CTI vs. CUI: How Controlled Technical Information Fits Within CUI

Written by: 
Team Knox
Published on: 
August 13, 2026

Controlled Unclassified Information (CUI) is the government-wide framework for sensitive but unclassified data, administered by the National Archives and Records Administration (NARA) under Executive Order 13556. Controlled Technical Information (CTI) is one of the named categories within that framework.

For SaaS vendors and defense contractors evaluating federal market entry, the two terms get used interchangeably, and that confusion affects data marking and contract obligations before a company can sign.

The distinction matters because it determines regulatory obligations. Get the relationship wrong and a company either over-engineers compliance for data that does not warrant it or under-protects technical data that triggers strict statutory controls and Cybersecurity Maturity Model Certification (CMMC) requirements.

Key Takeaways

  • CUI is broader. CTI sits inside CUI, while most CUI falls into other categories, and that hierarchy determines which obligations apply.  
  • CTI is specified. It is listed in the NARA CUI Registry as CUI Specified, is subject to contractual safeguarding requirements under the Defense Federal Acquisition Regulation Supplement (DFARS), DFARS safeguarding clause, uses a distinct marking regime, and triggers CMMC Level 2 requirements for applicable DoD contracts.  
  • Cloud baselines converge. For covered defense information and DoD CUI environments, cloud hosting starts with Federal Risk and Authorization Management Program (FedRAMP) Moderate-equivalent requirements. The DoD Cloud Computing Security Requirements Guide (SRG) V1R6 (December 2025) places DoD CUI environments at Defense Information Systems Agency Impact Level 4 (DISA IL-4).  
  • Infrastructure drives cost. Federal authorization costs vary widely across broad ranges, while Knox's managed service brings the cost to approximately $500,000.

CUI Is the Category, and CTI Is a Subset

Controlled Unclassified Information is the government-wide framework for sensitive but unclassified data, administered by NARA and codified in 32 CFR Part 2002.

Controlled Technical Information is one of the named categories within that framework. CTI is CUI Specified with a safeguarding authority of 48 CFR 252.204-7012 and is governed specifically by DFARS 252.204-7012.

CTI covers technical data with military or space application, including engineering drawings, specifications, software executable code and source code, technical manuals, and research and engineering data, that is subject to controls on its access, use, reproduction, modification, performance, display, release, disclosure, or dissemination.

CTI is CUI, while most CUI falls into other categories. That distinction determines which regulatory obligations apply and how.

CUI Covers the Full Range of Federal Sensitive Data

32 CFR § 2002.4 defines CUI as information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. The federal CUI program's history reflects a framework that encompasses state, local, Tribal, private-sector, academic, and industry entities.

CUI Basic and CUI Specified Carry Different Obligations

Control unclassified information splits into two tiers that carry different handling obligations:

  • CUI Basic follows the uniform handling requirements in 32 CFR Part 2002 and the National Institute of Standards and Technology (NIST) SP 800-171 Rev3 when the authorizing law does not specify specific controls. Civilian SaaS vendors may encounter CUI Basic when a contract identifies CUI, such as personally identifiable information (PII), financial records, or procurement data, without category-specific handling controls.  
  • CUI Specified carries additional or more restrictive controls set by the underlying statute or regulation and uses the SP- prefix marking, for example, CUI//SP-CTI. CTI is CUI Specified. Specified is different from CUI Basic; it carries different handling requirements rather than a higher CUI level.

CUI Applies Beyond Defense Contracts

CUI categories that reach civilian SaaS vendors extend well beyond the Defense Industrial Base, including personally identifiable information, federal financial and procurement records, law-enforcement-sensitive data, certain health information, and export-controlled data under the International Traffic in Arms Regulations (ITAR) or the Export Administration Regulations (EAR).

The proposed FAR CUI rule, published January 15, 2025, would extend NIST SP 800-171 compliance obligations to all non-defense federal contractors handling CUI, not just DoD contractors. Current FAR open cases show no final rule has been issued, but civilian agency contracts are moving toward the same baseline DoD contractors already operate under.

When the information is technical, defense-related, and subject to distribution controls, DFARS and DoD distribution rules narrow the analysis.

CTI Is a Defense-Specific CUI Category

CTI is narrower and more specific than general CUI. DFARS 252.204-7012 defines it as technical information with military or space applications that is subject to controls on access, use, reproduction, modification, performance, display, release, disclosure, or dissemination. The statutory basis under 10 U.S.C. 130 covers blueprints, drawings, plans, instructions, computer software, and documentation that can be used to design, engineer, produce, manufacture, operate, repair, overhaul, or reproduce military or space equipment.

Controlled Technical Information Includes Defense-Related Technical Data

DFARS 252.204-7012 and DoD Instruction 5230.24 (January 10, 2023) enumerate the content types that qualify:

  • Research and engineering data.  
  • Engineering drawings and associated lists.  
  • Specifications, standards, and process sheets.  
  • Technical reports, manuals, and technical orders.  
  • Catalog item identifications, datasets, studies, and analyses.  
  • Computer software, executable code and source code.

