Skip to main content
v2026.11,858 entries · CC-BY 4.0

Direct comparison

CUI Basic vs. CUI Specified

How CUI Basic and CUI Specified differ under 32 CFR 2002: safeguarding, dissemination, and marking rules researchers must follow.

Written and maintained by CASRAI Editorial Board

Last updated

Ask CASRAI · free to try

Ask about CUI Basic vs. CUI Specified

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

How do CUI Basic, CUI Specified compare side by side?

The table below compares CUI Basic, CUI Specified across 8 procurement-relevant dimensions, from what determines the category through practical effect.

Side-by-side comparison

DimensionCUI BasicCUI Specified
What determines the categoryAuthorizing law/regulation/policy sets no unique controls -- uniform CUI Basic rules in 32 CFR 2002 apply.Authorizing law/regulation/policy sets its own specific handling, dissemination, or safeguarding requirements.
Safeguarding standardNIST SP 800-171 baseline on nonfederal systems (32 CFR 2002.14).Same NIST SP 800-171 baseline, plus any additional controls the authorizing source requires.
Dissemination controlsDefault CUI Limited Dissemination Controls, applied uniformly.Category-specific limits set by the authorizing source (e.g., distribution statements, narrower need-to-know).
Banner markingCUICUI//SP-[CODE] (registry-assigned category code, e.g., CUI//SP-CTI)
Where it's listedCUI Registry, Basic Authorities column for the category.CUI Registry, Specified Authorities column for the category.
Research-relevant examplesGeneral proprietary business information; general privacy information.Controlled Technical Information (DFARS 252.204-7012); export-controlled technical data (EAR/ITAR).
Discretion to applyApplied by default whenever the source authority is silent.No discretion -- the designating authority must apply the exact controls the specific law/regulation dictates.
Practical effectStandard CUI safeguarding and banner marking on documents, email, and systems.Basic protections plus category-specific extras (distribution statements, access limits) -- treating it as Basic under-protects it.

Common questions

Common questions about CUI Basic vs CUI Specified

How do I know if information is CUI Basic or CUI Specified?

+

Check the CUI Registry entry for the category the information falls under. If the entry lists a Specified Authorities column citing a law, regulation, or Government-wide policy with its own handling requirements, the information is CUI Specified and those requirements govern. If only Basic Authorities is listed, the uniform CUI Basic controls in 32 CFR 2002 apply. The award, contract, or data use agreement that made the information CUI should also identify the governing authority -- when in doubt, confirm with your institution's research security or export control office.

Can CUI Specified be less restrictive than CUI Basic?

+

No. CUI Specified exists only where the authorizing source imposes controls that differ from Basic, and in practice this means additional restrictions -- narrower dissemination, extra marking, distribution statements -- not fewer. 32 CFR 2002.4 defines CUI Specified as the subset where the authorizing law, regulation, or policy contains specific handling controls beyond the uniform Basic default.

Is Controlled Technical Information (CTI) CUI Basic or CUI Specified?

+

CTI -- technical data and computer software with military or space application, controlled under DFARS 252.204-7012 -- is a CUI Specified category in the CUI Registry, marked CUI//SP-CTI, because DFARS imposes distribution-statement and access requirements beyond the CUI Basic default.

Does NIST SP 800-171 apply to both CUI Basic and CUI Specified?

+

Yes, as the safeguarding floor for CUI on nonfederal systems under 32 CFR 2002.14. A CUI Specified category can require additional controls beyond NIST SP 800-171 if its authorizing source specifies them -- 800-171 is the minimum, not necessarily the ceiling, for Specified categories.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Ask CASRAI · Regulatory Radar

Research-admin question? Get an answer that links its sources.

An AI assistant specialized in research administration. Every answer links its sources to check before you act. 2 questions free, no account. $29/month after.

  • Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
  • Every answer numbers its sources and links each one, so you can check the source yourself.