CMMC ANSWER ENGINE

How do I know if data I'm receiving is CUI?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-16
Quick answer. CUI determination uses a two-layer test. Layer 1 is the federal definition in 32 CFR Part 2002: information is CUI only if (a) the government creates or possesses it, or you create or possess it for the government, AND (b) a law, regulation, or government-wide policy requires or permits safeguarding or dissemination control. Layer 2 is the category-specific authorities listed at the bottom of the NARA CUI Registry entry that fits the information. For DoD-originated unclassified technical documents, the Jan 2025 revision of DoDI 5230.24 simplifies the read: any document with a Distribution Statement of B, C, D, E, or F is properly CUI under the new framework. Distribution Statement A is public and is not CUI.

The two-layer test

Every CUI determination has two parts and you must apply both:

  1. Layer 1: the federal definition (32 CFR Part 2002). Information qualifies as CUI only when BOTH of these are true: the government creates or possesses it, or you (an entity such as a contractor) create or possess it for or on behalf of the government; AND a law, regulation, or government-wide policy requires or permits the information to be safeguarded or dissemination-controlled. If either condition fails, it is not CUI, regardless of marking or contract context.
  2. Layer 2: the category-specific authorities. Identify which CUI category fits the information, then read the authorities listed at the bottom of the NARA CUI Registry entry (and the DoD CUI Registry entry for DoD-equity categories). Those authorities define the actual scope, the explicit exclusions, and who the rule is speaking to. Many authorities are far narrower than the category name implies.

Skipping either layer is the most common source of error. Teams that only read 32 CFR end up with a definition too abstract to be operational. Teams that only read the customer's marking instructions end up overscoping (controlling things that are not CUI) or underscoping (missing categories that apply).

Where the actual definition lives in a NARA Registry entry

When you click into a NARA Registry entry, the page leads with a category description. That description is a NARA-authored summary. It is not the legal definition, it is not binding, and it should not be the last thing you read. Scroll to the bottom of the entry, find the box labeled "Safeguarding and/or Dissemination Authority," and read the authorities themselves. The PDF behind each link, within its section or part, contains the actual sentence or paragraph that defines a regulated information type.

The DoD CUI Registry at dodcui.mil mirrors NARA's category structure but enriches entries for DoD-equity categories by listing the upstream supporting authorities that NARA summarized but did not cite. Read both registries for DoD categories.

The DoDI 5230.24 simplification for DoD-originated technical documents

The Jan 2025 revision of DoD Instruction 5230.24 (Distribution Statements and Distribution Statement Markings on DoD Technical Documents) establishes a unified marking framework that aligns Distribution Statements with the CUI Program. The headline rule: all unclassified Controlled Technical Information must now be marked as CUI. For practical reading of DoD documents you receive:

Distribution StatementMeaningCUI?
AApproved for public release; distribution unlimited.Not CUI. Public information cannot be CUI.
BDistribution authorized to U.S. government agencies only.CUI.
CDistribution authorized to U.S. government agencies and their contractors only.CUI. Common for technical data flowed to contractors.
DDistribution authorized to DoD and DoD contractors only.CUI. Common for defense-specific technical data.
EDistribution authorized to DoD components only.CUI. Should not normally be in contractor hands.
FFurther dissemination only as directed by the controlling DoD office.CUI. Case-by-case dissemination authority.

This is operationally clarifying: a DoD-originated document with any Distribution Statement other than A is, under the new guidance, properly CUI, even if it has not yet been remarked with the new CUI banner and Designation Indicator. There is no project to retroactively remark legacy documents, so expect a mix of legacy distribution-statement-marked documents and newly CUI-marked documents for years.

CUI Basic vs CUI Specified

TypeDefinitionHandling
CUI BasicCUI without specific safeguarding or dissemination controls beyond the baseline in 32 CFR 2002.Standard CUI handling per NIST SP 800-171 (CMMC Level 2) at minimum.
CUI SpecifiedCUI with specific safeguarding or dissemination controls required by law, regulation, or government-wide policy (for example, NNPI, Export Controlled).Standard CUI handling plus the specific category's additional requirements.

