Do You Actually Hold CUI on a Civilian Contract?
Sensitive, proprietary, and export-controlled are three different things. None of them is automatically Controlled Unclassified Information — and the difference decides your scope.
By Rob Maupin, founder of Overwatch Tools and author of the CMMC Practical Guides series — Volume 1: CMMC Level 1 and Volume 2: CMMC Level 2.
⚠ This rule is proposed, not final
Nothing in this article describes an obligation you are currently failing to meet. The FAR CUI rule is a proposal. Obligations attach only when a final rule issues and the resulting clauses appear in your contracts. Clause numbers, the form designation, and the details can and probably will shift before then. Read this as lead time, not urgency — the identification work described here takes the same number of weeks whether a rule is pending or not, and only one of those schedules belongs to you.
Every conversation about the proposed FAR CUI rule arrives at the same place. A contractor asks what the controls cost, how long the documentation takes, or whether they need a different license tier. Reasonable questions. They're also the second question.
The first question is whether the rule reaches your data at all. Controlled Unclassified Information — CUI — is a narrower and stranger category than most small contractors assume. On the defense side, a decade of DFARS 252.204-7012 flow-downs forced the vocabulary into common use. On the civilian side it mostly didn't, because civilian agencies improvised: some issued their own safeguarding clauses, some pointed at an agency handbook, many said nothing specific at all. A contractor can be fifteen years into supporting a civilian agency, excellent at the work, and have never had a reason to learn where the CUI line sits.
The proposed rule changes that, in a way that is genuinely favorable to small contractors. But it does not answer the question for you. It answers a related question, and the gap between the two is where the work lives.
What CUI actually is
CUI is not a description of how sensitive something feels. It is a legal status conferred by an authority.
The program traces to Executive Order 13556, signed in 2010 to replace a sprawl of agency-specific markings — For Official Use Only, Sensitive But Unclassified, and dozens of local variants — with one governmentwide system. The National Archives and Records Administration acts as the CUI Executive Agent. The implementing regulation is 32 CFR part 2002. The authoritative list of what qualifies is the CUI Registry, which NARA publishes and maintains.
Three consequences follow, and they matter more than the definition.
1. It is category-based
Information is CUI because it falls into a category the Registry recognizes — more than a hundred of them, in index families like Defense, Export Control, Privacy, Procurement and Acquisition, and Critical Infrastructure. If it doesn't map to a Registry category, it isn't CUI, however badly you'd rather nobody saw it.
2. It is agency-designated
An authorized holder — ordinarily the designating agency — determines that a specific item qualifies and applies the marking. A contractor does not confer CUI status on its own information by deciding the information is important. You can hold CUI. You generally do not create it out of nothing.
3. Basic and Specified are not the same
CUI Basic is the default: the source authority protects the information but doesn't prescribe handling. CUI Specified carries handling or dissemination requirements written into that authority. It rarely changes your technical baseline, but it can change dissemination limits — and those show up in contract language, not in a control list.
The legacy-marking trap
Under 32 CFR 2002.20, the markings in the CUI Registry are the only authorized way to designate unclassified information as requiring safeguarding. A document still carrying an old For Official Use Only or Sensitive But Unclassified banner tells you nothing: that marking is void. It doesn't establish that the information is CUI, and it doesn't establish that it isn't. A stack of FOUO-stamped PDFs on an agency share is a question, not an answer.
Three words that are not synonyms for CUI
Most of the confusion at our end of the market comes from three substitutions. Each is common, each is understandable, and each produces a scope that's either too big or too small.
| The word | Why it isn't the same thing |
|---|---|
| Sensitive | A judgment, not a designation. Plenty of genuinely sensitive government information is not CUI, and some information that feels routine — certain procurement and acquisition data, for instance — is. Scoping to your intuition produces a boundary with no relationship to your obligation. |
| Proprietary | Your trade secrets, pricing models, and internal designs are yours to protect and no part of the federal CUI program. Contractor proprietary information can become CUI when a specific authority brings it in — but that comes from the authority, not from your preference. Protecting it is good business. It isn't compliance. |
| Export-controlled | This one overlaps, which is why it misleads. Export Control is a Registry category, so export-controlled technical data received under a federal contract often is CUI. But your ITAR and EAR obligations stand on their own and aren't satisfied by CUI safeguarding — and export-controlled material from purely commercial work isn't pulled into a contract's CUI scope by sharing a file server. |
The pattern underneath all three: people reason from the character of the information to its status. The program runs the other way — status comes from a category and an authority, and handling follows from status.
