Skip to main content
Category: Data Protection & Privacy

Controlled Unclassified Information

Also known as:
Simply put

Controlled Unclassified Information (CUI) is sensitive government-related information that is not classified but still requires protection under law, regulation, or governmentwide policy. It covers information the government must safeguard or restrict from unrestricted sharing, even though it does not meet the criteria for formal classification.

Formal definition

CUI is a category of unclassified information within the U.S. federal government, defined in Executive Order 13556 and 32 CFR § 2002.4(h), that law, regulation, or governmentwide policy requires to have safeguarding or dissemination controls, excluding information already subject to classification. The CUI program standardizes how such information is identified, marked, handled, and protected across federal agencies and their partners, replacing prior agency-specific ad hoc designations.

Why it matters

For organizations that work with or supply the U.S. federal government, Controlled Unclassified Information (CUI) represents a category of data that carries legal and contractual protection obligations even though it is not classified. Because CUI is defined by law, regulation, or governmentwide policy rather than by any single agency's discretion, the requirement to safeguard it can attach to a wide range of routine business information, from technical documents to research data. Mishandling CUI can expose an organization to contract loss, regulatory consequences, and reputational damage, which makes it a governance and business-risk concern rather than a purely technical one.

The CUI program was established under Executive Order 13556 to replace the patchwork of inconsistent, agency-specific designations that previously governed sensitive-but-unclassified information. Standardizing how such information is identified, marked, handled, and protected across federal agencies and their partners was intended to reduce ambiguity about what needed protection and how. For security leaders, this history matters because it clarifies that CUI obligations often flow through the government's partners and contractors, meaning that responsibility does not stop at the agency boundary.

Accountability for correctly identifying and protecting CUI generally remains with the organization and its officers that hold or receive the information. A security leader can advise on marking, handling, and safeguarding practices and help build a program aligned to the applicable requirements, but the legal and organizational responsibility to meet those obligations rests with the client. Whether an organization succeeds in protecting CUI often depends on organizational maturity, defined scope of the contracts involved, and the cooperation of stakeholders who create and handle the information day to day.

Who it's relevant to

Federal contractors and suppliers
Organizations that receive or generate information under government contracts may be obligated to safeguard CUI even when they are not federal agencies. These obligations often flow down through contractual terms, so contractors should understand which categories apply to their work and what safeguarding and dissemination controls are required.
Security and risk leaders (including virtual and fractional CISOs)
A vCISO or fractional CISO can help an organization identify where CUI may exist, establish marking and handling practices, and build a program aligned to applicable requirements. This is advisory and governance work; legal and organizational accountability for correctly protecting CUI typically remains with the client organization and its officers, and the value of the engagement depends heavily on stakeholder access and cooperation.
Research institutions and universities
Institutions conducting government-related research may encounter CUI, and its handling can intersect with export controls and other compliance regimes. Because the requirements derive from law, regulation, or governmentwide policy, research administrators should confirm which controls apply to specific projects rather than assuming a single uniform standard.
Compliance and legal teams
Because CUI status is triggered by external legal and policy sources, compliance and legal functions play a central role in interpreting which requirements apply and how they map to the organization's contracts and information. Coordination between these teams and security leadership helps ensure that safeguarding and dissemination controls reflect actual obligations.

Inside CUI

Definition and Origin
Controlled Unclassified Information (CUI) is information that requires safeguarding or dissemination controls under applicable laws, regulations, and government-wide policies, but that is not classified. It typically arises in the context of information created or possessed on behalf of the U.S. federal government by contractors and other nonfederal organizations.
CUI Categories
CUI is organized into categories and subcategories that reflect the type of sensitive information involved, such as controlled technical information, financial information, or privacy-related information. Category applicability often varies by the specific contract or data type an organization handles.
Marking and Handling Requirements
CUI generally carries marking, labeling, and dissemination-control obligations intended to signal how the information must be protected and shared. The specifics may vary by category and by the requirements flowed down in a given agreement.
Relationship to CMMC and Safeguarding Standards
Protection of CUI is commonly associated with security requirements referenced in frameworks and standards such as CMMC. A virtual CISO engagement may support readiness against these requirements, but supporting readiness is distinct from asserting or guaranteeing certification or assessment outcomes.
Accountability Context
Legal and organizational accountability for properly identifying, marking, and safeguarding CUI typically remains with the client organization and its officers. A virtual CISO advises and directs on CUI governance but does not generally assume regulatory or contractual accountability unless a contract explicitly specifies it.

