What actually counts as CUI, and who decides?
Controlled Unclassified Information (CUI) is government-created or possessed unclassified information requiring safeguarding or dissemination controls pursuant to law, regulation, or government-wide policy. The designating authority, typically a government agency, determines what constitutes CUI based on specific categories outlined in the CUI Registry. Contractors receive CUI from these agencies, which are responsible for proper marking and identification, although contractors also bear responsibility for identifying CUI they generate that meets CUI criteria.
For practitioners, accurately identifying CUI is paramount for CMMC compliance. Misidentifying CUI, whether by over-marking or under-marking, carries significant risks. Over-marking can lead to unnecessary security costs and operational inefficiencies, while under-marking results in non-compliance, potential data breaches, and contractual penalties. Contractors must establish robust processes for CUI identification, inventory, and flow-down requirements to subcontractors, ensuring consistent protection across the supply chain. This includes training personnel to recognise CUI and understand its handling requirements.
The ultimate authority for CUI designation rests with the Executive Agent for CUI, currently the National Archives and Records Administration (NARA), which maintains the CUI Registry. However, individual government agencies are the "designating authorities" for specific information they create or possess. Contractors are generally expected to protect information identified as CUI by the government. When contractors generate new information that meets CUI criteria based on existing contracts or regulations, they must also identify and mark it as CUI, ensuring it receives appropriate protection according to the CUI Registry categories and the contract's CMMC level.
Sources
- 32 CFR Part 2002 (Controlled Unclassified Information)
- DFARS Clause 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting)
- CUI Registry (maintained by NARA)