Home / Resources / Guide
Guide

What Is CUI?

CUI · Scoping · 6 min read

CUI — Controlled Unclassified Information — is the trigger. If your contracts involve CUI, you almost certainly need CMMC Level 2. Knowing whether you handle it is the first question every defense contractor should answer.

What CUI is

CUI is government-created or government-owned information that isn't classified but still requires safeguarding under law, regulation, or government-wide policy. In defense work it shows up as technical drawings, specifications, engineering data, source code, test results, and other sensitive program information — often the very data you need to do the job.

FCI vs. CUI

TypeWhat it isTriggers
FCIFederal Contract Information — non-public info provided or generated under a contractCMMC Level 1
CUIControlled Unclassified Information — sensitive info requiring specific safeguardingCMMC Level 2

How to tell if you handle CUI

You very likely handle CUI if any of the following are true:

A practical note: you don't have to expose your actual CUI to get assessed for readiness. A readiness review evaluates your program — your policies, procedures, and the way you store and transmit CUI — not the controlled data itself.

Why CUI means CMMC Level 2

Because CUI is exactly the data NIST SP 800-171 was written to protect. If it lives in your environment, you're expected to implement all 110 controls — and from late 2026, prove it through certification. If you're not sure whether you handle CUI, that's the first thing we'll help you nail down.

Not sure if you handle CUI?

We will help you scope it — and tell you exactly what compliance requires.