Controlled Unclassified Information: What Contractors Must Protect

CUI appears in more contractor files than most firms realize. Learn what it is, how to spot it and the basic safeguards defense subcontractors need.

3 min readBy Ironfield Cyber Team

Controlled Unclassified Information, or CUI, is information that the federal government creates or possesses, or that a contractor handles on its behalf, that requires safeguarding under law, regulation, or government policy but is not classified. For contractors, the term appears constantly in defense contracts and in discussions of CMMC. Yet many firms are unsure whether they handle it at all.

Understanding CUI is the first step in deciding what security requirements apply to you.

Why CUI matters to contractors

Under federal acquisition rules, contractors that handle CUI in their information systems must meet specific security requirements. For many defense contracts, those requirements are based on NIST SP 800-171, and the CMMC program is designed to verify that contractors actually implement them. The scope of what needs protection depends heavily on where CUI lives in your environment.

This means one of the most valuable things you can do is figure out whether CUI exists at your company, and if so, where.

Federal Contract Information versus CUI

Two related terms often get confused.

  • Federal Contract Information (FCI) is information provided by or generated for the government under a contract that is not intended for public release. Many federal contractors handle FCI, and it carries a baseline set of safeguarding requirements.
  • CUI is a more specific category of sensitive information that the government has designated for protection. It typically comes with markings and handling instructions.

Handling CUI generally involves more rigorous requirements than handling only FCI.

Where CUI shows up for contractors

The contract and its supporting documents are the starting point. CUI is often found in:

  • Technical drawings and specifications with distribution restrictions.
  • Facility or infrastructure details for sensitive installations.
  • Engineering data, test results, and performance information.
  • Documents marked with CUI banners or distribution statements.

In construction, drawings and specifications for certain government facilities may carry handling restrictions. Subcontractors often receive these files from a prime without a fanfare, so look for markings.

How to find out what you have

  1. Read your contracts and flow-down clauses. Look for language about safeguarding covered defense information, CUI, DFARS clauses, and security requirements.
  2. Ask your prime or contracting officer. If it is unclear whether information is CUI, ask in writing which items are covered and how they are marked.
  3. Search your own files and email. Look for markings, banners, and distribution statements in documents and messages.
  4. Trace the flow. Follow each type of sensitive document from receipt to storage to sharing to disposal.

Keep the scope small

If CUI scatters across laptops, personal email, and shared drives, every one of those becomes part of what you must protect and demonstrate. A common strategy is to confine CUI to a defined, well-controlled environment. That can reduce cost and effort considerably. Options include a dedicated enclave, a segmented part of your network, or a managed cloud environment designed for this purpose. Whichever approach you pick, check that it meets the requirements that apply to you, particularly for cloud services that handle CUI.

Basic safeguards

Without going into every control, expect to need the following in the environment that handles CUI:

  • Individual accounts with multi-factor authentication.
  • Limits on who can access CUI, based on need.
  • Encryption of CUI at rest and in transit.
  • Logging and review of activity.
  • Secure configuration and timely patching.
  • Controls on removable media and mobile devices.
  • Physical protection of systems and paper copies.
  • Incident reporting procedures.
  • Training for people who handle CUI.

Handling and sharing rules

Follow the marking and dissemination instructions on the documents. Do not forward CUI through personal email or consumer file-sharing services. Confirm that recipients, including subcontractors, are authorized and have appropriate safeguards. Destroy materials properly when no longer needed and when the contract allows.

Common mistakes

  • Assuming that because a project is unclassified, no special handling applies.
  • Allowing CUI to accumulate in email.
  • Using unapproved cloud tools for convenience.
  • Failing to flow requirements down to subcontractors who receive CUI.
  • Waiting for an assessment before looking at scope.

A starting plan

Identify your contracts with security clauses, inventory where related information lives, decide whether to consolidate it into a controlled environment, then compare that environment with NIST SP 800-171 requirements.

Help from Ironfield Cyber

Ironfield Cyber helps defense subcontractors scope their CUI environment and prepare for assessment. If you are not sure whether you handle CUI, we can help you work through the contract language and your files.