Publicly available technical information is explicitly excluded. DFARS phrases this as information "lawfully publicly available without restrictions," and DoD Instruction 5230.24 excludes general scientific, mathematical, or engineering principles taught in schools or already in the public domain.

Distribution Statements B Through F Trigger CTI Handling

Distribution statements determine whether a technical document qualifies as CTI.

  • Technical documents receive distribution statements A through F under DoD Instruction 5230.24 to indicate authorized recipients.  
  • Statement A documents are approved for public release with unlimited distribution, so they fall outside the scope of CTI.  
  • Statements B through F restrict distribution to progressively narrower audiences, and any technical document bearing one of these statements qualifies as CTI. It must carry both the distribution statement and the CUI//SP-CTI marking in contractor and non-DoD contexts.  
  • A separate CUI designation decision by an authorized holder is required; a distribution statement alone does not automatically designate a document as CTI/CUI.

CTI Triggers CMMC Level 2

Because CTI is CUI-specified and governed by DFARS 252.204-7012, any covered contractor information system that processes, stores, or transmits CTI must implement all 110 NIST SP 800-171 Rev2 security requirements and achieve CMMC Level 2. The DoD CIO's CMMC program requirements confirm that Level 2 requires all NIST SP 800-171 Rev2 controls invoked by DFARS clause 252.204-7012.

This applies whether the contractor is the prime or a subcontractor, because DFARS 252.204-7012 flows down without alteration to any subcontractor whose performance involves CTI.

CTI and CUI Share a Security Baseline but Differ on Authority

CUI and CTI diverge on tier, governing authority, marking, flow-down mechanics, and certification. Both rest on NIST SP 800-171 and require FedRAMP Moderate-equivalent infrastructure for covered defense cloud systems.

DimensionCUI BroadlyCTI Specifically
DefinitionSensitive unclassified federal data requiring safeguarding controls under law or regulationTechnical data with military or space application is subject to dissemination controls
Governing authorityEO 13556; 32 CFR Part 2002; NARA CUI RegistryDFARS 252.204-7012; DoD Instruction 5230.24
TierCUI Basic or CUI Specified, depending on categoryCUI Specified only
Applicable frameworksNIST SP 800-171; FedRAMP Moderate for applicable cloud systemsNIST SP 800-171; CMMC Level 2; FedRAMP Moderate or FedRAMP High
Who encounters itVendors with federal contracts across civilian or DoD agenciesDefense contractors and subcontractors in the Defense Industrial Base
MarkingCUI or CUI//[Category]CUI//SP-CTI plus Distribution Statement B-F
Flow-down requirementApplies when subcontractor performance involves operationally critical support or covered defense information/CUI handlingMandatory flow-down to applicable subcontractors under DFARS 252.204-7012
Additional obligationNIST SP 800-171 complianceNIST SP 800-171 plus CMMC Level 2 certification

Three scoping distinctions matter most:

  • CTI is always CUI Specified, meaning it carries handling requirements dictated by specific authorizing laws, regulations, or government-wide policies. Other CUI categories may be Basic and follow uniform default controls.  
  • CTI compliance is enforced through DFARS contract clauses, which flow automatically to subcontractors. General CUI compliance in civilian contexts is enforced through agency contracts on a more variable basis.  
  • CTI triggers CMMC Level 2 certification for DoD contractors. General CUI in civilian federal contracts does not require CMMC; the applicable cloud and security obligations come from the contract, the agency, and the CUI authority in scope.

The cloud baseline applies to the DoD environment and DFARS scope, not to whether the CUI category is CTI or another DoD CUI category.

DoD Cloud Infrastructure Requirements Converge for CTI and CUI

Whether a SaaS platform handles broad DoD CUI or the narrower CTI subset, once that data touches an external cloud environment under DFARS, the infrastructure obligation converges on the FedRAMP Moderate-equivalent covered defense baseline. The label on the data changes the contracting and certification work while the DoD cloud hosting baseline stays the same.

FedRAMP Moderate Applies in Covered Defense Cloud Contexts

Any external cloud service provider used to process, store, or transmit covered defense information, including CTI as a subset of CUI, must meet FedRAMP Moderate-equivalent security requirements under DFARS 252.204-7012. Federal Information Processing Standards (FIPS) Publication 199, through its impact classification rules, remains relevant to impact categorization, while the DFARS provides the obligation for covered defense cloud providers.

For CTI in DoD environments, the DoD Cloud Computing SRG V1R6 (December 2025) places CUI at DISA IL-4, which layers DoD FedRAMP+ controls on top of the FedRAMP Moderate baseline. More sensitive workloads may require a FedRAMP High authorization. The infrastructure authorization requirement does not change based on which DoD CUI category is in scope.

