A practitioner's guide to identifying CUI - the 32 CFR 2002 definition, the Registry, Basic vs Specified, what is NOT CUI, and how to scope it into an enclave.
Controlled Unclassified Information (CUI) is government-created or -owned information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy - but is not classified. It is defined in 32 CFR Part 2002, the government-wide CUI rule, and the authoritative list of what qualifies lives in the CUI Registry at the National Archives (archives.gov/cui). Information counts as CUI only if it falls into a category on that Registry - "sensitive" or "confidential" is not enough. CUI comes in two types, Basic and Specified, which differ in how tightly the underlying authority dictates handling. This guide shows you how to identify CUI correctly, avoid the over-scoping mistakes that inflate compliance cost, and draw a defensible boundary around it.
The instinct most people have, that "it feels sensitive, so it must be CUI," is exactly the instinct that gets scoping wrong. CUI has a precise legal definition, and precision here saves money.
Under 32 CFR 2002.4, CUI is information that the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or government-wide policy requires or permits an agency to handle with safeguarding or dissemination controls. Three things follow from that definition:
That framing (authority, Registry category, unclassified) is your first filter for every document, email, and dataset you assess.
Once you have established that something is CUI, the next question is which type. This distinction drives handling, and it is one of the most-searched CUI questions for a reason - people conflate the two.
| CUI Basic | CUI Specified | |
|---|---|---|
| What it is | The default category of CUI | CUI whose authority prescribes specific controls |
| Handling source | The uniform controls in 32 CFR 2002 / the CUI Program | The controls named in the underlying law, regulation, or policy |
| Who sets the rules | The CUI Program baseline | The specific authorizing statute or regulation |
| Example distinction | The underlying authority says "protect it" but not how | The underlying authority says "protect it this specific way" |
Source: 32 CFR Part 2002 and the CUI Registry.
CUI Basic is the floor. When an authority designates information as CUI but does not spell out particular handling or dissemination controls, you protect it using the uniform baseline in 32 CFR 2002 and the CUI Program - the standard safeguarding, marking, and dissemination rules that apply across the board.
CUI Specified is the exception that overrides the floor. When the underlying authority specifies particular handling or dissemination controls beyond the Basic baseline, those specific controls govern. Export-controlled information is a common example: the authority behind it dictates handling that goes past the generic baseline.
The practical rule for practitioners: check the category in the Registry. The Registry tells you whether a category is Basic or Specified and, for Specified categories, points to the controlling authority. Do not assume - look it up.
If you are a defense contractor, most of your CUI questions are really DoW questions, and the Department implements the CUI Program through its own instruction: DoD Instruction 5200.48, Controlled Unclassified Information (CUI).
DoDI 5200.48 establishes DoW's CUI policy and covers the responsibilities, marking, handling, decontrol, and destruction procedures for CUI within the Department. It is the document that operationalizes 32 CFR 2002 for the defense industrial base, so when a DoW contract obligates you to protect CUI, DoDI 5200.48 (together with the DFARS clauses) is where the specifics live. The Department first issued it on March 6, 2020. Check the DoD CUI Program site at dodcui.mil for the current edition and related guidance before you cite a specific version.
For the contractual machinery that ties CUI protection to your DoW contracts, including the safeguarding and reporting obligations, see our breakdown of DFARS 252.204-7012 and the CMMC clause set.
This is the section that saves you the most money, because over-scoping CUI is the most common and costly mistake in defense compliance. Every document you wrongly treat as CUI drags more of your environment into a CMMC assessment. Here is what is not CUI:
A useful discipline: for every dataset you are tempted to mark CUI, write down which authority and which Registry category makes it so. If you cannot fill in both blanks, it probably is not CUI - and you have just kept it out of scope.
The flip side matters too: under-marking is a compliance failure with teeth. Missing CUI markings can mean CUI is handled on unprotected systems. The goal is accuracy in both directions, not minimizing at all costs.
Put the filters together into a repeatable process. Run every candidate dataset through it:
Run this on your actual data flows, covering what you receive, what you generate for the government, and where it moves, and you will end up with a defensible inventory instead of a nervous over-guess.
Once you know precisely what your CUI is and where it lives, you can draw a boundary around it - and this is where CUI identification pays off in real dollars.
The expensive path is letting CUI live everywhere: every laptop, every shared drive, every cloud tenant. That drags your entire enterprise into a CMMC Level 2 assessment. The disciplined path is an enclave - a deliberately bounded environment (commonly a separate cloud tenant or a segmented network) where CUI is stored, processed, and transmitted, walled off from the rest of the business. You protect and assess the enclave; everything outside it that never touches CUI stays out of scope.
Building a defensible enclave depends entirely on the CUI inventory you just produced. If you do not know what your CUI is, you cannot bound it - which is why identification comes first and scoping comes second. Our CMMC certification cost guide shows how enclave-versus-enterprise scope moves the price by an order of magnitude.
CUI Basic is the default type of Controlled Unclassified Information. It applies when a law, regulation, or government-wide policy requires the information to be protected but does not prescribe specific handling or dissemination controls. You safeguard CUI Basic using the uniform baseline controls in 32 CFR 2002 and the CUI Program.
CUI Specified is CUI whose underlying authority specifies particular handling or dissemination controls beyond the standard baseline. Those specific controls govern how you protect and share it. Export-controlled information is a common example. The CUI Registry indicates which categories are Specified and points to the controlling authority.
The CUI Registry, maintained by the National Archives' Information Security Oversight Office (ISOO) as the CUI Executive Agent, is the authoritative, government-wide list of approved CUI categories and subcategories. It defines what qualifies as CUI and provides marking, safeguarding, and dissemination guidance. If information does not map to a Registry category, it is not CUI.
DoD Instruction 5200.48, Controlled Unclassified Information (CUI), implements the CUI Program within DoW. It establishes the Department's policy and procedures for marking, handling, decontrolling, and destroying CUI, operationalizing the government-wide 32 CFR 2002 rule for the defense community.
CUI is unclassified information that a law, regulation, or government-wide policy requires or permits to be protected with safeguarding or dissemination controls. It is defined in 32 CFR 2002 and enumerated in the CUI Registry. It sits below classified information and replaced older ad hoc markings like "For Official Use Only" for information that meets the CUI definition.
No. Information you generate and control for your own business, such as trade secrets, pricing, and internal roadmaps, is not CUI, because there is no government law, regulation, or policy behind it. CUI must trace to a government authority and map to a Registry category. Treating company-confidential data as CUI is a common and costly over-scoping mistake.
Getting CUI right is where a good compliance program starts, because everything downstream (your enclave boundary, your CMMC scope, your assessment cost) depends on an accurate inventory. Compli.ai records each CUI data asset with its Registry category, storing system, ingress channel, and flow narrative, maps the systems inside your boundary, and keeps the SSP implementation statements and POA&M that show an assessor how your CUI is bounded and protected under NIST SP 800-171 and CMMC. All of it lives in a SharePoint site in your own Microsoft 365 tenant. See how Compli.ai supports CMMC compliance and NIST 800-171 compliance, and book a demo to map your CUI boundary with a practitioner.