FCI versus CUI — the distinction that sets your scope
Before CUI is even in play, there is a lower tier most small contractors are already standing in and don't have a name for.
Federal Contract Information — FCI — is information provided by or generated for the government under a contract, not intended for public release. Broad and mundane: task orders, delivery schedules, unreleased performance data, most of your contract correspondence. If you hold a federal contract that isn't purely for commercially available off-the-shelf items, you almost certainly hold FCI. FAR 52.204-21 has required fifteen basic safeguarding practices for it since 2016 — on civilian contracts as much as defense ones. Those fifteen practices are also, verbatim, CMMC Level 1.
Federal Contract Information
- Broad, contract-generated, not for public release
- Governed by FAR 52.204-21 — 15 practices
- At CMMC Level 1: MET / NOT MET plus an annual affirmation — no numeric score, no POAM
- Documented with a system description, not a system security plan
- Commercial Microsoft 365 or Google Workspace is sufficient
Controlled Unclassified Information
- Narrow, category-based, designated by an agency
- Governed today by DFARS 252.204-7012 on the defense side; the proposed FAR rule would add a governmentwide framework
- Baseline is NIST SP 800-171 — the proposed rule reaches for Rev. 3
- Documented with a system security plan, POAM framework, and risk register
- Platform variant matters — a dedicated enclave on Google Workspace or Microsoft 365 GCC High
Two things follow that contractors routinely get backwards.
Holding CUI does not replace your FCI obligation. It adds to it. The enclave holds the CUI; the rest of your environment still holds FCI and carries its own Level 1 obligation. Level 2 sits on top of Level 1, never instead of it. That is a fact about the obligations, not a sales argument — it's true whether you build the thing yourself, hire someone else, or work from a book.
And most small contractors hold FCI only. The default assumption in a lot of vendor marketing is the opposite, which is how a five-person shop ends up quoted for an enclave it doesn't need. This distinction is worked through at length in both volumes of the CMMC Practical Guides — Volume 1 takes the FCI side and the scoping consequences that follow from it, Volume 2 takes CUI enclave scoping — because getting the line wrong in either direction is the most expensive single mistake available at either level. Scope too wide and you buy controls for data that never needed them. Scope too narrow and your documentation describes a boundary your data doesn't respect.
⚠ Self-Assessment Programs Only. The L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO — a certified third-party assessor organization — are not in scope.
What the SF XXX would do — and what it wouldn't
Here is the part of the proposed rule that deserves more credit than it has gotten.
Both the January 2025 version and the June 2026 rewrite build around a new standard form, referred to in the draft as the SF XXX, Controlled Unclassified Information Requirements. Under the proposal, the contracting officer completes it for the solicitation and identifies whether CUI is expected to be involved in performance, which categories, where it will reside, and which safeguarding and reporting requirements attach. The June version pairs it with clauses designated FAR 52.240-6 and 52.240-7, with 52.240-7 carrying the substantive safeguarding and incident-reporting obligations where CUI is involved. The June version also dropped FAR 52.204-YY, the January clause that addressed identifying and reporting potentially-CUI information.
The significance for a small contractor is structural. Today, on a civilian solicitation, the first move of identification is effectively yours — you read the statement of work, you guess, and you either over-scope defensively or under-scope optimistically. The proposal moves that first move to the agency. That is a real improvement, and it is worth saying plainly, because most coverage of this rule treats it exclusively as new burden.
What it would not do
It doesn't remove your obligation to speak up
Unmarked and mismarked CUI is a persistent condition — agencies can waive re-marking of legacy holdings while that material stays under agency control, and it doesn't always stay there. The proposal preserves the contractor's duty to notify the contracting officer when CUI arrives improperly marked. A form that says “no CUI” and an inbox that contains it is a scenario the rule anticipates and assigns to you.
