Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Who Is Responsible for CUI Compliance at a University?

No single office owns CUI compliance at a university. This guide breaks down the distinct responsibilities of the institutional CUI program lead, the IT security office (NIST SP 800-171/CMMC), the sponsored programs office (contract flow-down), and the principal investigator.

No single office at a university “owns” Controlled Unclassified Information (CUI) compliance end to end. It is a distributed responsibility that runs across at least four functions — an institutional CUI program lead, the IT security office, the sponsored programs (research administration) office, and the individual principal investigator and research team — each accountable for a different piece of the same obligation. Confusion about which office does what is one of the most common reasons a university’s CUI program stalls or fails an assessment. This guide breaks down who is actually responsible for what, and how those roles are supposed to coordinate.

What Counts as CUI, Briefly

Controlled unclassified information is United States government information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy, but that is not classified under Executive Order 13526. It was formalized by Executive Order 13556 (2010) and is overseen governmentwide by the National Archives and Records Administration (NARA), whose CUI Registry enumerates categories such as Export Controlled, Privacy, and Procurement and Acquisition information. A research contract or subaward that specifies CUI categories typically also imposes a technical safeguarding standard — most commonly NIST SP 800-171 — as a condition of the award.

The Institutional CUI Program Lead — and Why It Is Not a “Senior Agency Official”

Executive Order 13556 directs each federal executive branch agency — not each contractor, grantee, or university — to designate a Senior Agency Official (SAO) accountable for that agency’s own CUI program, under the implementing regulation at 32 CFR Part 2002. A university is not a federal agency, so the EO does not require an institution to name an SAO of its own. What it does face is the contractual, downstream version of the same obligation: when an award or subaward’s terms and conditions flow down CUI-handling requirements — most commonly through DFARS 252.204-7012 for Department of Defense-funded work, or an equivalent clause from another federal agency — the institution becomes responsible for implementing the required safeguarding controls, without itself becoming subject to EO 13556’s agency-level SAO designation requirement.

In practice, most research-intensive universities create an internal equivalent anyway, because someone still has to coordinate across IT, sponsored programs, and individual labs. Job postings for this coordinating role are increasingly common at research universities, typically titled something like “CUI Manager,” “Assistant Research Security Officer, CUI Manager,” or “Information Security Compliance Manager,” and the role most often sits inside the information security office or the Office of the Vice President for Research (OVPR) — sometimes as a dedicated position, sometimes as a function absorbed into a broader research security officer role established to satisfy NSPM-33. Regardless of title, this role’s actual job is rarely hands-on technical implementation; it is program-level: maintaining an inventory of which awards and systems touch CUI, writing and updating institutional CUI policy, coordinating training, and serving as the point of contact when the IT security office, sponsored programs, and a PI need to reconcile a specific award’s requirements.

The IT Security Office: NIST SP 800-171 and CMMC Technical Controls

Once an award is identified as involving CUI, the technical safeguarding burden falls to the institution’s IT or information security office. NIST SP 800-171 (Revision 2 remains the version referenced by DFARS 252.204-7012 as of this writing) specifies 110 security requirements across 14 control families — access control, incident response, media protection, system and communications protection, and others — that any non-federal system processing CUI must implement. For Department of Defense-funded work, those same controls are the basis for CMMC (Cybersecurity Maturity Model Certification) assessment, most commonly at CMMC Level 2.

The IT security office’s core responsibilities typically include:

  • Scoping the CUI boundary for a given award — usually implemented as a segmented, isolated network enclave rather than an attempt to bring the entire campus network into compliance, since a boundary drawn too broadly multiplies audit burden for no security benefit.
  • Building and maintaining the System Security Plan (SSP) and Plan of Action and Milestones (POA&M) that document how each of the 110 requirements is met or is being remediated.
  • Configuring and operating the actual technical controls — access restrictions, encryption, logging, endpoint management — inside the CUI enclave.
  • Preparing for and supporting self-assessment, third-party (C3PAO) assessment, or government-led (DIBCAC) assessment, depending on what the specific contract requires.

What the IT security office typically does not do on its own is decide which awards are in scope in the first place, or negotiate the contract language that creates the obligation — that determination starts upstream, with the contract itself. For institutions using a broader information-security-management framework rather than (or alongside) NIST SP 800-171, see CASRAI’s ISO 27001 for Research Data Security guide.

Sponsored Programs (Research Administration): Contract Clause Flow-Down

The sponsored programs or research administration office is where a CUI obligation typically first enters the institution, because it is the office that reviews the award terms before acceptance. Its responsibilities include:

  • Identifying, during pre-award review, whether a solicitation or contract contains a clause that flows down CUI-handling or NIST SP 800-171 requirements — commonly DFARS 252.204-7012 and, increasingly, DFARS 252.204-7021 for CMMC status.
  • Flagging those awards to the institutional CUI lead and IT security office before acceptance, so the technical scoping work in the previous section can start early rather than after the award is already active.
  • Ensuring the same flow-down obligation is correctly passed to any subrecipient on a subaward, and monitoring that the subrecipient’s own compliance posture is adequate for the CUI it will handle.
  • Post-award, tracking modifications or re-scopes that could newly bring CUI into a previously unaffected award.

