Examples
Worked examples
- Is an instance
A research contract clause requires the institution to implement NIST SP 800-171 controls because the project involves CUI.
- Is an instance
CUI markings on a sponsor-provided dataset trigger restricted handling at the receiving lab.
Counter-examples
Looks similar, but isn't
- Not an instance
Information that is publicly released under standard government open-data policies is not CUI.
- Not an instance
Classified Secret information is not CUI; it is governed by classified information handling rules.
Editorial commentary
Controlled Unclassified Information (CUI) is U.S. government information that requires safeguarding or dissemination controls under a law, regulation, or government-wide policy, but that is not classified under Executive Order 13526 or the Atomic Energy Act. CUI was formalised as a single, government-wide category by Executive Order 13556 (November 2010), which replaced a patchwork of dozens of agency-specific “sensitive but unclassified” markings (For Official Use Only, Sensitive Security Information, Law Enforcement Sensitive, and similar labels) with one standardised system. It is distinguished from classified information by the absence of a formal classification level (Confidential, Secret, Top Secret) — CUI is unclassified information that still needs protecting, not a lower tier of classification.
Who is responsible for CUI: the roles, from executive agent down to the researcher
CUI responsibility is layered across several distinct roles, each set out in Executive Order 13556 and its implementing regulation, 32 CFR Part 2002. Getting the layers right matters for a research institution because “who is responsible” has a different answer depending on which layer of the question is being asked.
- NARA, as CUI Executive Agent. Executive Order 13556 designates the National Archives and Records Administration (NARA) as the CUI Executive Agent, responsible for implementing the Order and overseeing agency compliance with it, with 32 CFR Part 2002, and with the CUI Registry.
- ISOO, as NARA’s delegated operating authority. NARA has delegated day-to-day administration of the CUI Program to the Director of its Information Security Oversight Office (ISOO). ISOO staff carry out the Program’s actual oversight work: maintaining the CUI Registry, issuing implementing policy, and reviewing agency self-inspection programs.
- Individual federal agencies. Each executive branch agency that handles CUI is responsible for implementing the Program internally — designating CUI at the point information is created or received, applying the correct category from the CUI Registry, marking material correctly, training personnel, safeguarding CUI on its own systems, and running self-inspections that ISOO can review. An agency awarding a research grant or contract that will involve CUI is also responsible for flagging that fact in the award and for specifying which CUI category and any applicable CUI Specified handling requirements apply.
- Contractors, grantees, and other non-federal entities — including universities. When an agency shares CUI with a non-executive-branch recipient (a contractor, a grant or cooperative-agreement recipient, or another non-federal partner), 32 CFR 2002 expects the agency to do so through a written agreement or arrangement that includes CUI-specific provisions, rather than informally. For a university or research institution named in such an agreement, responsibility runs directly to it as the receiving organization: implementing the safeguarding controls the agreement calls for, marking and handling CUI according to the CUI Registry category specified, restricting access to authorized personnel, and reporting incidents — not just to individual researchers who happen to touch the data. In practice, the security-control baseline most research awards point to for this is NIST SP 800-171, which was written specifically to describe how a nonfederal system or organization protects CUI, and which many federal research sponsors incorporate into award terms by reference (DoD awards typically do so through DFARS clause 252.204-7012, which also carries its own cyber-incident reporting obligations).
- The individual researcher or staff member. At the working level, whoever creates, receives, stores, transmits, or disposes of CUI is responsible for following the institution’s implementation of the controls above — using the correct markings, keeping CUI on approved systems, not forwarding it to unauthorized recipients or personal accounts, and following the destruction requirements for the material’s CUI category. This obligation exists because the institution accepted it in the award terms, which is why research administrators, not just IT security, need to know it’s there before a CUI-bearing award is accepted.
The CUI Registry and CUI categories
The CUI Registry, maintained by ISOO, is the government-wide, publicly available catalog of every approved CUI category and subcategory, the law/regulation/policy authorizing each one, and the specific handling requirements that apply to it. Categories relevant to research administration include Export Controlled, Privacy, Procurement and Acquisition, Proprietary Business Information, Controlled Technical Information, and Defense-related categories, among others. A given piece of information is only CUI if it falls within a category actually listed in the Registry — a sponsor or agency cannot invent a new CUI category informally; it has to already exist in the Registry or be added to it through the Executive Agent.