It describes the contract, not your environment
The form says what the government expects to send and where it expects the information to live. It says nothing about your mail flow, file shares, backup targets, subcontractor collaboration folder, or the laptop somebody uses at home on Tuesdays. The boundary is yours to draw; the form is an input to that exercise, not a substitute for it.
It doesn't arrive uniformly on day one
Contracting officers will complete these forms at different levels of precision, and the Council expects finalization before the end of 2026 with no anticipated phase-in once the clauses appear. A contractor whose entire identification strategy is “wait for the form” starts scoping the day the clause lands.
📚 Going deeper than a blog post can
This article covers identification. The full method — scoping decisions, the artifacts that prove them, and the self-assessment itself — runs to two volumes.
CMMC Level 1: A Practical Guide for Small to Medium GovCon Contractors
All fifteen practices, FCI versus CUI, scoping, the system description, evidence, and the annual affirmation — written for the 5- to 50-employee contractor.
CMMC Level 2: A Practical Guide for Small to Medium GovCon Contractors
CUI enclave scoping, the 110 practices across 14 domains, the system security plan, POAM framework, and risk register — without assuming an enterprise IT department.
Overwatch Press. Kindle, paperback, and hardcover — Kindle from $12.99. See the series on Amazon →
Reading a solicitation for CUI signals today
The form doesn't exist yet. Solicitations still go out. So what do you actually look at?
A caution first, and it isn't boilerplate: whether a given contract involves CUI is a contract-interpretation question. What follows is not a determination framework and not legal advice — it's a list of places the answer tends to leave fingerprints. The point of noticing them is to arrive at a specific, well-formed question for your contracting officer and, where the stakes justify it, your attorney.
- The deliverables list. Anything you are producing for the government using government-furnished information is the likeliest place for a category to attach.
- Government-furnished information and data clauses. What is the agency handing you, and does the solicitation put handling limits on it?
- Agency-specific safeguarding clauses and handbooks. The patchwork the proposed rule is meant to replace — and, until it does, still the governing text on civilian work.
- Any DFARS 252.204-7012 flow-down. On mixed portfolios this is the loudest signal available, and it's already sitting in contracts you have.
- Categories named outright. Some solicitations already say “controlled technical information” or name a Registry category directly. People skim past it because the acronym CUI never appears.
- What the last contract like this one produced. The most useful evidence is often historical: what did the agency actually send you last time, and how was it marked?
The subcontractor blind spot
If you sit below a prime, none of the above may reach you directly. The solicitation isn't yours. The contracting officer isn't yours. Your visibility is whatever your prime chooses to pass down.
Under the proposal, primes prepare and distribute the form downstream at every tier where CUI is handled. That's the mechanism by which a shop with no direct federal relationship acquires a federal safeguarding obligation. And because commercial products and services sit inside the rule's scope — with a narrow exception for contracts solely for commercially available off-the-shelf items — “we just sell them a commercial service” isn't automatically the exit people assume.
The practical move is unglamorous: ask your prime, in writing, what they expect to send you and how it will be marked. Ask now, while it's a planning conversation rather than a modification. Most primes have no idea either, which is itself useful and tends to make you the easiest sub on their list.
Not sure which side of the line you're on?
That's the conversation to have out loud, with someone who has run it before. Thirty minutes, no charge, no pitch deck — we walk your contracts, your data flows, and where your boundary would sensibly sit.
Book a 30-Minute Consultation → We don't make CUI determinations for clients — that's between you, your contracting officer, and your counsel. We help you ask the right question and build to the answer.Scope is where cost is decided — not the control list
Here is the argument this article has been building toward. The control list is fixed — NIST SP 800-171 is what it is, and you don't negotiate the requirements. What you control is how much of your company they apply to, and that single decision moves cost more than every other decision in a compliance program combined.
