Compliance
What actually counts as CUI?
Almost every question about your compliance obligations follows from one answer, and it is the answer most defense contractors are least sure about.
If you hold Federal Contract Information and nothing more, your obligation is the fifteen basic safeguarding requirements of FAR 52.204-21, self-assessed. If you hold Controlled Unclassified Information, you are looking at DFARS 252.204-7012, all 110 controls of NIST SP 800-171, incident reporting inside 72 hours, and CMMC Level 2.
That is the difference between a modest piece of work and a programme. Which is why it is worth more than the ten minutes most businesses give it.
What CUI actually is
Controlled Unclassified Information is government-created or government-owned information that law, regulation, or government-wide policy requires to be safeguarded — but which is not classified. It was created by executive order in 2010 to replace a sprawl of agency-specific labels like “For Official Use Only” and “Sensitive But Unclassified” with one framework.
The National Archives maintains a registry of CUI categories. It is long, and most of it will never touch you. For a defense contractor the category that matters most is usually Controlled Technical Information — technical data with military or space application, which in practice means drawings, specifications, process descriptions, test data and engineering packages.
That last point is the one worth sitting with, because it is where most of the misunderstanding lives.
The assumption that catches manufacturers
Ask a small manufacturer whether they handle CUI and the answer is often no, delivered with confidence. The mental image is personnel records, intelligence products, something obviously sensitive.
Then you look in their email and find a prime’s engineering drawing package.
Controlled Technical Information is the most common CUI in the supply chain, and it is exactly what you receive in order to make a part. It arrives as an attachment, it gets forwarded to the shop floor, it sits on a file share, and nobody thinks of it as regulated information because it looks like a day-to-day work document. It is a day-to-day work document. It is also CUI.
Unmarked does not mean unregulated
Here is the trap.
Marking CUI is the government’s job. It is done inconsistently, and it gets less consistent the further down the supply chain information travels. By the time a drawing reaches a third-tier supplier through two primes and an email forward, the markings may be long gone — if they were ever applied.
Whether something is CUI depends on what it is and what your contract requires, not on whether anyone remembered to stamp it. An assessor is not going to accept “it wasn’t marked” as a reason your environment was not protecting it.
This cuts both ways, and it is worth being fair about that: you are not responsible for divining the status of everything that arrives. What you are responsible for is asking, and being able to show that you asked.
How to actually find out
In rough order of reliability:
1. Read your contract. The presence of DFARS 252.204-7012 is the clearest single signal. It is the clause that brings NIST SP 800-171 with it, and it appears because the government anticipates covered defense information being involved.
2. Read your prime flowdowns. Primes are required to flow that clause down unaltered. What they are less good at is telling you plainly which of the things they send you it applies to.
3. Ask the contracting officer, in writing. This is the step people skip because it feels like admitting ignorance. It is not — it is the correct process, the government designates CUI, and a written answer is worth more than any amount of internal debate.
4. Look at what you actually hold. Not what the contract anticipated — what is in the mailboxes, the file shares, the shop floor PCs and the ERP system. This is usually the point at which someone finds something they did not expect.
If you cannot get a clear answer, document that you asked. An unanswered question you can evidence is a far stronger position than an assumption you cannot.
Both wrong answers are expensive
The obvious risk is assuming you have no CUI when you do. That leaves you non-compliant with a clause you already signed, with an affirmation in SPRS that may not be true, and with the Department of Justice’s Civil Cyber-Fraud Initiative paying attention to false certifications.
The less-discussed risk is assuming you have CUI when you do not. That means scoping and paying for a boundary you did not need, quite possibly including a GCC High tenant that costs more and offers less than commercial Microsoft 365. We have told businesses that before, and it is a slightly awkward conversation to have with someone who arrived intending to buy the larger thing.
Neither error is free. That is the argument for establishing this properly rather than defaulting in either direction.
Once you know, the scope follows
If it is FCI only, your work is CMMC Level 1 and FAR 52.204-21 — a smaller engagement that should be priced as one.
If CUI is in scope, the order of operations matters more than anything else: the boundary gets designed first, and everything else follows it. Deciding where CUI is allowed to live, who can reach it, and how that is evidenced comes before any migration. Do it the other way round and you will move the data twice — once to get there, once to fix what should never have come across.
And whichever it is, the split of who does what is worth settling in writing at the same time. A substantial share of NIST SP 800-171 is organisational — training, screening, physical access — and no technology provider can do it for you. Our shared responsibility matrix sets out the usual division across all fourteen families, free and without an email gate.
If you are not sure
Most businesses that ask us this question already have the answer somewhere in a contract nobody has read closely. Establishing it is usually a short piece of work, and it is the one that determines the size of everything after it.
Schedule a call — twenty minutes, and if it turns out you only owe Level 1, we will say so.
Frequently asked
- What is the difference between FCI and CUI?
- Federal Contract Information is information provided by or generated for the government under a contract that is not intended for public release. Controlled Unclassified Information is a narrower, more sensitive category that law, regulation or government-wide policy requires be safeguarded. If you hold only FCI, your obligation is FAR 52.204-21 and CMMC Level 1. CUI brings DFARS 252.204-7012, all 110 NIST SP 800-171 controls, and CMMC Level 2.
- If information is not marked as CUI, is it still CUI?
- Very possibly. Marking is the government's responsibility and it is inconsistently done, particularly on information that reaches you through a prime rather than directly. Whether something is CUI depends on what it is and what your contract requires, not on whether somebody remembered to stamp it. Treating unmarked information as unregulated because it is unmarked is one of the most common and most expensive mistakes in the defense supply chain.
- We only manufacture parts. Do we handle CUI?
- Quite likely yes. Controlled Technical Information — drawings, specifications, process data, test results — is one of the most common CUI categories in the supply chain, and it is exactly what a manufacturer receives in order to make something. Many small manufacturers assume CUI means personnel or intelligence data and overlook the engineering package sitting in their email.
- Who decides whether we hold CUI?
- The government designates CUI, and your contract should tell you. In practice, ask your contracting officer in writing, and read your prime flowdowns. If you cannot get a clear answer, document that you asked — an unanswered question you can evidence is a far better position than an assumption you cannot.
- Is it safer to just assume we have CUI?
- It is safer than assuming you do not, but it is not free. Treating everything as CUI means building and paying for a boundary you may not need, and possibly a GCC High tenant you could have done without. Both directions cost money. The point of establishing this properly is that you stop guessing in either direction.
Continue reading
-
GCC High or Commercial — which do you need?
For a defense contractor the real choice is between two Microsoft 365 environments. What decides it, and why GCC High is not automatically the safer answer.
-
CMMC Phase II is suspended. Your signature got heavier.
The third-party certification requirement is on hold. Your safeguarding clauses, your SPRS affirmation, and your prime's flowdowns are not.