---
title: "What Is CUI? CMMC Definition"
description: "CUI is government-created or -owned information that requires safeguarding under law, regulation, or government-wide policy, but is not classified."
url: https://policycortex.com/cmmc/glossary/cui
sealed: 2026-07-02
register: cmmc/glossary/cui
records: 3
digest: sha3:d468682448aaabc8fd6bbc4777b2d1121573f846917a172ea21b122e789beba8
---

# What is CUI?

Register / Glossary

CUI is government-created or -owned information that requires safeguarding under law, regulation, or government-wide policy, but is not classified.

Sealed 2026-07-02

CUI stands for Controlled Unclassified Information.

Controlled Unclassified Information (CUI) is the category of sensitive-but-unclassified information that drives most CMMC requirements. If a defense contract involves CUI, the contractor generally needs CMMC Level 2 rather than Level 1.

CUI includes things like technical drawings, specifications, engineering data, and program information marked as controlled. Simply receiving or forwarding an email containing CUI puts that system in scope.

Correctly identifying whether you handle CUI — and which of the 80+ CUI categories applies — determines your assessment path (self-assessment vs. third-party C3PAO) and the boundary of your assessment.

## Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

- **proof.state**: [Proof of State](https://policycortex.com/proof/state). What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- **proof.change**: [Proof of Change](https://policycortex.com/proof/change). Who or what altered the environment, under what authority, with before and after state hashes.
- **proof.agency**: [Proof of Agency](https://policycortex.com/proof/agency). What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- **architecture**: [Architecture](https://policycortex.com/architecture). How the chain is built and where it lives: inside your tenant, with no egress of evidence.

### Related terms and reading

| Entry |
|---|
| [FCI: Federal Contract Information](https://policycortex.com/cmmc/glossary/fci): FCI is information provided by or generated for the government under a contract that is not intended for public release: the trigger for CMMC Level 1. |
| [NIST SP 800-171](https://policycortex.com/cmmc/glossary/nist-800-171): NIST SP 800-171 is the federal standard of 110 security controls for protecting CUI in non-federal systems: the technical basis of CMMC Level 2. |
| [C3PAO: CMMC Third-Party Assessment Organization](https://policycortex.com/cmmc/glossary/c3pao): A C3PAO is an organization authorized by the Cyber AB to conduct official CMMC Level 2 certification assessments. |
| [CMMC Level 2 Requirements: Complete Guide](https://policycortex.com/blog/cmmc-level-2-requirements-2026-complete-guide) |

Know the term. Then see the record behind it. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

Dates of record

- **Sealed**: 2026-07-02
- **Last amended**: Unchanged since sealing
- **Record**: https://policycortex.com/cmmc/glossary/cui

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | HEAD | 462c466dcac6 | 415a1dcae287 |
| REC 0001 | DEFINITION | 671233a6ef05 | 462c466dcac6 |
| REC 0002 | RELATED RECORDS | d468682448aa | 671233a6ef05 |

Head sha3:d468682448aaabc8fd6bbc4777b2d1121573f846917a172ea21b122e789beba8. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
