Controlled Unclassified Information
Controlled Unclassified Information (CUI) is sensitive government-related information that is not classified but still requires protection under law, regulation, or governmentwide policy. It covers information the government must safeguard or restrict from unrestricted sharing, even though it does not meet the criteria for formal classification.
CUI is a category of unclassified information within the U.S. federal government, defined in Executive Order 13556 and 32 CFR § 2002.4(h), that law, regulation, or governmentwide policy requires to have safeguarding or dissemination controls, excluding information already subject to classification. The CUI program standardizes how such information is identified, marked, handled, and protected across federal agencies and their partners, replacing prior agency-specific ad hoc designations.
Why it matters
For organizations that work with or supply the U.S. federal government, Controlled Unclassified Information (CUI) represents a category of data that carries legal and contractual protection obligations even though it is not classified. Because CUI is defined by law, regulation, or governmentwide policy rather than by any single agency's discretion, the requirement to safeguard it can attach to a wide range of routine business information, from technical documents to research data. Mishandling CUI can expose an organization to contract loss, regulatory consequences, and reputational damage, which makes it a governance and business-risk concern rather than a purely technical one.
The CUI program was established under Executive Order 13556 to replace the patchwork of inconsistent, agency-specific designations that previously governed sensitive-but-unclassified information. Standardizing how such information is identified, marked, handled, and protected across federal agencies and their partners was intended to reduce ambiguity about what needed protection and how. For security leaders, this history matters because it clarifies that CUI obligations often flow through the government's partners and contractors, meaning that responsibility does not stop at the agency boundary.
Accountability for correctly identifying and protecting CUI generally remains with the organization and its officers that hold or receive the information. A security leader can advise on marking, handling, and safeguarding practices and help build a program aligned to the applicable requirements, but the legal and organizational responsibility to meet those obligations rests with the client. Whether an organization succeeds in protecting CUI often depends on organizational maturity, defined scope of the contracts involved, and the cooperation of stakeholders who create and handle the information day to day.
Who it's relevant to
Inside CUI
Common questions
Answers to the questions practitioners most commonly ask about CUI.