What Is CUI and Why It Drives Your Compliance Obligations
Controlled Unclassified Information is government-created or government-owned information that requires safeguarding under law, regulation, or government-wide policy, but is not classified. That distinction matters: CUI is not secret, it does not require a security clearance to handle, and it can flow freely to defense contractors who need it to perform their work. But the obligation to protect it is real, contractual, and legally enforceable.
The CUI program was established by Executive Order 13556 in 2010 and is administered by the National Archives and Records Administration. The DoD incorporated CUI protection into its acquisition system through DFARS 252.204-7012, which requires any contractor handling CUI to implement all 110 NIST SP 800-171 security requirements. CMMC Level 2 adds mandatory third-party verification of that implementation for contractors on sensitive programs.
Who This Guide Is For
This guide is written for anyone in the defense industrial base whose work involves CUI: prime contractors who generate or receive it, subcontractors and suppliers who receive it from primes, IT and compliance teams responsible for protecting it, and owners and executives deciding how to approach CMMC compliance.
| Prime contractors | You receive CUI directly from the DoD, generate CUI in the course of program work, and are responsible for flowing protection requirements down to every subcontractor you share it with. |
| Subcontractors and suppliers | You receive CUI from a prime. Your obligations are identical to the prime's with respect to the data you handle. The fact that you are a sub does not reduce your NIST 800-171 requirements or your 72-hour incident reporting obligation. |
| IT and compliance teams | You are responsible for implementing the technical and procedural controls that make CUI protection real. |
| Owners and executives | You are signing the certifications. |