6 Examples of Controlled Unclassified Information (CUI)

Written by: 
Team Knox
Published on: 
August 3, 2026

The National Archives and Records Administration (NARA) maintains a CUI category registry of 126 distinct Controlled Unclassified Information (CUI) categories. For Software as a Service (SaaS) vendors entering the federal market, the practical trigger is straightforward: when a platform handles data from any one of those categories on behalf of a federal agency, the vendor inherits compliance obligations under federal law.

Data classification determines the requirement, and that requirement affects Federal Risk and Authorization Management Program (FedRAMP) readiness.

Key Takeaways

  • CUI creates obligations. CUI is unclassified federal data, spans 126 registry categories, and handling any of them on behalf of an agency can create federal or contractual compliance obligations.  
  • Data drives impact. Personally Identifiable Information (PII) generally pushes systems to FedRAMP Moderate; procurement data can require Moderate when the agency's Federal Information Processing Standards (FIPS) analysis assigns Moderate confidentiality impact.  
  • Sensitive categories escalate. Law enforcement and health data can reach FedRAMP High when compromise could cause severe harm to individuals, investigations, or agency operations.  
  • Infrastructure ownership matters. Building a compliant boundary from scratch can cost upwards of $3.5 million, while inheriting a pre-authorized boundary changes the cost and timeline.

Controlled Unclassified Information Drives Federal Compliance Requirements

NARA’s CUI overview describes Controlled Unclassified Information (CUI) as unclassified but sensitive government data that federal law, regulation, or government-wide policy requires agencies to handle with safeguarding or dissemination controls. Established under Executive Order 13556, the CUI program replaced legacy labels, including For Official Use Only and Sensitive But Unclassified, with a uniform framework.

NARA maintains the authoritative CUI Registry, the index of 126 approved CUI categories tied to specific legal authorities. Two tiers exist:

  • CUI Basic, which follows the standard handling requirements set by 32 CFR Part 2002,  
  • CUI Specified, which carries additional or more restrictive controls set by the underlying statute or regulation.

A SaaS vendor whose system handles information designated as CUI within a Registry category for a federal agency or covered contractor may be subject to applicable federal and contractual obligations.

Six CUI Examples Show How Data Type Drives Authorization Scope

Different types of CUI create different handling triggers for SaaS vendors entering federal environments. The examples below are common across defense, civilian, law enforcement, procurement, and health workflows.

1. Controlled Technical Information Creates Defense Contractor Handling Obligations

Defense contractors and technology vendors often handle Controlled Technical Information (CTI) when they store technical schematics, system design documents, software with military or space applications, or research data subject to distribution controls under the Defense Federal Acquisition Regulation Supplement (DFARS). CTI is CUI Specified, carrying CTI banner marking, CUI//SP-CTI, which means stricter handling requirements apply beyond the CUI Basic defaults.

CTI commonly includes:

  • Weapon system specifications and supporting engineering data  
  • Software source code and executable code with a defense application  
  • Export-controlled technical data that overlaps with International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR) regimes  
  • Engineering drawings subject to distribution statement controls under Department of Defense (DoD) Instruction 5230.24

Any platform that handles technical documentation on behalf of a defense contractor or agency is handling CTI. The DFARS safeguarding clause requires that every covered contractor's information system that touches this data meet the National Institute of Standards and Technology (NIST) SP 800-171 Rev3 security requirements, and the clause flows down to subcontractors at every tier.

2. Personally Identifiable Information Drives Moderate Authorization Scope

Federal HR platforms, benefits systems, citizen portals, and procurement tools routinely handle PII in ways that trigger CUI obligations. PII held by federal agencies covers data that can be used to distinguish or trace an individual's identity, and PII is PII considered CUI.

Common examples include:

  • Social Security numbers and other government-issued identifiers  
  • Financial account information tied to federal employees or beneficiaries  
  • Medical records maintained on behalf of an agency  
  • Biometric data used for identity verification  
  • Contact information of federal employees, contractors, or benefits recipients

Handling PII on behalf of a federal agency places a SaaS system at FedRAMP Moderate in virtually all cases. Low-impact SaaS treatment applies only to systems that do not store PII beyond basic login credentials, and FedRAMP 2026 scope rules state that maintaining federal PII for an agency function necessitates authorization.

PII is governed under the Privacy Act category in the CUI Registry. Under the FIPS 199 and FIPS 200 high-watermark rule, a system carrying PII at Moderate confidentiality impact is categorized at no less than Moderate.

3. Export-Controlled Information Adds Access Control Obligations

SaaS platforms enter export control territory when they handle items, commodities, technology, software, and other information whose export could reasonably be expected to adversely affect U.S. national security and nonproliferation objectives. Export-controlled CUI includes dual-use items, items identified in the EAR, the ITAR and the munitions list, license applications, and sensitive nuclear technology information.

Typical examples include:

  • Defense-related design data shared with agency contractors and subject to the U.S. Munitions List  
  • Dual-use technology research funded by federal grants  
  • Satellite or aerospace technical documentation is subject to ITAR controls  
  • License applications and sensitive nuclear technology information

ITAR data and CUI overlap in limited cases; each is governed by distinct legal authorities. The governing underlying authority determines whether the data is Basic or Specified.

SaaS platforms handling export-controlled CUI must meet NIST SP 800-171 Rev3 requirements and ensure no unauthorized foreign nationals can access the data. Under the ITAR deemed export rule, any release of technical data to a foreign person in the United States counts as an export.

4. Federal Law Enforcement Information Can Require High Authorization

SaaS platforms for case management, analytics, and records used by federal law enforcement agencies often process tightly controlled CUI. The legacy Law Enforcement Sensitive label was replaced by the CUI framework. Specifically, the legacy label was replaced by General Law Enforcement in April 2018.

Several Law Enforcement subcategories now carry CUI Specified designation, including Informant, Investigation, Criminal History Records Information, Law Enforcement Financial Records, DNA, and Accident Investigation. These cover data generated by federal law enforcement activities and handled by federal law enforcement agencies.

Specified examples include:

  • Investigation records tied to active or closed cases  
  • Informant and source information  
  • Criminal History Records Information  
  • Law Enforcement Financial Records

Law enforcement data, particularly data whose compromise could endanger individuals or undermine active investigations, frequently pushes systems toward FedRAMP High under the FIPS 199 high-watermark rule. Vendors targeting agencies with these workflows should plan for FedRAMP High rather than Moderate from the outset.

5. Financial and Procurement Information Can Carry Moderate Confidentiality Impact

Agency enterprise resource planning systems, financial management platforms, acquisition tools, and any SaaS product managing federal spend data can process CUI through federal financial and procurement records. That data can include agency budget data, procurement-sensitive records, contractor bid information, and financial transactions involving federal funds.

Examples include:

A commercial SaaS vendor with a finance or procurement product entering a federal deployment may not realize that the data its system processes qualifies as CUI. The FAR proposal disclosure bar prohibits disclosure of contractor bid or proposal information before contract award, and the FAR proposal safeguards require that proposals be protected throughout the source selection process.

Source selection and cost-or-pricing data can carry a moderate confidentiality impact, placing those systems at FedRAMP Moderate when the agency's FIPS 199 analysis reaches that level.

6. Health Information Can Reach a High Authorization Scope

VA enterprise systems, DoD platforms, federally funded clinical or research systems, and federal health program tools can all handle CUI under the health information category. Health information is CUI Specified, covers medical and health information, and appears in federal CUI materials, including the National Archives CUI Registry and agency resources from the Department of Veterans Affairs and DoD.

Health information is governed by both the CUI Registry and the Health Insurance Portability and Accountability Act (HIPAA), where applicable. The HIPAA security standards statute appears as a Specified authority under the CUI health marking, CUI//SP-HLTH.

Examples include:

  • Veteran medical records held in VA enterprise systems  
  • Military personnel health data processed across DoD platforms  
  • Clinical or research health data funded by federal agencies  
  • Beneficiary records held by federal health programs

Health data whose compromise could cause serious harm to individuals or disrupt critical agency operations frequently meets the FedRAMP High threshold. Vendors entering this space should validate their impact level assessment with the sponsoring agency early.

Every CUI Category Leads to the Same Infrastructure Requirements

Regardless of which CUI category a vendor's platform touches, the system must meet FedRAMP requirements where it operates as a cloud service for an agency.

  • The vendor must achieve FedRAMP authorization at the appropriate impact level, and every sub-processor receiving CUI must be addressed within the system boundary, an inheritance relationship, or an equivalent agency-approved authorization path.  
  • PII generally lands at Moderate or High. Source selection and cost-or-pricing data can require Moderate when the agency's FIPS 199 analysis assigns Moderate confidentiality impact. Law enforcement and health data can reach High when compromise could cause severe harm.  
  • DoD workloads can add Defense Information Systems Agency (DISA) IL-4 requirements under the DoD Cloud Computing SRG V1R6, December 2025, on top of the FedRAMP baseline.