Sub-Processor Obligations Follow the Data

The same logic flows down to every service that touches the data. Any external service that handles federal information or directly affects its confidentiality, integrity, or availability belongs in the FedRAMP boundary analysis. A ticketing system, logging tool, or identity provider that receives CTI data without a valid FedRAMP authorization creates a compliance gap that a Third-Party Assessment Organization (3PAO) will flag.

For DoD contractors handling CTI, sub-processor non-compliance also implicates DFARS 252.204-7012 flow-down requirements. A SOC 2 report does not satisfy that flow-down on its own. The practical effect is that the CTI-versus-CUI distinction affects marking, contracting, and certification obligations while leaving DoD cloud hosting requirements aligned.

Authorized Infrastructure Is the Constraint for Federal SaaS Revenue

A CUI or CTI-ready environment usually requires six workstreams:

  1. Achieve Moderate or high levels at a minimum for applicable cloud systems touching CUI or CTI, with covered defense information requiring FedRAMP Moderate-equivalent cloud security and DoD CUI environments mapped to DISA IL-4.  
  2. For DoD contracts involving CTI, achieve CMMC Level 2 certification independently of FedRAMP.  
  3. Implement and document all 110 NIST SP 800-171 controls in a System Security Plan.  
  4. Secure agency sponsorship and undergo an independent 3PAO assessment.  
  5. Maintain Continuous compliance obligations, including vulnerability scans, annual assessment requirements, and remediation timelines.  
  6. Ensure that every external service that handles CUI or CTI is either included within the appropriate authorization boundary or separately authorized at the applicable impact level.

That is the construction project most vendors underestimate. It is also a project that many vendors may not need to own.

Knox Eliminates the Infrastructure Build for CUI and CTI Environments

Knox is a FedRAMP-as-a-Service platform that operates the Knox FedRAMP boundary, meaning SaaS vendors inherit most required controls rather than building them from scratch. Knox currently supports FedRAMP Moderate, FedRAMP High, and DISA IL-4. Impact Level 5 (IL-5) authorization is in process, with an estimated completion date of December 2026.

Knox is designed to let vendors deploy into the Knox FedRAMP boundary across Amazon Web Services (AWS), Azure, or Google Cloud Platform (GCP) with limited re-architecting, inherit 60% to 80% of the required NIST SP 800-53 Rev5 controls depending on scope, and pursue authorization in approximately 90 days. While traditional FedRAMP authorization can take 12 to 36 months and cost upwards of $3.5 million, Knox's managed service brings that down to approximately $500,000 per application, roughly 90% less.

Knox's automated continuous monitoring platform supports ongoing continuous monitoring after authorization. That inherited infrastructure turns the CTI-versus-CUI scoping exercise into an authorization path vendors can execute.

CTI and CUI Scoping Is the Start of the Authorization Path

Cloud services that store, process, or transmit federal information require appropriate authorization when they fall within FedRAMP's scope, and traditional authorization costs can vary widely before a vendor can sign a federal contract. Whether a platform handles broad CUI or the narrower CTI subset, that authorized environment is the gate to federal revenue. The category label is a scoping question for contract review and marking. The authorized environment is what stands between a vendor and a signed contract.

With Knox Systems, vendors handling CUI, CTI, or both can authorize against the federal compliance stack without having to build it themselves. Knox’s FedRAMP boundary spans FedRAMP Moderate, FedRAMP High, and DISA IL-4, covering the data environments required by DoD and civilian agency contracts. IL-5 authorization is in process, with an estimated completion date of December 2026. Vendors can deploy within Knox's boundary and inherit much of the control workload from the infrastructure that is already authorized and continuously monitored.

If your product handles federal data and DoD or civilian agency contracts are on your roadmap, the authorization path starts with a single conversation. Book a meeting with Knox.

FAQs about CTI vs. CUI

Is all CTI considered CUI?

Yes. CTI is a category within the CUI framework and is handled as CUI-Specified. Other CUI categories, including PII or procurement data, may follow different authorities and markings.

Does handling CTI require CMMC certification?

For applicable DoD contracts, yes. Systems handling CTI must comply with NIST SP 800-171 Rev 2 and achieve the CMMC level required by the contract. CMMC Phase 2, which would have required third-party (C3PAO) assessments starting November 10, 2026, was suspended by DoD on July 13, 2026, pending a 60-day program review. Phase 1 self-assessment obligations and DFARS 252.204-7012 safeguarding requirements remain in force during the pause.

What marking distinguishes CTI from other CUI categories?

CTI uses the CUI//SP-CTI banner and a distribution statement B through F in contractor and non-DoD contexts. The marking reflects both its CUI Specified status and its distribution-control requirement.

Does the cloud hosting requirement differ between CTI and general CUI?

In DoD CUI environments, the hosting baseline generally aligns. Covered defense cloud services start from FedRAMP Moderate-equivalent requirements, and CTI in DoD environments maps to DISA IL-4.