Controlled Unclassified Information, or CUI, is one of those terms that appears in a solicitation and quietly raises the stakes. It is not classified, so it does not require a facility clearance or a safe. But it carries handling, safeguarding, and increasingly cybersecurity obligations that can shape your costs, your IT environment, and even whether you are eligible to perform the work. Missing CUI requirements in a solicitation is both a compliance risk and a pricing mistake, and the pricing mistake is often the more expensive of the two.
This guide explains what CUI actually is, how it shows up in a solicitation, the cybersecurity obligations it can trigger, what it requires you to do, and why you need to catch it during triage rather than after award.
What CUI is
CUI is government-created or government-owned information that is sensitive but not classified, and that some law, regulation, or government-wide policy requires be protected or controlled. The program was established by Executive Order 13556 and is run under a National Archives framework codified at 32 CFR Part 2002. Its main purpose was to bring order to chaos: before CUI, agencies used dozens of inconsistent markings like FOUO, SBU, and Sensitive But Unclassified, each with its own ad hoc rules. CUI standardized all of that into one system with defined categories and a public CUI Registry maintained by NARA.
CUI categories
The CUI Registry lists many categories, but the ones contractors encounter most include controlled technical information, export-controlled information, privacy and personally identifiable information, procurement-sensitive and source-selection information, and law-enforcement-sensitive material. Each category has its own handling rules, and some, like export-controlled data, intersect with other regulatory regimes that carry serious penalties of their own.
CUI Basic versus CUI Specified
The framework distinguishes two levels. CUI Basic follows the standard handling controls in the governing framework. CUI Specified applies when a specific law or regulation imposes more stringent handling requirements for a particular category. The marking on a document tells you which set of rules applies, which is one reason marking discipline matters so much.
How CUI shows up in a solicitation
CUI rarely arrives with a headline. It shows up as a dedicated CUI section or clause, attachments or documents stamped with CUI markings, references to safeguarding and handling requirements, language about storing and destroying the information, and, increasingly, cybersecurity requirements tied to protecting CUI on your systems. Sometimes the solicitation package itself contains CUI, which constrains how you are even allowed to store and share the document you are responding to. For a general approach to spotting and decoding clause language, see how to read FAR clauses without losing your mind.
The cybersecurity obligations
For many contractors, especially in the defense space, the biggest impact of CUI is cybersecurity. Protecting CUI on contractor systems is commonly tied to the security controls in NIST Special Publication 800-171. In Department of Defense work, the clause at DFARS 252.204-7012 has long required safeguarding of covered defense information and prompt reporting of cyber incidents. Layered on top of that, the Cybersecurity Maturity Model Certification, or CMMC, is phasing into DoD contracts and will require contractors that handle CUI to demonstrate a defined level of cybersecurity maturity, in some cases through third-party assessment.
The practical takeaway is that a solicitation involving CUI may require you to meet a specific, auditable cybersecurity bar on the systems that touch the information, and meeting that bar is neither instant nor free.
What it obligates you to do
Depending on the specific requirement, handling CUI can obligate you to safeguard the information to a defined standard, implement and document cybersecurity controls on the systems that store or process it, mark and control documents correctly, train your staff on CUI handling, properly destroy the information when you are done, and flow these requirements down to your subcontractors. That last point matters in any teaming arrangement: a subcontractor who mishandles CUI is your problem as the prime.
The cost and infrastructure reality for small firms
For a large defense integrator, CUI obligations are business as usual. For a small firm moving into work that involves CUI for the first time, the security controls represent real cost and real infrastructure: compliant systems, documented policies, training, and potentially a third-party assessment. None of that is free, and all of it belongs in your bid decision and your price, not as an afterthought discovered during performance. The dynamic is similar to the compliance-cost question we cover in DCAA compliance for small contractors: the goal is to be auditable, and getting there has a price tag you need to plan for.
CUI and the solicitation package itself
One often-overlooked wrinkle: when the solicitation package or its attachments contain CUI or export-controlled data, you cannot handle the document casually. It cannot be forwarded freely, posted to an uncontrolled shared drive, or uploaded into systems that lack the appropriate controls. This affects how your capture and proposal teams collaborate on the pursuit, and it is a reason to know a package contains CUI before it ever lands in someone's personal inbox.
Why catch it before you bid
CUI requirements affect three things that all belong in your bid/no-bid decision. They affect eligibility, because you have to be able to meet the security bar to perform. They affect cost, through compliance and infrastructure that has to be priced in. And they affect risk, because mishandling CUI carries consequences ranging from a lost contract to regulatory penalties. Spotting CUI during triage lets you price it, plan for it, or pass on it deliberately, rather than discovering the obligation after you have committed. For where this fits in the overall solicitation read, see how to evaluate an RFP in under 10 minutes and build the requirement into your compliance matrix so it does not get lost. CUI often travels alongside other Section H provisions like organizational conflict of interest language, so the same careful read tends to catch both.
How CUI differs from classified information
It is worth being precise about what CUI is not. Classified information, Confidential, Secret, and Top Secret, requires personnel clearances, accredited facilities, and physical security measures, and mishandling it can be a criminal matter. CUI requires none of that infrastructure. It is unclassified information that simply must be controlled, protected, and handled according to defined rules. The confusion comes from the fact that both are sensitive, but the obligations and the consequences operate on completely different scales. A small firm can handle most CUI with disciplined IT practices and good policies; handling classified information is a different business entirely.
Marking and handling basics
CUI is identified through standardized markings. Documents carry a banner marking at the top indicating CUI and, where applicable, the specific category, along with a designation indicator identifying who designated the information and under what authority. Portion markings may flag which parts of a document are controlled. The marking is not decoration: it tells everyone who touches the document which handling rules apply, including whether it is CUI Basic or the more stringent CUI Specified. Mishandling typically triggers an incident-reporting obligation, and in defense contracts a cyber incident affecting CUI must be reported within a defined window under the applicable DFARS clause. Knowing the markings, and training your team to recognize and respect them, is the baseline of CUI compliance.
Building CUI into your pursuit process
The practical discipline is to screen for CUI the moment a solicitation arrives, on the same first-read pass that catches set-aside status, key personnel, and OCI language. If a package contains or will require handling CUI, route it through controlled channels from the start, flag the security requirements for pricing, and decide deliberately whether your firm can meet the bar. Catching it on the first read keeps a marked document from ever landing in an uncontrolled inbox, and keeps the compliance cost from becoming an unpriced surprise.
Bottom line
CUI is not classified, but it is not casual either. Find the CUI requirements during triage, understand the safeguarding and cybersecurity bar they set, and fold the cost and feasibility into your bid decision. It is far cheaper to plan for CUI before you commit than to discover it after award, when the obligation is fixed and the price is already set.
This guide is general information, not legal or cybersecurity compliance advice. CUI handling, NIST SP 800-171, DFARS, and CMMC requirements are governed by regulations that change over time and depend on your contract and customer. Confirm current obligations with qualified counsel or a cybersecurity compliance professional.