Controlled Unclassified Information (CUI)
Controlled Unclassified Information (CUI) is information the government creates or possesses, or that an entity handles on its behalf, that a law, regulation, or governmentwide policy requires safeguarding or dissemination controls for — sensitive but not classified, governed by 32 CFR Part 2002.
Executive Order 13556 (2010) built the CUI program to replace the ad hoc, agency-specific markings and handling policies that preceded it. NARA administers the program as Executive Agent under 32 CFR Part 2002, and the CUI Registry is the authoritative list of approved categories and markings. CUI Basic follows the uniform handling controls; CUI Specified carries whatever controls the underlying law or policy itself prescribes.
Part 2002 binds agencies, not contractors — CUI obligations reach industry only through agreements. For DoD work that means DFARS 252.204-7012: NIST SP 800-171 safeguarding and 72-hour cyber incident reporting. Civilian agencies use their own clauses, because the governmentwide FAR rule has been in rulemaking since FAR Case 2017-016 opened.
The recurring problem is identification. The government is supposed to tell the contractor what CUI a contract involves; legacy markings, over-marked documents, and unmarked deliverables leave contractors guessing, and scoping an 800-171 environment around a guess gets expensive in both directions.
Regulatory Reference
Executive Order 13556; 32 CFR Part 2002; DFARS 252.204-7012; FAR Case 2026-001 (proposed FAR Part 40)
RFO Status
The June 2026 overhaul proposed rule (FAR Case 2026-001) folds the January 2025 CUI proposed rule into proposed FAR Part 40, standardizes CUI identification on a new form, and relaxes the incident-reporting window from 8 hours to 72; comments closed July 23, 2026.
Category
Regulations & Policy
How AcqBot Helps
AcqBot checks whether a requirement involves CUI, verifies the solicitation identifies the categories in play, and inserts the safeguarding and incident-reporting clauses that match the agency — DFARS coverage for defense work, agency supplements elsewhere — so contractors are not left to infer scope from markings alone.
Related glossary entries
Class Deviation
A class deviation authorizes an agency to depart from specific FAR or supplement provisions for a category of contract actions rather than a single case — the mechanism agencies are using to implement the Revolutionary FAR Overhaul ahead of formal rulemaking.
Commercial Products and Services (FAR Part 12)
Commercial products and commercial services are items of a type sold, leased, licensed, or offered in the commercial marketplace, defined at FAR 2.101. FAR Part 12 implements the statutory preference for buying them whenever market research shows they can meet the agency's need.
Rule of Two
The rule of two directs a contracting officer to set aside an acquisition for small business when there is a reasonable expectation of receiving offers from at least two responsible small business concerns and making award at fair market prices, per FAR 19.502-2.
NIST SP 800-171
NIST Special Publication 800-171 lists the security requirements for protecting CUI on nonfederal information systems. DFARS 252.204-7012 makes it contractual for defense work — held at Revision 2 by class deviation — and its 110 requirements are the CMMC Level 2 baseline.