Many institutions split this work between separate pre-award and post-award functions rather than a single generalist office; see CASRAI’s Departmental vs. Central Sponsored Programs Office guide for how that organizational split typically works, and NIH Foreign Subawards for how flow-down obligations extend to subrecipients specifically. What sponsored programs staff are not expected to do is implement or assess the technical controls themselves — their role is contractual identification and flow-down, not systems administration.

The Principal Investigator and Individual Researchers

Compliance ultimately depends on the people actually handling the information day to day. A principal investigator and their research team are responsible for:

  • Recognizing CUI markings on sponsor-provided material and treating marked material according to the institution’s approved handling procedures.
  • Working with CUI only inside the approved system or enclave — not copying it to personal devices, unapproved cloud storage, or unmanaged lab computers, all of which sit outside the boundary the IT security office actually secured.
  • Restricting access to authorized project personnel only, and not sharing CUI with students, collaborators, or subcontractors who have not been cleared to receive it under the award’s terms.
  • Completing required CUI-handling and information-security training before working with CUI, and on whatever renewal cycle the institution sets.
  • Reporting a suspected mishandling incident or data spill immediately, rather than attempting to remediate it informally — timely reporting materially affects how an incident is assessed.

A PI cannot delegate this responsibility away by assuming “IT handles security” — the safeguarding controls only work if the people generating and using the CUI actually operate inside them.

Where CUI Overlaps with Export Control

CUI and export control are governed by different legal bases but frequently apply to the same underlying research. The CUI Registry’s “Export Controlled” category exists specifically because export-controlled technical data — governed by the Export Administration Regulations (EAR) and the International Traffic in Arms Regulations (ITAR) — is also treated as a CUI category once shared under a government contract. That means a university’s export control office and its CUI program frequently need to coordinate on the same award, particularly around fundamental research exemption determinations, foreign national access, and deemed exports. See CASRAI’s Export Control (EAR/ITAR) and International Research Collaboration guide and The Four Pillars of Export Control Compliance for how that office structures its own work. Institutions handling classified as well as CUI research should also see 32 CFR Part 117 (NISPOM), which governs the separate, more stringent classified-information regime.

How These Roles Fit Into a Broader Research Security Program

At many institutions, CUI compliance is not administered as a standalone program but as one component of the broader research security program that NSPM-33 directs federal agencies to require of their funded institutions. See CASRAI’s NSPM-33 Research Security Program Requirements guide for the four mandated program elements, and Research Security Training for how the training obligation referenced above is typically structured and which agencies require it. Framing CUI compliance as one thread inside that larger program — rather than a siloed IT project — is generally what keeps the four roles above coordinated instead of working at cross purposes.

A Practical Summary of Who Does What

  • Institutional CUI program lead / research security officer: maintains the inventory of CUI-touching awards, owns institutional CUI policy, coordinates training, and is the point of contact reconciling requirements across the other three roles.
  • IT security office: scopes the CUI system boundary, builds and maintains the SSP/POA&M, implements and operates the technical controls, and supports assessment.
  • Sponsored programs / research administration office: identifies CUI-related flow-down clauses at pre-award review, flags affected awards early, and ensures subrecipients are held to the same obligation.
  • Principal investigator and research team: handle CUI only within the approved system, restrict access to authorized personnel, complete required training, and report incidents promptly.

Frequently Asked Questions

Who is legally responsible for CUI compliance at a university?

The institution as a whole is the party bound by the contract or subaward clause that imposes the requirement. Responsibility for actually meeting it is distributed across the roles above, coordinated by whichever office the institution designates as its CUI program owner — there is no single federally mandated role a university must appoint, unlike the agency-level Senior Agency Official requirement that applies only to federal agencies themselves.

Does a university need to designate a Senior Agency Official for CUI?

No. The Senior Agency Official designation in Executive Order 13556 and 32 CFR Part 2002 applies to federal executive branch agencies, not to universities or other non-federal organizations that handle CUI under a contract or subaward. Universities commonly create an analogous internal role anyway, but it is an institutional choice, not a regulatory requirement under the EO.

Is CUI compliance the IT department’s responsibility alone?

No. IT security implements and operates the technical controls, but it typically has no visibility into which awards carry CUI obligations until sponsored programs flags them at pre-award review, and it cannot enforce day-to-day handling practices inside a lab — that depends on the PI and research team.

Do individual researchers need CUI-specific training?

Yes. Because safeguarding controls only work if the people generating and using CUI actually follow them, institutions typically require CUI-handling and information-security training before a researcher is granted access, in addition to any broader research security training their funder requires.

How is CUI compliance different from export control compliance?

They are governed by different legal authorities — CUI by Executive Order 13556 and agency-specific contract clauses, export control by the EAR and ITAR — but they frequently apply to the same technical data, since the CUI Registry’s “Export Controlled” category exists specifically to cover export-controlled technical data shared under a government contract. Institutions typically need their export control office and CUI program to coordinate on any award where both apply.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →