sha3:d468682448aaabc8fd6bbc4777b2d1121573f846917a172ea21b122e789beba8Intact462c466dcac66148b54481f8584330ffb1a316ac529419b636de9b226c356d98prev:415a1dcae287RegisterGlossary
What is CUI?
CUI is government-created or -owned information that requires safeguarding under law, regulation, or government-wide policy, but is not classified.
671233a6ef0590eea482b5a19a323ca943ce131460d2b2593816b5a398e47b7cprev:462c466dcac6CUI stands for Controlled Unclassified Information.
Controlled Unclassified Information (CUI) is the category of sensitive-but-unclassified information that drives most CMMC requirements. If a defense contract involves CUI, the contractor generally needs CMMC Level 2 rather than Level 1.
CUI includes things like technical drawings, specifications, engineering data, and program information marked as controlled. Simply receiving or forwarding an email containing CUI puts that system in scope.
Correctly identifying whether you handle CUI — and which of the 80+ CUI categories applies — determines your assessment path (self-assessment vs. third-party C3PAO) and the boundary of your assessment.
d468682448aaabc8fd6bbc4777b2d1121573f846917a172ea21b122e789beba8prev:671233a6ef05Related records
Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.
- proof.state
- Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- proof.change
- Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
- proof.agency
- Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- architecture
- Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.
Related terms and reading
Know the term. Then see the record behind it.
- Sealed
- Last amended
- Unchanged since sealing