CUI (Controlled Unclassified Information)
CUI — Controlled Unclassified Information — is the US government’s category for information that’s sensitive enough to require protection but not classified: defense technical data, export-controlled information, certain procurement and financial records, and dozens of other categories in the national CUI Registry.
Why the definition matters commercially
Obligations follow the data. If CUI enters your systems — a defense customer’s technical drawings, a prime contractor’s controlled specs — NIST 800-171’s 110 requirements and, increasingly, CMMC certification attach to wherever it lives. Teams discover this in contract clauses (DFARS 252.204-7012 is the classic) rather than in their architecture reviews, which is the wrong order.
The scoping move
Because obligations follow the data, the winning strategy is containment: an enclave — a bounded environment where CUI lives, hardened to 800-171 — rather than dragging the whole company into scope. This is data classification with contractual teeth: CUI is a tier, the tier has handling rules, and the rules are federal.
The practical checklist
Know whether any customer’s data is CUI (ask; the contract marks it), know exactly which systems it touches, keep it out of everything else (no CUI in Slack, analytics, or prompts), and if defense pipeline is growing, price the enclave before a contract deadline prices it for you.
CMMC — CMMC is the DoD's cybersecurity certification for contractors — three levels, anchored to NIST 800-171, now appearing in defense contracts and flow-downs.
Data Classification — Data classification assigns sensitivity levels to data so controls can scale with risk — three or four tiers, applied where data lives, not in a binder.
NIST 800-53 — NIST 800-53 is the US government's control catalog — hundreds of controls across 20 families — underlying FedRAMP, FISMA, and federal procurement.