Common questions

Answers to the questions practitioners most commonly ask about CUI.

Does a virtual CISO become accountable for protecting our Controlled Unclassified Information (CUI)?
Generally, no. A virtual CISO typically advises on and directs the design of controls intended to safeguard CUI, but legal and organizational accountability for CUI handling usually remains with the client organization and its officers. Unless a specific contract states otherwise, a vCISO provides strategy and governance guidance rather than assuming regulatory accountability for compliance failures. It is a common mistake to assume that engaging a vCISO transfers liability for mishandled CUI away from the organization.
Can a virtual CISO guarantee that our handling of CUI is compliant or certified?
Not typically. A virtual CISO can often support readiness efforts and help align practices with the applicable requirements, but supporting readiness is not the same as asserting certification or guaranteeing compliance. Certification and formal attestation, where they apply, generally involve independent assessors and processes outside a vCISO engagement. Expert practitioners would caution against treating advisory guidance as a compliance guarantee, since outcomes depend on organizational cooperation, defined scope, and actual implementation.
How does a virtual CISO typically help an organization begin managing CUI?
In many engagements, a virtual CISO starts at the governance and strategy level: helping identify where CUI may exist, establishing data classification and handling policies, and defining the roles responsible for its protection. This work is advisory and directive in nature. Hands-on operational tasks such as configuring tools or monitoring systems generally fall outside the typical scope unless explicitly contracted. Value often depends on the organization's maturity and the vCISO's access to relevant stakeholders.
What is typically out of scope when a virtual CISO addresses CUI protection?
A virtual CISO generally provides executive-level guidance on strategy, governance, risk management, and program development. Operational execution such as SOC monitoring, tool administration, and incident response actions is typically out of scope unless specifically included in the engagement. It is a common error to expect a vCISO to function as a managed security service provider or to replace an entire security team; the role is a governance and business risk function rather than a hands-on operational one.
How can we structure a vCISO engagement to support CUI readiness effectively?
Effective engagements often begin with a clearly defined scope that states which advisory activities are included and which operational tasks, if any, are covered. Because a vCISO is typically a part-time or remote resource, and a fractional CISO may share time across multiple clients, it helps to specify stakeholder access, decision-making expectations, and how the organization will implement recommendations. Readiness value depends heavily on client cooperation and existing organizational maturity, so aligning those factors up front tends to improve results.
What should we retain internally when a virtual CISO advises on CUI handling?
Organizations typically retain accountability for the actual handling of CUI, ownership of security decisions, and the responsibility to implement and sustain the controls a vCISO recommends. A vCISO advises and directs, but internal roles usually carry the responsibility for day-to-day execution and the organization's officers usually carry accountability. Retaining clear internal ownership matters because engagement outcomes vary with how well the organization acts on the guidance provided.

Common misconceptions

CUI is a type of classified information.
CUI is explicitly not classified information. It is unclassified information that nonetheless requires safeguarding or dissemination controls under applicable laws, regulations, and government-wide policies. Treating it as classified misrepresents its handling regime.
Engaging a virtual CISO guarantees compliance or certification for handling CUI.
A vCISO engagement typically supports readiness and governance around CUI-related requirements, such as those referenced in CMMC, but it does not guarantee compliance or certification. Outcomes depend on organizational maturity, client cooperation, defined scope, and any independent assessment involved.
A virtual CISO will operationally protect CUI on the organization's behalf.
A virtual CISO generally provides strategy, governance, and program guidance rather than hands-on operational tasks such as tool administration or monitoring. Operational safeguarding of CUI usually remains the responsibility of the client's internal teams or contracted operational providers unless explicitly scoped into the engagement.

Best practices

Confirm which CUI categories and subcategories apply to the organization based on the specific contracts and data types involved, rather than assuming a single uniform standard.
Establish and document clear marking, labeling, and dissemination-control procedures aligned to the applicable CUI categories, and validate that these obligations match what is flowed down in relevant agreements.
Clarify in the engagement scope whether the virtual CISO is advising on CUI governance and readiness versus performing any operational safeguarding tasks, and confirm that accountability remains with the client's officers.
Treat CMMC or similar framework alignment as a readiness effort, distinguishing between supporting preparation and asserting certification or assessment results.
Ensure the virtual CISO has access to the stakeholders, contracts, and data-flow information needed to accurately identify where CUI resides, since engagement value depends on client cooperation and organizational maturity.
Document decisions and residual risk related to CUI handling so that legal and organizational accountability, which typically stays with the client, is clearly recorded.