What CUI looks like when properly marked

  • Banner marking at the top and bottom of every page: "CUI" alone for Basic, "CUI//[category]" for Specified, with limited dissemination controls appended where applicable.
  • Portion markings before each paragraph or portion: "(CUI)" or "(CUI//[category])".
  • CUI Designation Indicator (CDI) on the first page identifying the controlling body, the distribution letter code (for DoD documents under the unified framework), the CUI category, and a point of contact for clarification.

For the full marking rules see What are the CUI marking requirements I must apply?.

Situations to push back on

You will hear these three things over and over. None of them holds up under the two-layer test, and each one is worth pushing back on.

  • "Everything from the customer is CUI." Public information cannot be CUI. A contract package that is section-marked as CUI but contains the company name, contract number, dollar amount, and program name (all published on USAspending.gov) has overbroad marking. The categories of information present each need to be evaluated against their own authorities. Sections with no governing authority are not CUI.
  • "Everything you create on the contract is CUI." The government's interest in contractor-generated work is constrained: agencies must request specific line-item deliverables to receive copies. Federal records are generated when a contractor delivers an item the contract called for. Internal work that is not a deliverable, that the government does not own, and that no underlying authority regulates is not CUI even if it was generated during contract performance.
  • "Just ask your contracting officer." Contracting officers are professionally focused on the FAR and DFARS, not the upstream statutes and regulations that define CUI categories. A competent CUI practitioner inside the contractor often has a deeper working knowledge of ITAR, EAR, 10 U.S.C. 130, or the specific authorities behind a category than the CO does. Deferring the whole question to the CO usually produces "treat all of it as CUI," which is operationally expensive and rarely correct. The right move is to do the authority reading yourself, propose a defensible determination, and engage the CO on specific points where genuine uncertainty remains.

The right clarification questions to ask

When you receive a document with only a banner marking and no clear category identification, or a category designation but no obvious authority basis, ask:

  • What CUI category applies to this document?
  • Is this a Basic or Specified category, and what additional handling requirements apply?
  • Which portions of this document drive the CUI categorization?
  • If this document is marked at the agency level, what handling instructions should we apply to contractor-generated derivative work?

Ask these questions even if you think you already know the answer. If the customer answers clearly, you can check your work against theirs. If they cannot, you know the authority reading is on you.

Common errors

  • Treating the NARA Registry category description as the definition. The description is orientation. The authorities listed at the bottom of the entry are what define the category. Scroll, read, and click through.
  • Treating any document associated with a CUI contract as CUI. Public information cannot be CUI, and internal contractor data that no authority regulates is not CUI.
  • Confusing CUI with classified information. CUI is unclassified. Classified information has its own framework under Executive Order 13526.
  • Treating FCI as CUI. FCI is broader and less sensitive than CUI; it triggers Level 1, not Level 2. CUI is a more specific category with NARA Registry membership.
  • Stripping a customer name or program reference and concluding the document is decontrolled. The information is CUI because of what it contains, not because of who is named on it.

Sources

  • 32 CFR Part 2002, Controlled Unclassified Information (CUI Final Rule). The two-part federal definition. link
  • NARA CUI Registry. Read the authorities at the bottom of each category entry, not just the description. link
  • DoD CUI Registry. DoD-equity categories enriched with upstream authorities. link
  • DoDI 5200.48, Controlled Unclassified Information. link
  • DoDI 5230.24, Distribution Statements and Distribution Statement Markings on DoD Technical Documents (revised Jan 10, 2025). link
Rulebook version: 32 CFR Part 2002; NARA CUI Registry; DoDI 5200.48; DoDI 5230.24 (revised Jan 10, 2025)

Set CUI handling expectations with users.

The CMMC Compliance Engine includes the AGR-CUI-01_CUI_Handling_Agreement, used to establish the workforce-level handling expectations that protect the CUI you receive.

Get the CMMC Compliance Engine
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.