Guide

CUI Handling Requirements for Defense Contractors (2026)

Last updated: 2026-02-27

What CUI Is Common CUI Categories in Defense Contracting How to Identify CUI in Your Environment CUI Storage Requirements CUI Transmission Requirements

What CUI Is

Controlled Unclassified Information is government-created or government-owned information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy — but is not classified. That last part is critical and frequently misunderstood. CUI is not secret. It is not classified. It can be handled by cleared and uncleared personnel alike. But it requires specific protection, and the obligation to protect it is contractual and legally enforceable.

The CUI program was established by Executive Order 13556 in 2010 and is administered by the National Archives and Records Administration (NARA). The DoD CUI Registry at archives.gov is the authoritative source defining every recognized CUI category, the specific laws or regulations establishing each one, and any handling restrictions that apply. There are more than 100 defined CUI categories, organized into 20 groupings.

The Key Distinction
CUI is not classified, but it is also not public. It sits in a specific middle tier: sensitive enough to require protection under federal law or regulation, but not sensitive enough to warrant classification. The failure to protect it carries real legal and national security consequences — which is precisely why DoD built CMMC around it.

For defense contractors, the most important thing to understand is that you do not decide what is CUI. The government does. The information you receive from a DoD customer is CUI if the government designates it as such — regardless of whether it is labeled, regardless of whether your contract spells it out explicitly, and regardless of whether you have historically treated it that way. Your obligation is to identify CUI in your environment and protect it accordingly.

Common CUI Categories in Defense Contracting

While the full CUI Registry contains more than 100 categories, defense contractors most commonly encounter the following types. Recognizing these categories in your day-to-day work is the first step in building an effective CUI handling program.

Controlled Technical Information (CTI)Technical information with military or space application that is subject to controls on access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. This includes technical specifications, engineering drawings, and design documentation for defense systems and components. The most common CUI category in the defense supply chain.
Export Controlled (ITAR/EAR)Technical data subject to International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR). Includes design data, manufacturing processes, and operational parameters for defense articles and dual-use items. Sharing ITAR-controlled CUI with foreign nationals or entities without authorization is a federal crime independent of CMMC.
Contract Performance DataSensitive information related to contract execution including cost data, schedule information, technical approaches, subcontractor relationships, and program performance details that are not publicly releasable. Often found in contractor reports, program reviews, and financial submissions.
Procurement and AcquisitionPre-decisional acquisition information, source selection data, contractor proposals, and pricing information that could compromise the integrity of the procurement process if disclosed. Handling this category incorrectly can create procurement integrity violations beyond CMMC exposure.
Naval Nuclear PropulsionInformation related to naval nuclear propulsion systems. Contractors on submarine or naval nuclear programs will encounter this category, which carries heightened handling restrictions beyond standard CUI requirements.
Privacy (PII)Personally Identifiable Information about DoD personnel, contractors, or beneficiaries. If your work involves personnel records, security clearance data, or health information related to DoD programs, this category applies. Privacy CUI carries additional handling requirements under the Privacy Act.

How to Identify CUI in Your Environment

Before you can protect CUI, you have to find it. CUI identification is a systematic process, not a one-time review. Information enters your environment continuously through customer deliverables, emails, shared drives, and project file transfers. Your CUI identification program needs to be ongoing.

Start with your contracts. Every DoD contract containing DFARS 252.204-7012 involves CUI. The contract and any Statement of Work will often describe the categories of information involved. Your contracting officer is required to identify CUI in the contract — if it is not clearly identified, ask.

Where CUI Hides
CUI does not only live in formal technical data packages. It appears in email attachments from your customer, in meeting notes from program reviews, in drawings shared via FTP or file sharing services, in CAD files on engineer workstations, on USB drives used to transfer data between systems, in cloud storage folders shared with the customer, and in backup systems that replicate all of the above. Your CUI boundary must account for every location where designated information exists — not just the obvious ones.

Once you identify where CUI exists, you need to document it in your System Security Plan. The SSP must define your CUI boundary — the specific systems, locations, and processes that handle CUI — with enough precision that a C3PAO assessor can understand exactly what is in scope for the CMMC assessment. Vague or incomplete CUI boundary documentation is one of the most common SSP deficiencies assessors find.

