markings. Properly designated CUI carries a CUI banner marking (top and bottom of the document), optionally with category markings and a limited-dissemination control, plus a designation indicator identifying the originating agency or office. If a document should be CUI but is unmarked, escalate to the designating agency rather than guessing.
  6. Record it in your CUI inventory. Log what it is, its category, Basic/Specified, and where it lives. This inventory is the backbone of your scoping.

Run this on your actual data flows, covering what you receive, what you generate for the government, and where it moves, and you will end up with a defensible inventory instead of a nervous over-guess.

From inventory to enclave: scoping the boundary

Once you know precisely what your CUI is and where it lives, you can draw a boundary around it - and this is where CUI identification pays off in real dollars.

The expensive path is letting CUI live everywhere: every laptop, every shared drive, every cloud tenant. That drags your entire enterprise into a CMMC Level 2 assessment. The disciplined path is an enclave - a deliberately bounded environment (commonly a separate cloud tenant or a segmented network) where CUI is stored, processed, and transmitted, walled off from the rest of the business. You protect and assess the enclave; everything outside it that never touches CUI stays out of scope.

Building a defensible enclave depends entirely on the CUI inventory you just produced. If you do not know what your CUI is, you cannot bound it - which is why identification comes first and scoping comes second. Our CMMC certification cost guide shows how enclave-versus-enterprise scope moves the price by an order of magnitude.

FAQ

What is CUI Basic?

CUI Basic is the default type of Controlled Unclassified Information. It applies when a law, regulation, or government-wide policy requires the information to be protected but does not prescribe specific handling or dissemination controls. You safeguard CUI Basic using the uniform baseline controls in 32 CFR 2002 and the CUI Program.

What is CUI Specified?

CUI Specified is CUI whose underlying authority specifies particular handling or dissemination controls beyond the standard baseline. Those specific controls govern how you protect and share it. Export-controlled information is a common example. The CUI Registry indicates which categories are Specified and points to the controlling authority.

What is the purpose of the ISOO CUI Registry?

The CUI Registry, maintained by the National Archives' Information Security Oversight Office (ISOO) as the CUI Executive Agent, is the authoritative, government-wide list of approved CUI categories and subcategories. It defines what qualifies as CUI and provides marking, safeguarding, and dissemination guidance. If information does not map to a Registry category, it is not CUI.

What DoD instruction implements the DoD CUI Program?

DoD Instruction 5200.48, Controlled Unclassified Information (CUI), implements the CUI Program within DoW. It establishes the Department's policy and procedures for marking, handling, decontrolling, and destroying CUI, operationalizing the government-wide 32 CFR 2002 rule for the defense community.

What is controlled unclassified information (CUI)?

CUI is unclassified information that a law, regulation, or government-wide policy requires or permits to be protected with safeguarding or dissemination controls. It is defined in 32 CFR 2002 and enumerated in the CUI Registry. It sits below classified information and replaced older ad hoc markings like "For Official Use Only" for information that meets the CUI definition.

Is company-confidential information CUI?

No. Information you generate and control for your own business, such as trade secrets, pricing, and internal roadmaps, is not CUI, because there is no government law, regulation, or policy behind it. CUI must trace to a government authority and map to a Registry category. Treating company-confidential data as CUI is a common and costly over-scoping mistake.

Getting CUI right is where a good compliance program starts, because everything downstream (your enclave boundary, your CMMC scope, your assessment cost) depends on an accurate inventory. Compli.ai records each CUI data asset with its Registry category, storing system, ingress channel, and flow narrative, maps the systems inside your boundary, and keeps the SSP implementation statements and POA&M that show an assessor how your CUI is bounded and protected under NIST SP 800-171 and CMMC. All of it lives in a SharePoint site in your own Microsoft 365 tenant. See how Compli.ai supports CMMC compliance and NIST 800-171 compliance, and book a demo to map your CUI boundary with a practitioner.