CUI Compliance Requirements: What Actually Applies to You

CUI Compliance Requirements: What Actually Applies to You

Here's the question most guides skip: which Controlled Unclassified Information (CUI) compliance requirements apply to your organization?

Not what CUI is. Not why the federal government protects it. Which specific obligations attach to the contracts you actually hold, and how you'd prove you met them.

The answer decides real work: which security controls you implement, how you handle sensitive data day to day, and what evidence you keep.

That question got harder to answer in 2026. For years, the practical answer was the National Institute of Standards and Technology (NIST) standard 800-171 and, for defense work, the Cybersecurity Maturity Model Certification (CMMC) program on top of it. One standard, one revision, one set of expectations.

That's no longer true. The same CUI now carries different requirements depending on which agency's contract it arrives under, and two federal frameworks currently point to two different revisions of the same standard.

This guide maps what applies where: the government-wide rules that never change, the agency-specific requirements that do, and how to tell which set governs your systems.

TL;DR

  • For contractors, CUI obligations operate through two connected layers: government-wide handling rules incorporated into your contract or agreement, and the agency-specific cybersecurity requirements that contract imposes on the systems holding the information.
  • The handling layer is largely constant. Marking, dissemination controls, limiting access to authorized personnel, and destruction rules follow the same government-wide rules wherever they're incorporated.
  • The security layer has fragmented. Department of Defense (DoD) contracts subject to Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 currently use NIST 800-171 Revision 2, with CMMC verification where its clauses apply. The General Services Administration (GSA) guide issued in January 2026 uses Revision 3 for applicable contractor systems where it's incorporated.
  • Your contract clauses decide everything. Federal Acquisition Regulation (FAR) clause 52.204-21, DFARS 252.204-7012, and agency-specific guides each impose different obligations, and holding contracts with multiple government agencies can mean meeting more than one set.
  • MotherBear gives defense contractors and their consultants one workspace for requirement status, evidence, and documentation, so CUI protection is provable rather than assumed.

Same CUI, Different Requirements: What Changed in 2026

For most of the last decade, "CUI compliance requirements" effectively meant NIST 800-171, with CMMC verification layered on for defense work. Defense contractors carried the strictest obligations by a wide margin.

That gap is closing. On January 5, 2026, GSA issued Revision 1 of its IT security procedural guide for applicable contracts and nonfederal systems handling GSA CUI, adopting NIST 800-171 Revision 3 with independent assessment rather than self-attestation.

It's an agency procedural guide rather than a government-wide rule, so it reaches contractors where it's incorporated into a solicitation or contract. It was still the first major federal use of Revision 3, and it arrived while DoD contracts run on Revision 2.

The detail that matters for planning: two agencies now point at two revisions of the same standard, so a control mapping built for one doesn't transfer cleanly to the other.

Here's how the main frameworks compare:

FAR 52.204-21 Baseline

DoD Contracts (CMMC)

GSA Contracts

Applies to

Contractors whose covered contractor information systems handle Federal Contract Information (FCI) under contracts containing the clause

Contracts with DFARS 252.204-7012

Applicable GSA contracts incorporating the guide

Information covered

FCI only

Covered defense information, including CUI

CUI on contractor systems

Security baseline

15 basic safeguarding requirements

NIST 800-171 Revision 2, 110 requirements, 14 families

NIST 800-171 Revision 3, 17 families

Verification

Contractual compliance, with no separate assessment mechanism in the clause

DoD assessment under DFARS 7019/7020, plus CMMC self-assessment where the clauses apply

Independent third-party assessment

For most readers in the Defense Industrial Base (DIB), the chain that matters runs DFARS 252.204-7012 to NIST 800-171 Revision 2 to the applicable CMMC requirements.

The strategic read is more useful than the details. Civilian agencies are adopting the model defense contractors have lived with for years, which means the work you do for DoD requirements is increasingly the work the rest of the federal government will expect.

Where CUI Requirements Come From: Executive Order 13556

CUI isn't a security standard. It's an information category, and the requirements attached to it come from separate places.

Executive Order 13556 created the category in 2010, replacing a sprawl of agency-specific labels with one government-wide system. The National Archives and Records Administration (NARA) oversees the federal CUI Program, while 32 CFR Part 2002 provides the government-wide framework for how CUI is managed.

Part 2002 binds executive branch agencies directly. For contractors and other nonfederal organizations, the duty arrives through contracts, grants, and other agreements that incorporate CUI safeguarding requirements.

That mechanism reaches contractors, subcontractors, and organizations receiving federal funding. Once CUI sits on nonfederal systems, the organization that stores, processes, or transmits CUI on its own systems has to protect it.

The regulatory definition is worth reading closely, because scope questions usually resolve inside it.

CUI covers unclassified government-related information subject to specific safeguarding or sharing restrictions under a law, regulation, or government-wide policy. That can include information the government holds itself as well as information a contractor creates or holds on its behalf.

Three things follow. Not all sensitive information is CUI, and the label doesn't depend on the information originating with a federal agency. It has to be traceable to a law, regulation, or government-wide policy rather than an agency's preference.

How Federal Agencies Designate Controlled Unclassified Information

The authority originates with the government. A federal agency identifies information that meets the standard, applies the category, and marks it before it reaches you.

Contractors have a narrower role. You may be required to identify and mark CUI you create during performance when the contract or agency instructions authorize it, but you shouldn't invent categories or designate information on your own judgment.

Unmarked information can still qualify if it meets the definition, which is why contracting officers are the right people to ask when the designation is unclear.

CUI Categories and Registry

NARA maintains the CUI Registry, the authoritative list of what qualifies. It's the reference to check when you're unsure whether something in your environment counts.

The categories are broader than most contractors expect: unclassified controlled technical information (UCTI), personally identifiable information (PII), proprietary business information (PBI), critical infrastructure data (CID), export-controlled technical data, and dozens more.

That breadth is why scoping errors are common. A company thinking only about engineering drawings may also hold confidential business information or personnel records carrying their own CUI designation.

CUI Basic and CUI Specified

The CUI Program splits the category in two, and the distinction changes your obligations.

  1. CUI Basic: The default. Handling follows the uniform requirements in 32 CFR Part 2002, with no special instructions beyond the baseline.
  2. CUI Specified: Categories where the underlying law or regulation imposes specific handling controls beyond the baseline. When those instructions exist, they override the default.

Check the CUI Registry for the category you hold. If it's Specified, the applicable laws tell you what additional handling applies, and that requirement sits on top of whatever your contract's security clauses demand.

Specified categories often involve national security, law enforcement, or export control. Their handling instructions are additional or different rather than simply stricter, and CUI Basic rules still cover whatever the authorizing law leaves unspecified.

CUI Compared With Classified Information

The two systems are separate, and conflating them causes real errors. Classified information runs on the national security classification system, with clearances, cleared facilities, and criminal penalties for mishandling.

CUI has none of that machinery. There's no CUI clearance, and protection happens on ordinary contractor systems.

Handling Controlled Unclassified Information: The Constant Rules

Underneath the security frameworks sits a layer that applies to all CUI regardless of agency. These are handling rules rather than access controls or technical security protocols, and they're where contractors most often slip.

  • Marking: CUI documents carry the CUI control marking. Category markings are mandatory for CUI Specified and optional for CUI Basic unless agency policy requires them. Unmarked CUI is still CUI, and the obligation to protect it doesn't wait for a label.
  • Access and lawful government purpose: CUI doesn't use clearance and need-to-know rules the way classified information does. Access goes to authorized personnel where it furthers a lawful government purpose and isn't restricted by an applicable dissemination control.
  • Dissemination controls: Limited dissemination markings restrict who can receive the information, and they travel with it when you share it downstream.
  • Physical protection: Physical access limits, controlled storage, and proper handling of printed material matter as much as network controls.
  • Destruction: Disposal has to render the information unreadable and unrecoverable, not merely deleted.
  • Training: Personnel handling CUI need the training the applicable contract or agency requires, including any initial and recurring requirements.

