About Us          CMMC          What's New          FAQs          Find Your Component POC
 
  Trigraph Country Codes          Top 10          Who Got Caught          Contact Us     
                                     

Questions about the CUI Program?
Contact your 
Component POC
 

Contracting companies - contact your Government Contracting Office Representative

CUI Registry

Redirecting...

Policies and Forms

Redirecting...

Training Resources

Redirecting...

Frequently Asked Questions

Redirecting...

What is Controlled Unclassified Information (CUI)?

CUI is sensitive information that does not meet the criteria for classification but must still be protected.  It is U.S. Government-created or owned UNCLASSIFIED information that allows for, or requires, safeguarding and dissemination controls in accordance with laws, regulations, or Government-wide policies.  
 
CUI is a control marking, not a classification marking.

CUI policy provides a uniform marking system across the Federal Government that replaces a variety of agency-specific markings, such as FOUO, LES, SBU, etc.

CUI markings alert recipients that special handling may be required to comply with law, regulation, or Government-wide policy.

 

The DoD CUI Registry contains information on every category to include a description of the category, required markings, authorities and DoD policies, and examples of the type of information that may fit into the category.

Not every category or authority listed in the Registry will be applicable to DoD.

DoD News

August 5, 2026 - Revolutionary FAR Overhaul Release 1: The first part of the Revolutionary FAR Overhaul (RFO) has been released as a proposed rule, significantly restructuring how Controlled Unclassified Information (CUI) is handled in federal contracting. The proposed CUI rule has been relocated to an expanded FAR Part 40, updating security baselines to NIST SP 800-171 Rev. 3 and extending incident reporting timelines to 72 hours. Public comments were submitted and are being reviewed. More information on the comments received and the text of the proposed rule can be found here:  https://www.federalregister.gov/d/2026-12559

Key Structural Changes
The CUI rule, originally designated for Part 4, has been moved to a newly structured FAR Part 40, which consists of three subparts:
  1. Processing Supply Chain Risk Information
  2. Security Prohibitions and Exclusions
  3. Safeguarding Information

CUI Standard Form SF XXX : The proposed CUI rule still utilizes Standard Form SF XXX, which requires the government to identify whether CUI will be involved in contract performance, specify which CUI categories are at issue, and outline where the CUI is permitted to reside.

Critical Updates from the 2015 Draft
Please note the following operational changes from the earlier proposed rule:
Requirement Previous (2015) New Proposed Rule
Security Baseline NIST SP 800-171 Rev. 2 NIST SP 800-171 Rev. 3
Incident Reporting 8 Hours 72 Hours
Incident Definition Broadly scoped Narrowly scoped & defined
 

July 14, 2026 - Add new memorandum to CUI Policy Memoranda page - Reduction of Mandatory CUI Training Requirements, 20260713