The two-layer test
Every CUI determination has two parts and you must apply both:
- Layer 1: the federal definition (32 CFR Part 2002). Information qualifies as CUI only when BOTH of these are true: the government creates or possesses it, or you (an entity such as a contractor) create or possess it for or on behalf of the government; AND a law, regulation, or government-wide policy requires or permits the information to be safeguarded or dissemination-controlled. If either condition fails, it is not CUI, regardless of marking or contract context.
- Layer 2: the category-specific authorities. Identify which CUI category fits the information, then read the authorities listed at the bottom of the NARA CUI Registry entry (and the DoD CUI Registry entry for DoD-equity categories). Those authorities define the actual scope, the explicit exclusions, and who the rule is speaking to. Many authorities are far narrower than the category name implies.
Skipping either layer is the most common source of error. Teams that only read 32 CFR end up with a definition too abstract to be operational. Teams that only read the customer's marking instructions end up overscoping (controlling things that are not CUI) or underscoping (missing categories that apply).
Where the actual definition lives in a NARA Registry entry
When you click into a NARA Registry entry, the page leads with a category description. That description is a NARA-authored summary. It is not the legal definition, it is not binding, and it should not be the last thing you read. Scroll to the bottom of the entry, find the box labeled "Safeguarding and/or Dissemination Authority," and read the authorities themselves. The PDF behind each link, within its section or part, contains the actual sentence or paragraph that defines a regulated information type.
The DoD CUI Registry at dodcui.mil mirrors NARA's category structure but enriches entries for DoD-equity categories by listing the upstream supporting authorities that NARA summarized but did not cite. Read both registries for DoD categories.
The DoDI 5230.24 simplification for DoD-originated technical documents
The Jan 2025 revision of DoD Instruction 5230.24 (Distribution Statements and Distribution Statement Markings on DoD Technical Documents) establishes a unified marking framework that aligns Distribution Statements with the CUI Program. The headline rule: all unclassified Controlled Technical Information must now be marked as CUI. For practical reading of DoD documents you receive:
| Distribution Statement | Meaning | CUI? |
|---|---|---|
| A | Approved for public release; distribution unlimited. | Not CUI. Public information cannot be CUI. |
| B | Distribution authorized to U.S. government agencies only. | CUI. |
| C | Distribution authorized to U.S. government agencies and their contractors only. | CUI. Common for technical data flowed to contractors. |
| D | Distribution authorized to DoD and DoD contractors only. | CUI. Common for defense-specific technical data. |
| E | Distribution authorized to DoD components only. | CUI. Should not normally be in contractor hands. |
| F | Further dissemination only as directed by the controlling DoD office. | CUI. Case-by-case dissemination authority. |
This is operationally clarifying: a DoD-originated document with any Distribution Statement other than A is, under the new guidance, properly CUI, even if it has not yet been remarked with the new CUI banner and Designation Indicator. There is no project to retroactively remark legacy documents, so expect a mix of legacy distribution-statement-marked documents and newly CUI-marked documents for years.
CUI Basic vs CUI Specified
| Type | Definition | Handling |
|---|---|---|
| CUI Basic | CUI without specific safeguarding or dissemination controls beyond the baseline in 32 CFR 2002. | Standard CUI handling per NIST SP 800-171 (CMMC Level 2) at minimum. |
| CUI Specified | CUI with specific safeguarding or dissemination controls required by law, regulation, or government-wide policy (for example, NNPI, Export Controlled). | Standard CUI handling plus the specific category's additional requirements. |
What CUI looks like when properly marked
- Banner marking at the top and bottom of every page: "CUI" alone for Basic, "CUI//[category]" for Specified, with limited dissemination controls appended where applicable.
- Portion markings before each paragraph or portion: "(CUI)" or "(CUI//[category])".
- CUI Designation Indicator (CDI) on the first page identifying the controlling body, the distribution letter code (for DoD documents under the unified framework), the CUI category, and a point of contact for clarification.
For the full marking rules see What are the CUI marking requirements I must apply?.
Situations to push back on
You will hear these three things over and over. None of them holds up under the two-layer test, and each one is worth pushing back on.
- "Everything from the customer is CUI." Public information cannot be CUI. A contract package that is section-marked as CUI but contains the company name, contract number, dollar amount, and program name (all published on USAspending.gov) has overbroad marking. The categories of information present each need to be evaluated against their own authorities. Sections with no governing authority are not CUI.
- "Everything you create on the contract is CUI." The government's interest in contractor-generated work is constrained: agencies must request specific line-item deliverables to receive copies. Federal records are generated when a contractor delivers an item the contract called for. Internal work that is not a deliverable, that the government does not own, and that no underlying authority regulates is not CUI even if it was generated during contract performance.
- "Just ask your contracting officer." Contracting officers are professionally focused on the FAR and DFARS, not the upstream statutes and regulations that define CUI categories. A competent CUI practitioner inside the contractor often has a deeper working knowledge of ITAR, EAR, 10 U.S.C. 130, or the specific authorities behind a category than the CO does. Deferring the whole question to the CO usually produces "treat all of it as CUI," which is operationally expensive and rarely correct. The right move is to do the authority reading yourself, propose a defensible determination, and engage the CO on specific points where genuine uncertainty remains.
The right clarification questions to ask
When you receive a document with only a banner marking and no clear category identification, or a category designation but no obvious authority basis, ask:
- What CUI category applies to this document?
- Is this a Basic or Specified category, and what additional handling requirements apply?
- Which portions of this document drive the CUI categorization?
- If this document is marked at the agency level, what handling instructions should we apply to contractor-generated derivative work?
Ask these questions even if you think you already know the answer. If the customer answers clearly, you can check your work against theirs. If they cannot, you know the authority reading is on you.
Common errors
- Treating the NARA Registry category description as the definition. The description is orientation. The authorities listed at the bottom of the entry are what define the category. Scroll, read, and click through.
- Treating any document associated with a CUI contract as CUI. Public information cannot be CUI, and internal contractor data that no authority regulates is not CUI.
- Confusing CUI with classified information. CUI is unclassified. Classified information has its own framework under Executive Order 13526.
- Treating FCI as CUI. FCI is broader and less sensitive than CUI; it triggers Level 1, not Level 2. CUI is a more specific category with NARA Registry membership.
- Stripping a customer name or program reference and concluding the document is decontrolled. The information is CUI because of what it contains, not because of who is named on it.
Sources
- 32 CFR Part 2002, Controlled Unclassified Information (CUI Final Rule). The two-part federal definition. link
- NARA CUI Registry. Read the authorities at the bottom of each category entry, not just the description. link
- DoD CUI Registry. DoD-equity categories enriched with upstream authorities. link
- DoDI 5200.48, Controlled Unclassified Information. link
- DoDI 5230.24, Distribution Statements and Distribution Statement Markings on DoD Technical Documents (revised Jan 10, 2025). link
Set CUI handling expectations with users.
The CMMC Compliance Engine includes the AGR-CUI-01_CUI_Handling_Agreement, used to establish the workforce-level handling expectations that protect the CUI you receive.
Get the CMMC Compliance Engine