Labeling is a related but separate obligation. When your organization creates documents that contain CUI, those documents should be labeled as CUI using the standard marking format. When you receive unlabeled information that you believe qualifies as CUI based on its content and context, you should treat it as CUI and notify the originating party of the unmarked CUI. You are not absolved of the protection obligation because a document arrived without a label.

CUI Storage Requirements

How and where you store CUI determines a significant portion of your CMMC compliance burden. The NIST SP 800-171 requirements for media protection, access control, and system and communications protection all derive from the fundamental need to keep CUI from being accessed by unauthorized parties — whether through logical access to systems or physical access to media.

Digital storage on-premisesSystems that store CUI must implement all applicable NIST SP 800-171 controls. Access must be restricted to authorized users with least-privilege permissions. Audit logging must be enabled to capture who accessed what and when. Systems must be within a defined, documented network boundary that is separated from general-purpose or guest networks.
Cloud storageCloud services storing CUI must be authorized at FedRAMP Moderate baseline or higher. This rules out standard commercial offerings from Microsoft, Google, Box, Dropbox, and similar providers. Required options include Microsoft 365 GCC, Google Workspace for Government, or other specifically FedRAMP Moderate-authorized services. This is a bright-line rule with enforcement precedent — the MORSECORP settlement was partly based on using a non-compliant cloud email provider.
Portable media and devicesUSB drives, external hard drives, laptops, and other portable media that contain CUI must be encrypted. Access to portable media on CUI systems must be controlled and logged. When portable media is no longer needed, it must be sanitized using NIST SP 800-88 guidelines before disposal or reuse — simply deleting files is not sufficient.
Physical documentsPrinted CUI must be stored in locked, access-controlled locations when not in active use. Access to physical CUI storage areas must be limited to authorized personnel. Physical documents containing CUI must be destroyed using cross-cut shredding or equivalent methods when no longer needed — standard recycling or trash disposal is not acceptable.
Backups and archivesBackup systems that include CUI are in scope for your CMMC assessment just as the primary systems are. Many organizations discover that their backup infrastructure — which may replicate data to offsite locations, cloud services, or older tape systems — extends their CUI boundary significantly beyond what they initially scoped.

CUI Transmission Requirements

NIST SP 800-171 requirement 3.13.8 specifies that CUI must be encrypted when transmitted over open networks. This requirement applies to every method by which CUI moves from one system, location, or person to another — including methods that organizations routinely use without thinking about encryption.

Email is the most common CUI transmission vector and one of the most frequently mishandled. Sending CUI via standard commercial email is not compliant if the email platform does not meet FedRAMP Moderate requirements. Encryption in transit (TLS) is required; end-to-end encryption is preferred for highly sensitive CUI. As noted above, standard Microsoft 365, Gmail, and similar commercial offerings do not meet the bar for CUI transmission — Microsoft 365 GCC does.

File transfer via FTP, unencrypted web portals, or consumer file sharing services (Dropbox, Google Drive personal, WeTransfer) is not compliant for CUI. Secure file transfer must use SFTP, HTTPS with TLS 1.2 or higher, or a FedRAMP Moderate-authorized file sharing platform. Many defense contractor teams routinely use consumer tools to share large files — this is a gap that consistently surfaces in C3PAO assessments.

Remote access to systems containing CUI must use encrypted connections. VPN with strong authentication is the standard approach. Remote desktop sessions must be encrypted and authenticated with multi-factor authentication. The specific remote access controls required by NIST SP 800-171 are among the most detailed in the Access Control domain and are frequently cited in assessment findings.

The FedRAMP Moderate Requirement in Practice
The migration to a FedRAMP Moderate-authorized cloud environment is one of the most significant infrastructure decisions in a CMMC compliance program. For most small contractors, this means migrating from standard Microsoft 365 or Google Workspace to their GCC equivalents. The cost is typically $4 to $12 per user per month in additional licensing. The cost of not making this change — as MORSECORP discovered at $4.6 million — is considerably higher.

CUI Destruction and Disposal

The obligation to protect CUI does not end when a project concludes or a contract expires. CUI must be destroyed or returned to the government in accordance with contract terms and applicable regulations. Improper disposal of CUI — including putting printed documents in the trash or discarding unwiped drives — is a violation of the handling requirements regardless of whether the underlying contract is still active.

For digital media, NIST SP 800-88 provides the authoritative guidance on media sanitization. The appropriate method depends on the sensitivity of the CUI and the type of media. Clearing (overwriting data) is acceptable for lower-sensitivity CUI on reusable media. Purging (cryptographic erase or secure overwrite) is required for higher-sensitivity categories. Physical destruction is required for media that cannot be reliably sanitized by software methods, including solid-state drives in some circumstances.

For physical documents, cross-cut shredding that reduces paper to particles of 1mm x 5mm or smaller is the standard. Strip-cut shredders do not meet this requirement. If your organization generates significant volumes of CUI paper documents, a certified shredding service with a certificate of destruction is a defensible approach that also produces documentation for your evidence package.

Your SSP should document your media protection and disposal procedures specifically, identifying the method used for each category of media and the process for documenting disposal. Assessors will examine this section and may request evidence of sanitization records for recently decommissioned equipment.

CUI Access Control Requirements

Access to CUI must be limited to individuals who have a legitimate need to access it for their work. This sounds straightforward, but implementing it correctly requires specific technical and procedural controls that many organizations have not formalized.

The NIST SP 800-171 Access Control domain (22 requirements) is the largest domain specifically because controlling who can access CUI — and under what circumstances — is foundational to the entire protection framework. The most consistently cited requirements in assessments and enforcement cases relate to:

Least privilegeUsers should only have access to the CUI they need for their specific role. A project manager who needs to read technical specifications does not need write access to the engineering drawing repository. Administrators who manage CUI systems should have separate privileged accounts distinct from their standard user accounts.
Multi-factor authenticationMFA is required for all accounts with access to CUI systems, and explicitly required for privileged accounts and remote access. Password alone is not sufficient. This requirement appears in both the Identification and Authentication domain and as a specific control in Access Control for remote access scenarios.
Access reviewsAccess to CUI systems must be periodically reviewed and accounts must be promptly disabled when no longer needed. The most common access control finding in assessments is former employees or contractors whose accounts were not disabled upon termination. Your offboarding procedure must include immediate CUI system access revocation as a required step.
Shared accountsShared accounts — where multiple people log in with the same credentials — are prohibited on CUI systems. Every individual who accesses CUI must have a unique, individually attributed account. This allows audit logs to identify specific individuals and holds each person accountable for their actions on the system.
External system accessCUI must not be processed on systems the organization does not own or control without explicit authorization. This includes personal devices (BYOD), contractor-owned systems, and public computers. If your employees access CUI from personal laptops, those devices are in scope for your assessment unless you have implemented controls that specifically prevent CUI from reaching them.

Training Requirements for CUI Handlers

Every individual in your organization who has access to CUI must be trained on their responsibilities for protecting it. NIST SP 800-171 Awareness and Training requirements are explicit: personnel must be aware of security risks associated with their activities and trained to carry out their responsibilities consistently with the organization's security policies.

CUI-specific training should cover what CUI is and the categories your organization handles, how to identify CUI when they receive it, how to handle and store CUI correctly on the systems they use, what to do if they suspect a CUI spill or unauthorized disclosure, and who to contact with questions or concerns. General cybersecurity awareness training is not a substitute for CUI-specific training — your training program must address the specific handling requirements your personnel need to follow in their roles.

Training must be documented. Your evidence package for the Awareness and Training domain should include training completion records for every individual with CUI access, the curriculum used, the date of training, and records of any personnel who did not complete required training and how that was resolved. Annual retraining is the standard cadence, with additional training required when significant changes occur in handling procedures or when new CUI categories are introduced.

Building a CUI Handling Program

A CUI handling program is not a single policy document — it is an integrated set of policies, procedures, technical controls, and training that together ensure CUI is consistently protected across your organization. Building one from scratch follows a logical sequence.

1. Identify and scopeDocument every contract containing DFARS 7012. For each, identify the CUI categories involved and trace where that information flows through your organization: who receives it, what systems it touches, where it is stored, and how it is transmitted. This scoping exercise produces the CUI boundary that your SSP must document.
2. Assess current controlsEvaluate your current technical and procedural controls against the NIST SP 800-171 requirements relevant to CUI handling: access control, media protection, system and communications protection, and personnel security. Identify gaps between your current posture and full compliance. This produces your SPRS score and your POA&M items.
3. Document in the SSPWrite your CUI boundary, system descriptions, and control implementations into your System Security Plan. For each NIST 800-171 requirement, describe specifically how it is implemented in your environment with respect to CUI — naming the systems, tools, configurations, and personnel responsible.
4. Implement and remediateClose identified gaps on a documented timeline. Migrate to FedRAMP Moderate cloud services if needed. Implement MFA across CUI-accessible systems. Enable audit logging. Establish media sanitization procedures. Work each POA&M item with a named owner and a committed completion date.
5. Train personnelRoll out CUI-specific training to all individuals with access. Document completion. Brief each role group on the specific handling procedures that apply to their work. Prepare personnel who may be interviewed during a C3PAO assessment to describe their CUI handling responsibilities accurately and consistently.
6. Monitor and maintainA CUI handling program is not a one-time project. Review access rights periodically. Update training annually. Re-assess scope when new contracts are added or when the information environment changes. The annual SPRS affirmation required under CMMC is a formal checkpoint — your program must be able to support that affirmation honestly.

Frequently Asked Questions

What is Controlled Unclassified Information (CUI)?

CUI is government-created or government-owned information that requires safeguarding under law, regulation, or government-wide policy — but is not classified. For defense contractors, the most common categories include technical specifications, ITAR-controlled data, engineering drawings for defense systems, and sensitive contract performance information. The DoD CUI Registry at archives.gov defines all recognized categories.

How do I know if I handle CUI?

Check your contracts for DFARS 252.204-7012. If that clause is present, the DoD has determined that CUI is involved in your work. Review the technical data, drawings, and specifications your customer sends you — if they carry distribution statement markings (B through F) or are labeled CUI or FOUO, they qualify. When uncertain, ask your contracting officer directly. They are required to identify CUI in the contract.

Can I store CUI in Dropbox or Google Drive?

No. Standard commercial cloud storage services including Dropbox, Google Drive (personal), Box, and OneDrive do not meet the FedRAMP Moderate baseline authorization required for CUI storage. You must use FedRAMP Moderate-authorized services such as Microsoft 365 GCC, Google Workspace for Government, or equivalent authorized platforms. Using non-authorized cloud services for CUI was a central element of the MORSECORP False Claims Act settlement.

What do I do if CUI is accidentally emailed to the wrong person?

An unauthorized CUI disclosure is a reportable cyber incident under DFARS 252.204-7012. Report to the DoD within 72 hours through the DIBNet portal at dibnet.dod.mil. Notify your contracting officer. Document what happened, what CUI was disclosed, and to whom. Preserve any relevant records. Attempt to retrieve or have the recipient destroy the information if possible. Your incident response plan should document this process in advance.

Do I need to label documents that contain CUI?

When your organization creates documents containing CUI, they should be labeled using the standard CUI marking format. When you receive unlabeled information that qualifies as CUI based on its content and context, you should treat it as CUI and notify the originator of the unmarked material. You are not relieved of the protection obligation simply because a document arrived without a label.

How do I properly dispose of CUI?

Digital media must be sanitized using NIST SP 800-88 methods — simple file deletion is not sufficient. Clearing (overwriting) is acceptable for lower-sensitivity CUI on reusable media; purging (cryptographic erase or secure overwrite) is required for higher-sensitivity categories; physical destruction for media that cannot be reliably sanitized. Physical CUI documents must be cross-cut shredded to particles of 1mm x 5mm or smaller. Document all disposal actions for your evidence package.

Does my personal laptop count as a CUI system?

If CUI is accessed from or stored on a personal device, that device is in scope for your CMMC assessment. This is one of the most common and overlooked CUI boundary issues. The solution is either to explicitly prohibit CUI access from personal devices and enforce that prohibition technically, or to treat those devices as in-scope systems subject to all applicable NIST SP 800-171 controls. Most organizations choose the prohibition approach and implement technical controls to enforce it.

What is the CUI Registry?

The CUI Registry is maintained by the National Archives and Records Administration (NARA) at archives.gov and defines all authorized CUI categories, the laws or regulations establishing each one, and any specific handling restrictions. It is the authoritative source for determining whether specific information qualifies as CUI. Defense contractors should reference it when evaluating whether information they receive requires CUI-level protection, particularly for less common categories.

Air-gapped. On-premises.

1TEN is a GRC platform built for the security posture CMMC demands. No cloud. No subscriptions. No data leaving your environment.

Request a Demo