What Is Controlled Unclassified Information (CUI)?
The federal government produces an enormous volume of sensitive unclassified data that is too sensitive to release publicly. For decades, agencies handled this data under more than 100 inconsistent agency labels, creating operational and security risk. Controlled Unclassified Information (CUI) is the framework that replaced the patchwork with a single set of rules.
For a SaaS vendor pursuing federal contracts, CUI is an important data category for National Institute of Standards and Technology (NIST) SP 800-171 obligations. Federal Risk and Authorization Management Program (FedRAMP) authorization and impact level are determined by the agency's cloud requirements and the system's Federal Information Processing Standards (FIPS) 199 impact categorization.
Key Takeaways
- CUI is sensitive. It is governed by Executive Order 13556 and administered by the National Archives and Records Administration (NARA). It sits between classified information and fully public data.
- CUI raises impact. The FIPS 199 categorization process uses the high-watermark principle, so a single CUI data type with Moderate confidentiality impact can raise the entire system.
- Obligations flow down. Any vendor, subcontractor, or cloud provider that processes, stores, or transmits CUI under NIST SP 800-171 Rev3, finalized in May 2024, inherits the same compliance requirements regardless of who owns the data.
- Authorization is expensive. Traditional FedRAMP authorization can take up to three years, while Government Accountability Office (GAO) authorization cost reporting describes widely varying authorization and maintenance costs.
Controlled Unclassified Information Sits Between Classified And Public Data
Controlled Unclassified Information (CUI) is information the government creates or possesses, or that an entity creates or possesses on the government's behalf, that a law, regulation, or government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. It was established by Executive Order 13556, signed in November 2010.
CUI sits in a distinct middle tier between classified information, which carries Top Secret, Secret, or Confidential designations under separate authority, and uncontrolled unclassified information such as publicly released government data. Before this framework existed, agencies used predecessor labels such as "For Official Use Only" and "Sensitive But Unclassified," producing a patchwork of conflicting markings across the executive branch.
CUI replaced those labels with a uniform handling framework administered by NARA, the program's executive agent. That uniform definition matters because the Registry determines which data types bring compliance obligations into scope.
CUI Categories Determine SaaS Vendor Scope
The category is broad, and the authoritative index of every type is the NARA CUI Registry maintained by NARA. If your product processes, stores, or transmits data in one of the Registry's categories, you are handling CUI.
CUI Basic And CUI Specified Use Different Handling Rules
CUI Basic controls follow the standard uniform controls set out in federal regulation. CUI Specified controls carry additional or more restrictive handling requirements written into the specific law or regulation that authorizes the category. CUI Basic and CUI Specified use the same protection level; the distinction is whether the underlying authority imposes safeguards that differ from the baseline.
The practical differences appear in three places:
- Marking requirements: CUI Basic uses the CUI banner marking
CUIwith an optional category marking, while CUI Specified always uses a mandatory category prefix in the formCUI//SP-[code]. - Dissemination limits: CUI Basic follows the Lawful Government Purpose standard, while CUI Specified is governed by the specific limits written into its authorizing law.
- Handling rules: CUI Basic applies one uniform set of controls, while CUI Specified rules vary by category; where the authorizing law is silent, CUI Basic controls apply.
Common CUI Categories Affect SaaS Vendor Scope
The Registry organizes categories into Organizational Index Groupings. A handful come up repeatedly for technology and defense contractors.
- Controlled Technical Information (CTI): Technical data with military or space application, including engineering drawings, specifications, and source code.
- Export Controlled information (EXPT): Information whose export could affect national security, including dual-use items and data governed by the International Traffic in Arms Regulations (ITAR).
- Sensitive Personally Identifiable Information (SPII): A subset whose loss could cause substantial harm, including Social Security numbers, financial account numbers, and biometric identifiers.
- Health Information category (HLTH): Information on an individual's health condition, care, or payment for care, created or received by a covered health entity.
- Financial and law enforcement data: The Registry includes financial CUI categories and multiple law enforcement categories.
Systems that touch any of these categories need legal authority for handling requirements.
