What is controlled unclassified information
Last updated: April 1, 2026
Key Facts
- CUI is unclassified government information requiring protection under law, regulation, or government-wide policy
- The National Archives and Records Administration (NARA) established the CUI Program to standardize handling across all federal agencies
- Categories of CUI include Controlled Technical Data, Safeguards Information, Privacy, Health, and Proprietary Information
- CUI must be marked with 'CUI' banners and handled according to specific processing, transmission, and storage requirements
- Unauthorized disclosure of CUI can violate federal laws and result in civil or criminal penalties for violators
Definition and Purpose
Controlled Unclassified Information (CUI) represents U.S. government information requiring protection and safeguarding but not meeting the threshold for classification as a national security secret. Created under Executive Order 13556 and standardized through NARA's CUI Program, it provides a consistent framework for protecting sensitive information across federal agencies. CUI includes information that, if disclosed, could compromise operational security, personal privacy, proprietary interests, or other protected interests, yet doesn't rise to the level requiring classification review.
Categories and Types
CUI encompasses multiple categories established by federal statute and regulation. These include Controlled Technical Data (technical specifications and design information), Law Enforcement Sensitive information, Privacy information (personally identifiable information protected under privacy laws), Health information (protected health information under HIPAA), Financial information, and Proprietary information belonging to private companies or individuals. Each category has specific handling requirements and authorized recipients, limiting access to personnel with documented need-to-know.
Marking and Identification
All CUI documents must be clearly marked with the designation 'CUI' at the top and bottom of pages, along with specific category labels indicating the type of controlled information contained. The marking system ensures employees understand handling requirements and protects the information appropriately. Agencies must maintain CUI registries documenting what information they hold and how it's protected. This standardized marking system enables consistent handling across government.
Handling Requirements
CUI requires specific safeguarding protocols including authorized access only to personnel with documented need-to-know, secure transmission through approved channels (never through unsecured email), secure storage in locked facilities or encrypted digital systems, and limitation of copying to authorized personnel. Information technology systems handling CUI must meet specific cybersecurity standards. When CUI is no longer needed, agencies must securely destroy it through approved methods. Training on CUI handling is mandatory for federal employees with access.
Legal and Compliance Implications
Unauthorized disclosure of CUI violates federal law and can result in criminal prosecution, civil penalties, and employment termination. Federal employees sign confidentiality agreements acknowledging their understanding of CUI protection requirements. Contractors and consultants working with CUI must also comply with protection standards. The CUI Program audit and compliance mechanism ensures agencies maintain appropriate controls. Individuals and organizations discovered mishandling CUI face serious legal consequences reflecting the sensitive nature of this unclassified information.
Related Questions
How does CUI differ from classified information?
CUI is unclassified but requires protection under law or regulation, while classified information poses direct national security risk and requires highest protection levels. CUI has broader authorized recipients and less stringent handling than classified information.
Who enforces CUI compliance?
NARA oversees the CUI Program government-wide, while individual agencies implement compliance through CUI Managers. Inspectors General, security offices, and law enforcement agencies investigate violations. Federal employees receive mandatory CUI training.
What happens if I accidentally disclose CUI?
Accidental disclosure may result in remedial action, disciplinary procedures, or criminal investigation depending on severity. Intentional disclosure can lead to federal prosecution, civil penalties up to thousands of dollars, and employment termination.
More What Is in Daily Life
Also in Daily Life
More "What Is" Questions
Trending on WhatAnswers
Browse by Topic
Browse by Question Type
Sources
- Executive Order 13556 - CUI ProgramPublic Domain
- Wikipedia - Controlled Unclassified InformationCC-BY-SA-4.0