What is CUI? A Guide to Controlled Unclassified Information
If you are drafting a System Security Plan (SSP) for a federal information system, you will almost certainly need to answer one question: Does this system create, store, process, or transmit Controlled Unclassified Information? This guide explains what CUI is, where the categories come from, and how to document CUI correctly inside your SSP.
What is Controlled Unclassified Information?
Controlled Unclassified Information, or CUI, is information the U.S. Government creates or possesses that requires safeguarding or dissemination controls consistent with law, regulation, or government-wide policy. CUI is not classified under Executive Order 13526, but it still needs to be protected from unauthorized access or release.
The CUI program was established by Executive Order 13556 and is implemented through 32 CFR Part 2002. The National Archives and Records Administration (NARA) manages the CUI Registry, which lists every approved CUI category and the laws or policies that authorize each one.
For an SSP author, the practical meaning of CUI is simple: if your system handles CUI, your security controls must be strong enough to protect it, and your SSP must say so explicitly.
The CUI Registry and categories
The CUI Registry is the official catalog of CUI categories. Each category is tied to a specific law, regulation, or government-wide policy. Categories are grouped into broad categories such as Defense, Export Control, Financial, Immigration, Intelligence, Legal, Naturalization, North America, Nuclear, Patent, Privacy, Proprietary Business, Tax, and Transportation.
A common example is CUI//SP-DOD (Department of Defense specific) or CUI//SP-NA (North Atlantic Treaty Organization information). Contractors working with the Department of Defense often encounter CUI//SP-DOD under DFARS 252.204-7012, which also triggers cybersecurity requirements such as NIST SP 800-171.
You cannot invent a CUI category. If information is not listed in the CUI Registry and covered by an authorized law or policy, it is not CUI. Your SSP should name the specific category or categories your system handles.
CUI Basic vs. CUI Specified
The CUI program distinguishes between two types of handling requirements:
- CUI Basic applies the uniform handling rules in 32 CFR Part 2002. These are the baseline safeguarding, dissemination, and marking rules that apply to every CUI category unless a specific law overrides them.
- CUI Specified applies when a specific law, regulation, or government-wide policy sets stricter or different handling rules. The category marking includes the agency or authority abbreviation, such as CUI//SP-DOD.
Your SSP should note whether the CUI you handle is Basic or Specified, because Specified categories may require additional controls or contractual clauses such as DFARS 252.204-7012.
How to identify CUI in your system
Start by listing every information type your system creates, collects, processes, stores, or transmits. For each type, ask:
- Is it created by or on behalf of a federal agency?
- Is it created or possessed by a contractor or grantee under a federal award?
- Does a law, regulation, or government-wide policy require safeguarding or dissemination controls?
- Is the information type listed in the CUI Registry?
If the answer to the last two questions is yes, you are likely handling CUI. Document the information type, the CUI category, the authorizing law or regulation, and whether the handling requirement is Basic or Specified.
CUI and FIPS 199 security categorization
FIPS 199 defines three impact levels — Low, Moderate, and High — for confidentiality, integrity, and availability. The presence of CUI usually drives the confidentiality impact to at least Moderate, because unauthorized disclosure could cause serious harm to national interests or the individuals the data describes.
The overall system categorization is the high-water mark across all three security objectives. If your CUI analysis produces Moderate confidentiality, and integrity and availability are Low, the overall impact level is Moderate. That result determines your baseline control set under FIPS 200.
A contractor system stores DoD CUI//SP-DOD and internal project schedules. The CUI drives confidentiality to Moderate. Integrity and availability are Low. The FIPS 199 overall impact level is Moderate, which maps to the Moderate baseline from NIST SP 800-53B.
Documenting CUI in the SSP
A complete SSP documents CUI in at least three places:
- System description: state whether the system processes CUI and name the categories.
- Information types: list each CUI-bearing information type, its C / I / A impact, and the rationale. Cite the CUI Registry category and the authorizing law or regulation.
- Control narratives: describe how specific safeguards protect CUI confidentiality, integrity, and availability.
Avoid vague statements like "the system may contain CUI." Be specific: "The system processes CUI//SP-DOD (Controlled Technical Information) under DFARS 252.204-7012. Confidentiality impact is Moderate based on FIPS 199."
NIST SP 800-53 controls that commonly apply
A Moderate baseline already includes a broad set of controls. When CUI is present, reviewers often look closely at the following controls in your SSP:
Identify and manage accounts that can access CUI.
Enforce approved authorizations for CUI access.
Document and monitor remote access to CUI.
Review audit records for indicators of unauthorized CUI access.
Enforce configurations that protect CUI.
Uniquely identify users who access CUI.
Store media containing CUI in protected locations.
Protect the confidentiality of CUI in transit.
Protect the confidentiality of CUI at rest.
Monitor for attacks that could expose CUI.
SSP Studio walks you through FIPS 199 categorization, baseline selection, and 800-53 control narratives. Start with the sample SSP to see how CUI documentation looks in practice, then create your own.