Where these CUI Program requirements are incorporated into the agreement governing the information, they apply alongside the technical safeguards your security clauses impose. Safeguarding CUI starts here, and unauthorized disclosure is the harm the whole program exists to prevent.

Covered Defense Information: CUI Requirements for DoD Contracts

For the DIB, the requirements chain is well established, and CUI implementation follows a documented path.

DFARS 252.204-7012 obligates you to safeguard covered defense information by implementing NIST 800-171, and to report cyber incidents within 72 hours. CMMC adds verification on top, checking that the requirements are genuinely implemented rather than merely claimed.

Those 110 requirements cover 14 control families, from access control and configuration management to incident response and media protection. Full implementation is the expectation, with only limited use of remediation plans for gaps.

The current verification picture is unusual. On July 13, 2026, the Department suspended CMMC Phase 2, which would have made third-party assessment a condition of award, pending a program review that reports in mid-September.

For planning purposes that changes little. The requirements are unchanged, and a CMMC compliance plan built now holds up whichever verification model returns.

Two verification mechanisms run in parallel, and they're often confused. DFARS 252.204-7019 and 7020 require contractors subject to 7012 to maintain a current NIST 800-171 DoD assessment. Separately, where CMMC clauses apply, Phase 1 adds a CMMC self-assessment and affirmation.

Both continue during the review, and the CMMC self-attestation behind a submission carries real legal weight.

The security practices themselves haven't changed during the review, only the verification model above them.

Enhanced Requirements for National Security Programs

For contracts involving the most sensitive defense information, Level 3 adds enhanced security requirements from NIST 800-172 aimed at advanced persistent threats.

These apply to a narrow set of programs supporting national security priorities. Most contractors never encounter them, and planning for them without a contractual reason wastes money.

What Federal Contractors Outside DoD Now Face

Outside DoD, the picture has historically been thinner. FAR 52.204-21 requires contractors subject to the clause to apply 15 basic safeguarding requirements to covered contractor information systems, which is basic cybersecurity hygiene rather than CUI-grade protection.

Civilian agencies largely relied on self-attestation, without a structured mechanism to verify that contractors adequately protect CUI. GSA's 2026 framework, with its independent assessment requirement, is the clearest sign that's ending.

For defense suppliers, the practical relevance is narrow but real. If you also hold civilian agency contracts, confirm which revision each one references, because your DoD control mapping won't answer for both.

How to Determine Which CUI Compliance Requirements Apply

Requirements attach through contract clauses, not through assumptions about your industry. Work through these in order.

  • Read your contract clauses: Look for FAR 52.204-21, DFARS 252.204-7012 and 7019/7020/7021, and any agency-specific security guide referenced in the terms. Those clauses are the requirement.
  • Confirm whether you actually receive CUI: Ask your contracting officer directly if the designation is unclear. Contractors routinely over-scope by treating all contract data as CUI, and under-scope by assuming unmarked information isn't.
  • Identify the category: Check the CUI Registry to learn whether you hold CUI Basic or CUI Specified, since Specified categories carry additional handling controls.
  • Map where it lives: Identify every system, location, and provider that stores, processes, or transmits CUI. Anywhere you receive, hold, or transmit CUI belongs inside the boundary, and that boundary determines the scope of everything that follows.
  • Run a gap analysis: Measure your current environment against the applicable requirement set, at the correct revision. A Revision 2 mapping doesn't demonstrate Revision 3 compliance.

Contractors serving multiple agencies should do this per contract vehicle rather than once. Requirements now vary enough that a single organizational answer can be wrong for half your portfolio.

