Controlled Unclassified Information · 1 of 3

What counts as controlled unclassified information

← All Insights

In short

  • CUI must rest on a law, regulation or Government-wide policy.
  • CUI Specified has controls set by its own authority.
  • The rule reaches contractors through agreements.
Published10 October 2026
Last reviewed10 October 2026
Sources current as of10 October 2026

1. One program for unclassified controls

The rule at 32 CFR part 2002 describes the executive branch’s Controlled Unclassified Information (CUI) Program. It sets policy for designating, handling and decontrolling information that qualifies as CUI (32 CFR 2002.1(a)). The program standardizes how the executive branch handles information that requires protection under laws, regulations or Government-wide policies but is not classified (32 CFR 2002.1(b)). That excludes information classified under Executive Order 13526 or the Atomic Energy Act of 1954.

All unclassified information throughout the executive branch that requires any safeguarding or dissemination control is CUI (32 CFR 2002.1(c)). Law, regulation, including part 2002, or Government-wide policy must require or permit such controls. Agencies therefore may not apply safeguarding or dissemination controls to unclassified information other than those consistent with the CUI Program.

Before the program, agencies often used ad hoc, agency-specific policies, procedures and markings (32 CFR 2002.1(d)). That patchwork led agencies to mark and handle information inconsistently and created obstacles to sharing. An executive branch-wide policy balances the need to safeguard CUI with the public interest in sharing information appropriately and without unnecessary burdens (32 CFR 2002.1(e)).

2. The definition

CUI covers information that the Government creates or possesses, and information an entity creates or possesses for or on behalf of the Government. The information must be something that a law, regulation or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)). CUI does not include classified information. Also excluded is information a non-executive branch entity keeps in its own systems. That exclusion applies where the information did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency.

Information qualifies on the basis that a law, regulation or Government-wide policy requires or specifically permits safeguarding or dissemination controls (32 CFR 2002.4(nn)). Specific permission can include language such as “is exempt from” release requirements or “is responsible for protecting” the information. It does not include general agency authority to make decisions, risk assessments or other broad discretionary powers.

3. CUI Basic and CUI Specified

An authority may require or permit controls in three ways (32 CFR 2002.4(h)). If it gives no specific controls, the information is CUI Basic. If it provides specific controls, the information is CUI Specified. If it specifies only some controls, the information is CUI Specified, with CUI Basic controls where the authority is silent.

Agencies handle CUI Basic under the uniform controls in part 2002 and the CUI Registry (32 CFR 2002.4(j)). CUI Specified controls may be more stringent than, or simply differ from, those for CUI Basic (32 CFR 2002.4(r)). The distinction is that the underlying authority spells out specific controls for CUI Specified information and does not for CUI Basic. The CUI Registry shows which authorities include such specific requirements.

4. Categories and the CUI Registry

CUI categories and subcategories are the exclusive designations for identifying unclassified information that an authority requires or permits agencies to control (32 CFR 2002.12(a)). Agencies may use only those categories or subcategories approved by the CUI Executive Agent and published in the CUI Registry (32 CFR 2002.12(b)). The controls for all CUI Basic categories and subcategories are the same, but CUI Specified controls can differ from CUI Basic ones and from each other (32 CFR 2002.4(k)). A category may be Specified while some or all of its subcategories are not, and the reverse.

The Executive Agent maintains the CUI Registry as the authoritative central repository for all guidance, policy, instructions and information on CUI, other than the Executive Order and part 2002 (32 CFR 2002.10(a)). The Registry is publicly accessible. It lists authorized categories and subcategories, their markings, decontrol procedures and the laws, regulations or policies on which each is based. Agencies and authorized holders must follow the Registry’s instructions in addition to the Order and part 2002 (32 CFR 2002.10(b)).

5. Who runs the program

The Executive Order on CUI designates the National Archives and Records Administration (NARA) as the CUI Executive Agent (32 CFR 2002.6(a)). NARA oversees agency efforts to comply with the Order, part 2002 and the CUI Registry. NARA has delegated those responsibilities to the Director of the Information Security Oversight Office (ISOO), whose staff manage the federal program (32 CFR 2002.6(b)).

Among its duties, the Executive Agent approves categories and subcategories and publishes them in the Registry (32 CFR 2002.8(a)(7)). It also considers and resolves, as appropriate, disputes, complaints and suggestions about the program from entities inside or outside the Government (32 CFR 2002.8(a)(11)). Each agency head designates a CUI senior agency official responsible for oversight of the agency’s program (32 CFR 2002.8(b)(2)). That official must be at the Senior Executive Service level or equivalent (32 CFR 2002.8(c)(1)). The official also sets up a contact for holders who receive unmarked or improperly marked CUI, and a process to accept and manage challenges to CUI status (32 CFR 2002.8(c)(12) and 32 CFR 2002.8(c)(13)).

6. Reach to contractors

Part 2002 applies to all executive branch agencies that designate or handle CUI (32 CFR 2002.1(f)). It does not apply directly to non-executive branch entities, but it applies indirectly to non-executive branch CUI recipients through incorporation into agreements. Agreements and arrangements include contracts, grants, licenses, certificates, memoranda of agreement or understanding, and information-sharing agreements (32 CFR 2002.4(c)).

A non-executive branch entity is a person or organization operated outside any official executive branch capacity, including private organizations and state, tribal or local government elements (32 CFR 2002.4(gg)). The term excludes foreign entities and those who receive information under federal disclosure laws such as the Freedom of Information Act. Information that is neither CUI nor classified is uncontrolled unclassified information, though agencies must still handle it under Federal Information Security Modernization Act requirements (32 CFR 2002.4(ss)). How CUI is protected is covered in safeguarding CUI in practice.

Key terms

CUIUnclassified information that an authority requires or permits agencies to safeguard or control.
CUI BasicCUI handled under uniform controls because the authority sets none of its own.
CUI SpecifiedCUI whose authority sets specific handling controls.
CUI RegistryThe public repository of categories, markings and guidance.
CUI Executive AgentNARA, which has delegated the role to the ISOO Director.

Every statement above links to the document behind it. The full source list for this piece is on the sources page.

This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.

How Sentfore supports this

Contractors abroad often receive CUI with their tasks. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.