For cloud services, the same infrastructure question arises: whether the vendor will build and operate the compliant boundary itself or inherit one.

A Pre-authorized Boundary Reduces the Burden

A pre-authorized boundary shifts the heaviest infrastructure work from the vendor to the platform operator that already holds the Authority to Operate (ATO). Instead of standing up every control from scratch, the vendor inherits a stack that already meets most FedRAMP requirements. With those layers inherited, the vendor's remaining work focuses on the application, its data flows, and the controls unique to how it uses the boundary, rather than on building the compliant substrate beneath it.

Knox is a FedRAMP-as-a-Service platform that operates the pre-authorized FedRAMP boundary, meaning SaaS vendors can inherit most of the required controls. That model maps directly onto the problem that the six examples reveal: no matter which CUI a vendor handles, the underlying infrastructure layer drives much of the work.

The specific layers Knox's pre-authorized boundary covers include:

  • Authorized cloud infrastructure. Compute, storage, networking, and hypervisor layers operate inside an environment that already carries a FedRAMP ATO.  
  • Physical and personnel security controls. Data center access, background screening, and facility safeguards are handled by the boundary operator and inherited as documented controls.  
  • Baseline NIST 800-53 controls. A large share of the applicable Rev5 controls is implemented, tested, and continuously monitored at the platform layer, leaving the vendor responsible only for the application-specific controls above the boundary.  
  • Encryption and key management. FIPS 140-validated cryptographic modules, key storage, and protections for data at rest and in transit are provided as inherited services.  
  • Identity, logging, and audit infrastructure. Centralized identity management, audit logging, SIEM ingestion, and log retention align with FedRAMP requirements without requiring the vendor to rebuild them.  
  • Continuous monitoring and vulnerability management. Scanning cadence, POA\&M tracking, inventory coverage, and monthly ConMon deliverables are executed at the boundary layer.  
  • Incident response and reporting. 24/7 monitoring, incident-handling procedures, and US-CERT reporting workflows are managed by the boundary provider.  
  • Sub-processor coverage. Downstream services already inside the authorized boundary are covered by the same ATO, removing the need to authorize each dependency individually.

Vendors can deploy without re-architecting, use Knox's managed service to support authorization in approximately 90 days, and inherit Knox's active ATOs from the start. Knox's automated continuous monitoring platform then handles the recurring Continuous Monitoring (ConMon) work after authorization, so vendors avoid the mapping, classification, 3PAO assessment, and sustainment lift that would otherwise fall entirely on the application team.

The Right CUI Compliance Path Depends on Infrastructure Ownership

The variable that moves CUI compliance cost and timeline is whether the vendor owns the infrastructure layer or inherits it. Across the 126 categories in the CUI Registry, the data type changes the marking and the impact analysis tied to the underlying authority. The construction project requires the same compliant boundary to be maintained.

Knox's pre-authorized government cloud platform currently supports FedRAMP Moderate, FedRAMP High, and DISA IL-4, with IL-5 authorization in process and an estimated completion date of December 2026. That span covers the CUI categories SaaS vendors commonly encounter, from PII at Moderate to health and law enforcement data at High to CUI processed in DoD environments at IL-4. Vendors come as they are, deploy into the Knox cloud, and inherit the authorized infrastructure layer as part of an approximately 90-day authorization path.

Book a meeting to map the CUI category and authorization path before federal pipeline stalls.

FAQs About Controlled Unclassified Information

Is CUI the same as classified information?

No. CUI is unclassified information that still requires safeguarding or dissemination controls. Classified information is governed under separate authorities and is outside the scope of commercial cloud environments, authorized only for CUI.

What is the difference between CUI Basic and CUI Specified?

CUI Basic follows the standard handling rules. CUI Specified carries additional or different controls written into the underlying statute or regulation.

Does handling CUI automatically require FedRAMP High?

No. The impact level is set by a FIPS 199 analysis of the most sensitive data the system handles. PII and procurement data commonly land at Moderate; law enforcement and federal health data can reach High.

Do my sub-processors also need to be FedRAMP authorized?

Any sub-processor that handles CUI must be covered by an authorization or inheritance model appropriate to the system boundary and impact level. Otherwise, the vendor remains responsible for that part of the stack.

How many CUI categories exist?

The NARA CUI Registry currently lists 126 individual categories organized across 20 groupings. Each category is tied to a legal authority that determines its handling requirements.