Federal Law And Regulation Extend CUI Protection Across The Contractor Ecosystem
CUI compliance is mandatory, and the obligation flows beyond the agency that owns the data. It moves downward through every vendor, subcontractor, and third party that touches the information. Understanding the legal stack helps vendors scope a federal opportunity before contract award.
Five instruments interlock to create the obligation.
- Executive Order 13556 established the CUI program in 2010, created the uniform handling framework, and designated NARA as the executive agent.
- 32 CFR Part 2002 codified CUI handling standards for federal agencies in 2016. It incorporates NIST standards by reference and states that CUI should be safeguarded at no less than the Moderate confidentiality impact level.
- NIST SP 800-171 Revision 3 provides the specific security requirements for protecting CUI in nonfederal systems. Vendors should confirm which revision their contracts reference, as federal rulemaking has lagged behind the current publication.
- The Defense Federal Acquisition Regulation Supplement (DFARS) cloud clause is the Department of Defense (DoD) contract clause requiring defense contractors to implement NIST SP 800-171 on covered systems. It also requires cloud service providers handling covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline.
- The proposed Federal Acquisition Regulation (FAR) CUI Rule, published in January 2025 with its comment period closed in March 2025, would extend analogous compliance requirements to all non-defense federal contractors handling CUI. The FAR rule remains proposed, with no final rule yet published.
CUI Compliance Flows To Vendors And Subcontractors
Contact with CUI triggers compliance, regardless of ownership. NIST SP 800-171 applies to any nonfederal system that processes, stores, or transmits CUI, and the standard does not condition obligations on who owns the data.
That obligation continues through the supply chain. Under DFARS 252.204-7012, prime contractors must flow the clause down to subcontractors whose performance involves covered defense information, and the prime remains responsible for enforcement across its supply chain.
Any cloud service provider or sub-processor in that chain that touches CUI must itself meet FedRAMP Moderate authorization or demonstrate full equivalency confirmed by a FedRAMP-recognized Third-Party Assessment Organization (3PAO).
FedRAMP Moderate Is The Authorization Standard For Systems Handling CUI
For most SaaS vendors, the practical consequence of touching CUI is direct: the system needs FedRAMP authorization, and in most cases, that means at least FedRAMP Moderate. The requirement follows from how the government categorizes information systems.
CUI Sensitivity Determines The FedRAMP Impact Level
FedRAMP's Rev5 transition materials and the FedRAMP Security Controls Baseline Rev5 (Current) list the Low, Moderate, and High baseline control counts used below.
- FedRAMP Low baseline, 156 controls: Public or non-sensitive data only. Handling CUI disqualifies a system from this tier.
- FedRAMP Moderate baseline, 323 controls: Standard CUI, personally identifiable information, and financial records. This is the floor for CUI and accounts for Moderate baseline authorizations across nearly 80% of all FedRAMP authorizations.
- FedRAMP High, 410 controls: The most sensitive CUI categories, including law enforcement, national security, and financial systems data.
Federal categorization starts with FIPS 199, and the high-watermark principle for impact level determination is associated with FIPS 199 rather than being described in FIPS 200 minimum requirements. A system's impact level is set by the highest sensitivity of any data type it contains.
A SaaS platform handling both low-sensitivity data and CUI inherits the higher CUI categorization across its whole boundary. Because regulation requires CUI to be safeguarded at no less than Moderate confidentiality impact, handling CUI requires a system to at least FedRAMP Moderate.
FedRAMP Moderate Requires Controls, Assessment, Sponsorship And Monitoring
Reaching FedRAMP Moderate requires implementation, documentation, independent assessment, agency authorization, and ongoing monitoring. Vendors must implement and document the FedRAMP requirements.
A FedRAMP-recognized 3PAO develops test procedures, conducts assessment and penetration testing, and drafts the Security Assessment Report. A federal agency must work with the vendor through authorization, after which an Authorizing Official issues an Authority to Operate (ATO). Each subsequent agency customer follows its own ATO process.
The work continues after authorization. Continuous Monitoring (ConMon) includes vulnerability scanning, an updated Plan of Action and Milestones, annual penetration testing, and obligations under FedRAMP's Continuous Monitoring Playbook. Any third-party service that stores, processes, or transmits CUI generally must meet the same bar.
