Complete Guide

The Complete CUI Guide
for DoD Contractors

Everything your organization needs to understand, scope, protect, and document Controlled Unclassified Information under DFARS 7012 and CMMC Level 2.

Last updated: April 2026

What Is CUI Who This Is For

What Is CUI and Why It Drives Your Compliance Obligations

Controlled Unclassified Information is government-created or government-owned information that requires safeguarding under law, regulation, or government-wide policy, but is not classified. That distinction matters: CUI is not secret, it does not require a security clearance to handle, and it can flow freely to defense contractors who need it to perform their work. But the obligation to protect it is real, contractual, and legally enforceable.

The CUI program was established by Executive Order 13556 in 2010 and is administered by the National Archives and Records Administration. The DoD incorporated CUI protection into its acquisition system through DFARS 252.204-7012, which requires any contractor handling CUI to implement all 110 NIST SP 800-171 security requirements. CMMC Level 2 adds mandatory third-party verification of that implementation for contractors on sensitive programs.

The Stakes
DoD contractors who handle CUI without adequate protections face contract termination, disqualification from future awards, and False Claims Act liability. The DOJ's Civil Cyber-Fraud Initiative has settled more than $26 million in cases against contractors who misrepresented their cybersecurity posture. This guide covers what you actually need to do.

Who This Guide Is For

This guide is written for anyone in the defense industrial base whose work involves CUI: prime contractors who generate or receive it, subcontractors and suppliers who receive it from primes, IT and compliance teams responsible for protecting it, and owners and executives deciding how to approach CMMC compliance.

Prime contractorsYou receive CUI directly from the DoD, generate CUI in the course of program work, and are responsible for flowing protection requirements down to every subcontractor you share it with.
Subcontractors and suppliersYou receive CUI from a prime. Your obligations are identical to the prime's with respect to the data you handle. The fact that you are a sub does not reduce your NIST 800-171 requirements or your 72-hour incident reporting obligation.
IT and compliance teamsYou are responsible for implementing the technical and procedural controls that make CUI protection real.
Owners and executivesYou are signing the certifications.

See every gap.

1TEN maps all 110 NIST SP 800-171 controls to your environment and shows you exactly where you stand.

Request a Demo