How you demonstrate compliance varies too. Some frameworks accept a self-assessment; others require an independent assessor, and the evidence you keep should be strong enough to prove compliance either way.

Building One CUI Program That Serves Multiple Requirement Sets

Fragmented requirements don't mean fragmented programs. The underlying work overlaps heavily, and the organizations handling this well build once and map many times.

The constant is your evidence. Access control records, encryption configurations, training completions, and incident response documentation prove the same facts to any assessor, whichever framework they're working from.

What differs is the mapping: which requirement in which revision each artifact satisfies. Maintaining that mapping is the actual work of multi-framework compliance, and it's where spreadsheets fail first.

Keep the evidence organized against requirements rather than against frameworks. Evidence filed by framework has to be rebuilt every time a new one applies; evidence filed by what it proves gets remapped instead.

How MotherBear Keeps Your CUI Protection Provable

Most CUI programs don't fail on controls. They fail on proof, because requirement status lives in one place, evidence in another, and documentation describes an environment that has since changed.

MotherBear is built for the defense side of this problem: requirement status against NIST 800-171, an evidence repository tied to the requirements each artifact proves, System Security Plan (SSP) and policy materials, remediation tasks, and assessment readiness in one workspace.

For managed service providers and consultants, separate contractor programs stay organized in the same place, with client reporting alongside them.

The result is a program where demonstrating compliance becomes a retrieval exercise rather than a reconstruction project.

Book a demo and see how MotherBear keeps CUI safeguarding requirements documented and current.

FAQs About CUI Compliance Requirements

What are the CUI requirements?

They come in two layers. Government-wide CUI handling rules under 32 CFR Part 2002 cover marking, dissemination controls, access limits, storage, and destruction. For contractors, those requirements apply through the contract, grant, or other agreement governing the CUI.

Security requirements come from your contract. FAR 52.204-21 sets a 15-requirement baseline, DFARS 252.204-7012 requires NIST 800-171 for defense contracts, and agencies like GSA now impose their own frameworks. The handling layer is broadly constant; the security layer depends on who you contract with.

Does CUI have a need-to-know requirement?

Not in exactly the same sense as classified information. CUI access is based on whether the recipient is authorized and the access furthers a lawful government purpose, subject to any applicable limited dissemination controls.

This is independent of security clearances, since CUI sits outside the classified system. Holding a clearance grants no automatic entitlement to CUI, and someone without one may be fully authorized. The practical test is purpose and authorization rather than clearance level.

Who is responsible for CUI compliance?

The organization holding the contract. Support providers can implement controls and manage documentation, but the obligation belongs to the contractor, and where a framework requires an affirmation, that responsibility stays with the contractor rather than its consultant or managed service provider.

Responsibility also flows through the supply chain. Prime contractors must pass down applicable CUI and cybersecurity requirements where the governing clauses require it, and DoD's CMMC clauses add specific subcontractor status checks where they apply.

Internally, the practical answer is that it fails without a named owner.

How often is CUI training required?

For contractors, the cadence depends on the contract and agency requirements rather than a single universal rule. 32 CFR Part 2002 requires federal agency employees to receive CUI training initially and at least every two years, while contractor agreements set their own cadence, and annual training is common.

Check the CUI provisions incorporated into your contract. The content should cover marking, handling, dissemination controls, reporting, and destruction rather than a general security awareness module.

Does NIST 800-171 apply to all CUI?

Not automatically. NIST 800-171 was written to protect CUI in nonfederal systems, but it becomes your obligation only when a contract, agreement, or agency requirement invokes it.

DoD does this through DFARS 252.204-7012. Other agencies use different clauses or frameworks, and some invoke a different revision of the standard. Check what your contract actually references rather than assuming Revision 2 governs every CUI system you operate.

Need to Handle CUI?

Book a demo of MotherBear to see how we help you stay complaint