Traditional CUI Compliance Creates A Multi-Year Cost Burden
On paper, the requirements above look like a checklist. In practice, working through them independently is a multi-year capital project. SaaS vendors need to plan staffing, cost, and opportunity timing before committing to a do-it-yourself authorization path.
Agency Sponsorship Extends The FedRAMP Authorization Timeline
A traditional FedRAMP Moderate authorization can take up to three years for new cloud services that secure a sponsor. A major variable is securing agency sponsorship, which the GAO identifies as a key challenge for cloud service providers.
The structure creates a chicken-and-egg problem. Vendors cannot win federal deals without authorization, and they struggle to secure sponsorship without a deal already in hand.
CUI-Ready Environments Create Ongoing Authorization Costs
The dollar figures compound across line items that vendors rarely budget for in full.
- 3PAO assessment fees for the initial Moderate assessment, plus penetration testing.
- Internal staffing for compliance, security operations, and documentation.
- Infrastructure build-out to meet FedRAMP boundary and isolation requirements.
- Continuous monitoring tooling for scanning, incident response, and evidence collection.
- Annual reassessment and ConMon obligations for the life of the authorization.
Traditional FedRAMP cost figures can run as high as $3.5 million. For a growth-stage SaaS company, that is a capital commitment made before related revenue is in place, often on a timeline that may extend beyond the contract opportunity that prompted it.
What if the CUI-ready FedRAMP boundary were already authorized?
A Pre-Authorized Boundary Changes The CUI Compliance Equation
Knox is a FedRAMP-as-a-Service platform that operates a pre-authorized infrastructure boundary. That model means a SaaS vendor can deploy its application into an environment that already holds authorization rather than constructing one from scratch.
The inherited boundary model addresses CUI requirements at the structural level.
- The boundary operator holds the ATO. Infrastructure-layer controls do not have to be built, assessed, and documented from scratch by the vendor.
- Vendors inherit most required controls. Inheritance limits the vendor's remaining scope to application-layer responsibilities, the part of the system it actually owns.
- Sub-processor obligations stay within the boundary. CUI handling occurs within the authorized environment, rather than requiring a separate vendor-managed authorization for each tool in the stack.
Compared with traditional FedRAMP authorization costs, Knox's managed service is approximately $500,000 per application, roughly 90% less. The question changes from whether the vendor can build a compliant environment to whether it needs to own that infrastructure layer at all.
CUI Authorization Determines Federal Market Entry
Compliance infrastructure, more than technical complexity, has historically made federal market entry hard. CUI is the data classification that triggers that requirement for many SaaS vendors, and the path from "we handle CUI" to "we are FedRAMP authorized" has traditionally meant years and millions of dollars before the first contract is signed.
Knox operates a pre-authorized boundary covering FedRAMP Moderate, FedRAMP High, and DISA IL-4 environments, with IL-5 authorization in process and estimated for December 2026. The model is designed to let vendors inherit active ATOs, deploy without re-architecting, and reach authorization in approximately 90 days at roughly 90% less than the traditional path.
If your product touches CUI and federal contracts are on your roadmap, early scoping helps you understand the authorization path before federal opportunities reach procurement. Book a meeting to find out how quickly your system can be authorized.
FAQs about Controlled Unclassified Information
Does handling CUI always require FedRAMP authorization?
For cloud-based systems processing CUI, plan around FedRAMP Moderate unless the contract and agency scope establish otherwise. On-premises systems that never touch a cloud service follow NIST SP 800-171 directly rather than FedRAMP.
What is the difference between FedRAMP Moderate authorization and equivalency?
Authorization means a system has completed the full FedRAMP process and holds an ATO. Equivalency means a 3PAO has confirmed full compliance with FedRAMP Moderate controls without conferring formal FedRAMP authorization.
Who decides whether a category is CUI Basic or CUI Specified?
The underlying authority listed in the CUI Registry dictates whether a category is Basic or Specified. If that authority imposes handling controls different from the regulatory baseline, the category is Specified.