What is Controlled Unclassified Information (CUI)?

What is Controlled Unclassified Information (CUI)?

What is Controlled Unclassified Information (CUI)?

CUI is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls.

A CUI Registry provides information on the specific categories and subcategories of information that the Executive branch protects. The CUI Registry can be found at: https://www.archives.gov/cui and https://www.dodcui.mil/Home/DoD-CUI-Registry/ and includes the following organizational index groupings:

  • Critical Infrastructure
  • Defense
  • Export Control
  • Financial
  • Immigration
  • Intelligence
  • International Agreements
  • Law Enforcement
  • Legal
  • Natural and Cultural Resources
  • NATO
  • Nuclear
  • Privacy
  • Procurement and Acquisition
  • Proprietary Business Information
  • Provisional
  • Statistical
  • Tax

Resources, including online training to better understand CUI can be found on National Archives’ website at https://www.archives.gov/cui/training.html as well as the Department of Defense’s website https://www.dodcui.mil/.

What are the concerns regarding cybersecurity in the Defense Industrial Base (DIB)?
What is CMMC?
Why was CMMC created?
When is the interim Defense Federal Acquisition Regulation Supplement (DFARS) rule implementing CMMC (DFARS Case 2019-D041) effective?
Will other Federal (non DoD) contracts use CMMC?
What is the relationship between National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 and CMMC?
How will CMMC be different from NIST SP 800-171?
What is the CMMC Accreditation Body (CMMC-AB)?
What is a CMMC Third Party Assessment Organization (C3PAO)?
Who will perform the CMMC assessments?
How will my organization become certified?
Will there be a self-certification?
Are the results of my assessment public? Does the DoD see my results?
How much will CMMC certification cost?
How often does my organization need to be reassessed?
If my organization has a CMMC certification and my unclassified network is compromised, do I lose my certification?
What if my organization cannot afford to be certified? Does that mean my organization can no longer work on DoD contracts?
My organization does not handle Controlled Unclassified Information (CUI). Do I have to be certified anyway?
I am a subcontractor on a DoD contract. Does my organization need to be certified?
How will I know what CMMC level is required for a contract?
Will CMMC certifications and the associated third party assessments apply to a classified systems and / or classified environments within the Defense Industrial Base?
How does my company become a C3PAO?
What is the CMMC Assessors and Instructors Certification Organization (CAICO)?
What is the status of Standard Acceptance Agreements between CMMC and other cybersecurity standards and assessments?
What is the Department’s phased rollout plan for CMMC?