Short answer
Controlled Unclassified Information (CUI) is federal information that needs safeguarding or dissemination controls under law or policy but is not classified. Executive Order 13556 created the program, 32 CFR Part 2002 sets the rules, and the National Archives CUI Registry lists every category. CUI Basic takes the baseline controls; CUI Specified follows the extra ones its authority names.
Key facts
- NARA defines CUI as information requiring safeguarding or dissemination controls that is not classified under Executive Order 13526 or the Atomic Energy Act.
- Executive Order 13556 established the program across the executive branch and designated the National Archives as Executive Agent.
- 32 CFR Part 2002 sets policy for designating, safeguarding, disseminating, marking, decontrolling and disposing of CUI.
- CUI Basic is the subset whose authorizing law, regulation or policy does not set out specific handling or dissemination controls.
- CUI Specified is the subset whose authorizing authority names specific handling controls that differ from those for CUI Basic.
- A category is CUI only when the CUI Executive Agent has approved it and listed it in the CUI Registry.
By Uniqcli Team
Controlled Unclassified Information (CUI) is information the government creates or possesses that requires safeguarding or dissemination controls under law, regulation or government-wide policy, but that is not classified under Executive Order 13526 or the Atomic Energy Act. It is the middle tier: not public, not classified, and governed by a single program instead of the patchwork of agency-invented markings — For Official Use Only, Sensitive But Unclassified, and dozens more — that the program replaced.
Three documents carry the whole framework. Executive Order 13556 established the program across the executive branch and named the National Archives and Records Administration as Executive Agent. 32 CFR Part 2002 sets the policy agencies follow for designating, safeguarding, disseminating, marking, decontrolling and disposing of CUI. And the CUI Registry, published by NARA, lists every approved category — if a category is not in the Registry, it is not CUI.
For a contractor the practical question is rarely philosophical. It is: which of the information we hold is CUI, what does its category require, and does the equipment it lives on meet that requirement. That is where a definitional page turns into a hardware conversation about encryption, media handling and separation.
What counts as CUI?
A category is CUI only when the CUI Executive Agent has approved it and listed it in the CUI Registry. NARA's own glossary is explicit about this: a CUI category or subcategory is a type of information for which laws, regulations or government-wide policies require or permit safeguarding or dissemination controls, and which the Executive Agent has approved and listed. Local practice, a program office's habit, or a marking inherited from a legacy contract does not create CUI.
The Registry organises those categories into organizational index groupings that read like the departments they come from — critical infrastructure, defense, export control, financial, immigration, intelligence, law enforcement, legal, nuclear, patent, privacy, procurement and acquisition, proprietary business information, statistical, tax, transportation, and others. Controlled Technical Information, export-controlled data and privacy records are the categories most contractors meet first.
The test is therefore documentary, not intuitive. Take the information in hand, find the category in the Registry, and read the authority the Registry cites. That authority is what tells you which of the two control levels applies.
CUI Basic and CUI Specified
CUI Basic is the subset for which the authorizing law, regulation or government-wide policy does not set out specific handling or dissemination controls. It gets the program's standard controls — the baseline in 32 CFR Part 2002 — and nothing further. Most categories a contractor handles fall here.
CUI Specified is the subset whose authorizing authority does name specific handling controls that differ from the CUI Basic baseline. Those named controls win wherever they exist; where the authority is silent, CUI Basic controls fill the gap. So a single document can be Specified for one requirement and Basic for the rest, which is why a marking on a Specified document usually names its category rather than stopping at the word CUI.
The consequence for buying is straightforward: CUI Basic tells you which baseline to meet, and CUI Specified tells you to go and read one more document before you decide anything. Neither is a certification and neither is something a vendor can hand you — the designation belongs to the agency that created or possesses the information.
Which equipment decisions does CUI actually touch?
The handling rules reach hardware at three points. The first is data at rest: portable media leaving a controlled space is the most common place CUI escapes, and a drive that performs encryption in hardware with the key held on the device keeps the key off the host PC entirely. Where a validated cryptographic module is required, that requirement is satisfied by a current certificate for the specific model, which is a thing to verify on the certificate itself rather than infer from a product name.
The second is separation. Where an operator works across networks of different sensitivity from one desk, the peripherals become the shared path, which is the argument for a purpose-built secure switch rather than a general-purpose one. The third is disposal — media sanitization and destruction at end of life, which the category's own authority will often address directly.
None of those decisions is made by reading a product page. They are made by reading the category in the Registry, then the authority it cites, then the specification of the part. This page is the first of those three steps.
Key takeaways
- CUI is information requiring safeguarding or dissemination controls that is not classified under Executive Order 13526 or the Atomic Energy Act.
- Executive Order 13556 created the program and named the National Archives as Executive Agent; 32 CFR Part 2002 sets the policy.
- A category is CUI only if the CUI Executive Agent has approved it and listed it in the CUI Registry.
- CUI Basic gets the program's baseline controls; CUI Specified follows the extra handling controls its own authority names.
- The Registry groups categories into organizational index groupings — defense, export control, privacy, procurement and acquisition, and others.
- Where the handling rules reach hardware they usually reach encryption of data at rest, peripheral separation between networks, and media disposal.
Shop it at Uniqcli
Parts for this job
Keypad drive
Apricorn
Apricon Aegis Secure Key 3NX: Software-Free 256-Bit AES XTS Encrypted…
ASK3-NX-16GB
A USB flash drive with an onboard PIN keypad and AES-XTS 256-bit encryption performed on the drive, so the key is never entered on the host computer.
A validation requirement is met by a current certificate for the exact model — confirm the certificate, not the product name.
$173.66In stockManaged fleet
iStorage/Kanguru
Kanguru Defender3000 FIPS 140-3 Certified Level 3, SuperSpeed USB 3.0…
KDF3000-16G
A hardware-encrypted USB 3.0 drive designed for centrally managed deployments, where an administrator needs an inventory of the drives in circulation.
$135.92*In stockPIN-protected
iStorage/Kanguru
iStorage datAshur PRO 16 GB | Secure Flash Drive | FIPS 140-2 Level 3…
IS-FL-DA3-256-16
A PIN-protected secure flash drive with full-disk hardware encryption, for moving working files between controlled spaces without exposing the key to a workstation.
$138.97Back-orderedFrequently asked
- What is considered to be CUI?
- Information the government creates or possesses that requires safeguarding or dissemination controls under a law, regulation or government-wide policy, and whose category the CUI Executive Agent has approved and listed in the CUI Registry. If a category is not in the Registry, it is not CUI. Classified information is not CUI either — CUI sits below the classification system, not inside it.
- Which is an example of CUI?
- Controlled Technical Information, export-controlled data, privacy records such as personally identifiable information held by an agency, and procurement-sensitive information are the categories contractors meet most often. Each appears in the CUI Registry under an organizational index grouping — defense, export control, privacy, procurement and acquisition — and each cites the authority that made it controlled.
- What is CUI cyber awareness?
- It is the annual training requirement that covers how to recognise, mark, handle, store, transmit and destroy CUI. The content follows 32 CFR Part 2002 and the CUI Registry: what the marking means, what CUI Basic and CUI Specified require, and who may receive the information. Agencies and contractors run their own versions, but the underlying rules are the same program.
- Is CUI the same as FOUO?
- No. For Official Use Only and similar agency-invented markings — Sensitive But Unclassified, Law Enforcement Sensitive, and others — are exactly what the CUI program replaced. Legacy documents still carry them, but a new designation must use a CUI category from the Registry, and a legacy marking on its own does not tell you which category or control level applies.
Sources
Keep reading