CUI Basic vs. CUI Specified
Within the Registry, every category is designated as either CUI Basic (subject to the uniform, government-wide safeguarding and dissemination controls set out in 32 CFR 2002) or CUI Specified (subject to those same baseline controls, plus additional, more restrictive requirements set by the specific law, regulation, or policy that authorizes the category — for example, export-controlled technical data carries handling requirements beyond the CUI Basic floor). Getting this distinction wrong is a common source of under-protection: treating a CUI Specified category as if it only needed CUI Basic-level controls misses the additional requirement the authorizing authority actually imposed. See CUI Basic vs. CUI Specified: Marking and Safeguarding for a full side-by-side comparison of what changes between the two.
Practical implications for research institutions
- Confirm at proposal stage, not after award, whether a solicitation or award is expected to involve CUI — the answer determines whether NIST SP 800-171 implementation, cover sheets/marking practices, and (for many DoD and some other federal awards) a Supplier Performance Risk System (SPRS) self-assessment score need to be in place before data starts flowing. See NIST SP 800-171 and CUI in University Research and SPRS Score: Calculating and Submitting Your NIST 800-171 Assessment.
- Assign institutional, not just individual, responsibility — a CUI-bearing award’s compliance obligations attach to the institution as the receiving organization under its agreement with the sponsoring agency, which is why research security offices, not individual PIs, typically own the underlying safeguarding program.
- Get marking right at the document level; see CUI Cover Sheets and Marking: A Working Guide for the mechanics of applying CUI banner markings, designation indicators, and category markings correctly.
- Treat CUI compliance as one part of a broader research-security posture — see Research Security for how CUI handling fits alongside export controls, foreign-influence disclosure, and other federal research-security requirements that often apply to the same award.
Frequently asked questions
Who is responsible for CUI?
Responsibility is layered: NARA is the CUI Executive Agent under Executive Order 13556, with day-to-day Program administration delegated to the Director of its Information Security Oversight Office (ISOO); individual federal agencies are responsible for designating, marking, and safeguarding CUI within their own operations and for flagging CUI obligations in the awards they issue; and contractors, grantees, and other non-federal recipients named in a written agreement — including universities — are responsible for implementing the safeguarding controls that agreement requires, typically the NIST SP 800-171 control set.
Is CUI the same as classified information?
No. CUI is unclassified information that nonetheless requires safeguarding or dissemination controls under a law, regulation, or government-wide policy. It has no formal classification level and is governed by Executive Order 13556 and 32 CFR Part 2002, not by the classified-information framework under Executive Order 13526.
Does a university have to comply with CUI requirements on its own initiative?
Only where it has agreed to — through an award or agreement with a federal agency that includes CUI provisions. There is no freestanding legal obligation for a university to implement CUI safeguards absent such an agreement, but once an award incorporates CUI-handling terms (commonly by requiring NIST SP 800-171 implementation), the institution is contractually bound to them for the life of that award.
What security controls does a research institution typically need for CUI?
Most federal research awards that involve CUI point to NIST SP 800-171, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations,” as the baseline control set. DoD awards commonly incorporate this by reference through DFARS clause 252.204-7012, which adds its own cyber-incident reporting timeline on top of the control implementation itself.
Where can I find the official list of CUI categories?
The CUI Registry, maintained by NARA’s Information Security Oversight Office and published at archives.gov/cui, is the authoritative, government-wide catalog of every approved CUI category and subcategory, the authority behind each one, and its specific handling requirements.
Related terms
Also known as
CUI
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Controlled unclassified information (CUI)"
vocab-term-identifier="https://casrai.org/dictionary/term/controlled-unclassified-information-cui" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/controlled-unclassified-information-cui",
"name": "Controlled unclassified information (CUI)",
"identifier": "https://casrai.org/dictionary/term/controlled-unclassified-information-cui",
"description": "United States government information that requires safeguarding or dissemination controls pursuant to law, regulation, or government-wide policy, but is not classified under Executive Order 13526 or the Atomic Energy Act.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/research-security#set",
"url": "https://casrai.org/dictionary/term/controlled-unclassified-information-cui",
"sameAs": [
"CUI"
],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-08-22T11:57:46",
"inLanguage": "en"
}






