" /> Is Everything Under a DoD Contract CUI? CUI vs FCI Explained | ITSECOPS
Veiledning

Is Only Marked Information CUI, or Is Everything We Do for the Government CUI?

Oppdatert · sep 2026 By ITSECOPS Gratis · Ingen påmelding

CMMC questions from the field · Is only marked information CUI, or is everything we do for the government CUI? · Updated September 2026

Neither. CUI is defined by what the information is, not by whether a banner is on it, and most of what a contractor does for the government is not CUI. The rule defines CUI as “information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls” (32 CFR 2002.4(h)). Two limits follow. Information is CUI only if it falls in a category the CUI Registry lists (32 CFR 2002.12); and it is never CUI if it is “information a non-executive branch entity possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency” (2002.4(h)). At the same time, unmarked information that qualifies is still CUI: “the lack of a CUI marking on information that qualifies as CUI does not exempt the authorized holder” (2002.20(a)(7)).

Three buckets, not one

Information in a defense contractor’s environment sorts into three regulatory buckets, and CMMC level follows the bucket.

Bucket Definition Typical examples CMMC consequence
CUI Government-created or government-purpose information in a CUI Registry category that law, regulation or government-wide policy requires or permits controls for (32 CFR 2002.4(h), 2002.12) Controlled Technical Information (drawings, specs, test data with military application), export-controlled technical data, some PII the government provides, procurement-sensitive source selection data Level 2 minimum for any system that processes, stores or transmits it (32 CFR 170.23(a)(2))
Federal Contract Information (FCI) “Information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government” (FAR 52.204-21) Contract terms, delivery schedules, invoices, status reports, non-public correspondence with the contracting officer Level 1 (FAR 52.204-21’s 15 requirements) where only FCI is handled (32 CFR 170.23(a)(1))
Uncontrolled unclassified information “Information that neither the Order nor the authorities governing classified information cover as protected” (32 CFR 2002.4(ss)) Your HR records, your pricing models, marketing, internal IT designs, public press releases, published standards Out of CMMC scope, provided it is not on a CUI asset and the system is separated

DoD’s CMMC FAQ draws the line the same way: “FCI and CUI are information that is ‘not intended for public release.’ However, CUI requires additional safeguarding and may also be subject to dissemination controls … CMMC makes no changes to CUI definitions or safeguarding requirements” (B-A7).

Why “everything is CUI” is wrong

  • The Registry is exclusive. “CUI categories and subcategories are the exclusive designations for identifying unclassified information that a law, regulation, or Government-wide policy requires or permits agencies to handle by means of safeguarding or dissemination controls” (32 CFR 2002.12(a)). If the information does not fit a listed category, an agency cannot make it CUI, and neither can you.
  • Your own information is carved out. The definition excludes what a contractor “possesses and maintains in its own systems that did not come from, or was not created or possessed by or for” an agency (2002.4(h)). Your payroll is not CUI because you have a DoD contract.
  • Public information is excluded. “CUI does not include information lawfully and publicly available without restrictions” (DoDI 5200.48 para 3.7.a). A drawing published in a public standard is not CTI because it appears in a DoD deliverable.
  • Over-marking is misuse. “Misuse of CUI … may also include designating or marking information as CUI when it does not qualify as CUI” (32 CFR 2002.4(o)). DoDI 5200.48 para 1.2.c prohibits designation to “control information not requiring protection under a law, regulation, or government-wide policy.”

The cost of the “everything is CUI” assumption is real. It turns a 12-user enclave into a company-wide Level 2 scope, forces every vendor into a CUI flow-down, and makes your SSP describe controls on systems that never touch government information. Assessors notice the mismatch between what is marked and what is protected.

Why “only marked information is CUI” is also wrong

  • “Treat unmarked information that qualifies as CUI as described in the Order, § 2002.8(c), and the CUI Registry” (32 CFR 2002.20(m)).
  • DFARS 252.204-7012 covers information “marked or otherwise identified in the contract” and information “collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract.” Technical data you develop is covered before anyone marks it.
  • “Any new document created with information derived from legacy material must be marked as CUI if the information qualifies as CUI” (DoDI 5200.48 para 3.2).

A marking is evidence that someone has made the determination. Its absence is a gap to close, not a decision. See what to do when you receive unmarked CUI.

A three-question test for any document

  1. Origin: Did the government create it, or did we create it for or on behalf of the government under a contract? If no, it is not CUI (it may still be FCI, or simply ours).
  2. Category: Does it fit a category in the CUI Registry that applies to DoD, and does the contract or the government’s marking identify it? Controlled Technical Information is the category that catches most engineering, manufacturing and test work.
  3. Public availability: Is it lawfully and publicly available without restriction? If yes, it is not CUI.

Yes to 1 and 2 and no to 3 means CUI, marked or not. Yes to 1 only, and not intended for public release, means FCI. Everything else is uncontrolled and belongs outside your CUI boundary.

What this means for scoping

The CMMC Level 2 Scoping Guide lets you leave out “assets that cannot process, store, or transmit CUI; and do not provide security protections for CUI Assets” and “assets that are physically or logically separated from CUI assets.” That relief only exists if you can say, document by document and system by system, which bucket the information belongs to. A CUI inventory per contract is the artefact that makes the out-of-scope claim credible, and it is the same inventory that answers the marking and vendor-sharing questions on this site.

Sources and clauses

This page is general information, not legal advice. ITSECOPS is not affiliated with the Department of Defense. Contract-specific questions belong with your contracting officer.

Answered by Gaurav Sengar, CISA

Cybersecurity expert with 12+ years across cybersecurity, IT operations and compliance. He has helped several defense suppliers and their subcontractors reach CMMC readiness, from scoping and SPRS scoring to POA&M closeout.

FAQ

Is everything under a DoD contract CUI?

No. Only information in a CUI Registry category that the government created or that you created for the government is CUI. Non-public contract administration information is FCI, and your own business information is uncontrolled.

Is an unmarked document CUI?

If the information qualifies, yes. 32 CFR 2002.20(a)(7) and (m) require holders to treat unmarked qualifying information as CUI. Ask the contracting officer for a determination and a marked copy.

Are my own drawings CUI if I made them for a DoD part?

Usually yes, as Controlled Technical Information: technical information with military or space application subject to controls, created in performance of the contract, is covered defense information under DFARS 252.204-7012. Confirm the category and distribution statement with the contracting officer.

Is FCI a type of CUI?

No. FCI is defined in FAR 52.204-21 and requires basic safeguarding (CMMC Level 1). CUI is defined in 32 CFR 2002 and requires NIST SP 800-171 (CMMC Level 2). Some information is both FCI and CUI; the stricter regime applies.

Not sure which bucket your data sits in?

Book a session with Gaurav Sengar: a contract-by-contract CUI and FCI inventory, a defensible out-of-scope boundary, and the smallest Level 2 enclave that still passes.

BOOK A CMMC SESSION

Trenger du hjelp til å ta dette i bruk i din bedriftsmiljø?

Vi gjør compliance-guider om til implementerte kontroller. Snakk med en ingeniør.

Bestill en konsultasjon