Direct comparison
CUI Basic vs. CUI Specified
How CUI Basic and CUI Specified differ under 32 CFR 2002: safeguarding, dissemination, and marking rules researchers must follow.
Side-by-side comparison
| Dimension | CUI Basic | CUI Specified |
|---|---|---|
| What determines the category | Authorizing law/regulation/policy sets no unique controls -- uniform CUI Basic rules in 32 CFR 2002 apply. | Authorizing law/regulation/policy sets its own specific handling, dissemination, or safeguarding requirements. |
| Safeguarding standard | NIST SP 800-171 baseline on nonfederal systems (32 CFR 2002.14). | Same NIST SP 800-171 baseline, plus any additional controls the authorizing source requires. |
| Dissemination controls | Default CUI Limited Dissemination Controls, applied uniformly. | Category-specific limits set by the authorizing source (e.g., distribution statements, narrower need-to-know). |
| Banner marking | CUI | CUI//SP-[CODE] (registry-assigned category code, e.g., CUI//SP-CTI) |
| Where it's listed | CUI Registry, Basic Authorities column for the category. | CUI Registry, Specified Authorities column for the category. |
| Research-relevant examples | General proprietary business information; general privacy information. | Controlled Technical Information (DFARS 252.204-7012); export-controlled technical data (EAR/ITAR). |
| Discretion to apply | Applied by default whenever the source authority is silent. | No discretion -- the designating authority must apply the exact controls the specific law/regulation dictates. |
| Practical effect | Standard CUI safeguarding and banner marking on documents, email, and systems. | Basic protections plus category-specific extras (distribution statements, access limits) -- treating it as Basic under-protects it. |
Common questions
FAQ
How do I know if information is CUI Basic or CUI Specified?+
Check the CUI Registry entry for the category the information falls under. If the entry lists a Specified Authorities column citing a law, regulation, or Government-wide policy with its own handling requirements, the information is CUI Specified and those requirements govern. If only Basic Authorities is listed, the uniform CUI Basic controls in 32 CFR 2002 apply. The award, contract, or data use agreement that made the information CUI should also identify the governing authority -- when in doubt, confirm with your institution's research security or export control office.
Can CUI Specified be less restrictive than CUI Basic?+
No. CUI Specified exists only where the authorizing source imposes controls that differ from Basic, and in practice this means additional restrictions -- narrower dissemination, extra marking, distribution statements -- not fewer. 32 CFR 2002.4 defines CUI Specified as the subset where the authorizing law, regulation, or policy contains specific handling controls beyond the uniform Basic default.
Is Controlled Technical Information (CTI) CUI Basic or CUI Specified?+
CTI -- technical data and computer software with military or space application, controlled under DFARS 252.204-7012 -- is a CUI Specified category in the CUI Registry, marked CUI//SP-CTI, because DFARS imposes distribution-statement and access requirements beyond the CUI Basic default.
Does NIST SP 800-171 apply to both CUI Basic and CUI Specified?+
Yes, as the safeguarding floor for CUI on nonfederal systems under 32 CFR 2002.14. A CUI Specified category can require additional controls beyond NIST SP 800-171 if its authorizing source specifies them -- 800-171 is the minimum, not necessarily the ceiling, for Specified categories.