The FAR Council's own analysis of the January 2025 version, priced against NIST SP 800-171 Rev. 2, estimated $148,200 in the initial year and $98,800 annually recurring for a small business, against $543,400 initial and $494,000 recurring for other-than-small entities. Read those as a pair: they are the Council's estimate of implementing that revision, not a quote and not an assessment fee. What they illustrate is the shape of the problem — cost scales with the size of the protected footprint, not with the length of the control list.
A contractor who hardens the entire company for CUI it holds on one contract pays the larger number to protect a small amount of data. A contractor who confines that data to a defined enclave pays for the enclave. Same controls, same standard, radically different bill — and the difference compounds when the same architecture has to answer to two regimes at once, which is exactly the situation a mixed-portfolio contractor is walking into. That's the subject of Part 4.
⚠ Self-Assessment Programs Only. Our L2 CUI Enclave Package is scoped for CMMC Level 2 programs eligible for annual self-assessment. Programs required to use a C3PAO are not in scope. We provide templates, configuration guides, and consulting — clients implement.
What you can do before a final rule exists
Two pieces of work. Neither depends on the rule's final language, and neither is wasted if the rule shifts.
Build the watch list
One page. Every active contract and serious pursuit, four columns: the agency, what information they send you, how it's marked, and whether the contract file addresses safeguarding. Write “unknown” rather than guessing — the unknowns are your question list, and the reason to call your contracting officer while nothing is on fire.
Map the data flows
Where does information from each contract actually go? Not the org-chart version — the real one. Which mailboxes, shared drives, laptops, personal phones, subcontractors, backup destinations. Most small contractors have never written this down, and the exercise routinely surfaces two or three paths nobody intended. It's useful the moment it exists, independent of the rule: it's the input to a boundary decision, the foundation of a system description at Level 1, and the first thing anyone asks for if you ever do need an enclave.
Our analysis — not a commitment
In our experience a small contractor with a handful of contracts gets both to a usable first draft in a few working sessions. That reflects what we typically see, not a guarantee — it moves with how many contracts you carry, how much of your history is documented, and how fast your contracting officers answer.
What we'd avoid: buying licensing, tooling, or an architecture before the watch list and the flow map exist. Purchases made ahead of scope are the ones that get replaced.
Start where the answer is cheapest to change
The identification and scoping conversation costs nothing and determines everything downstream. Bring your contract list; we'll bring the questions.
Schedule Your 30-Minute Call → Free Level 1 Gap Check The free tool covers all 15 CMMC Level 1 practices and returns a prioritized gap report in under 30 minutes — useful if FCI is where you're starting. No credit card.The Second Front — a four-part series
- The CMMC Pause Didn't Touch Your Civilian Contracts — one pause, two regimes, and who the FAR CUI rule reaches.
- Do You Actually Hold CUI on a Civilian Contract? — you're here.
- Rev. 2 to Rev. 3: What Changes for a Small Enclave — the delta, and why it's the longest-lead item in the rule.
- One Enclave, Two Regimes — building a boundary once that answers to both sets of requirements.
About the author
Rob Maupin is the founder of Overwatch Tools, a CMMC compliance practice for small to medium defense contractors, and the author of the CMMC Practical Guides series from Overwatch Press: CMMC Level 1: A Practical Guide for Small to Medium GovCon Contractors and CMMC Level 2: A Practical Guide for Small to Medium GovCon Contractors. Both are available in Kindle, paperback, and hardcover — Kindle from $12.99. He works with 5- to 50-employee GovCon firms on right-sized compliance.
Sources
- Federal Register — Revolutionary FAR Overhaul proposed rules, June 23, 2026 (91 FR 37550)
- Federal Register — FAR Controlled Unclassified Information proposed rule, January 2025 (90 FR 4278, FAR Case 2017-016)
- Hunton Andrews Kurth — analysis of the updated CUI proposed rule, June 30, 2026
- NARA — the CUI Program and the CUI Registry
- 32 CFR 2002.20 — CUI marking requirements
- Department of War — CMMC Phase II suspension release, July 13, 2026
- SBA Office of Advocacy — CMMC Reform Task Force request for information
- NIST SP 800-171
This article is general information about a proposed regulation, not legal advice. Contract interpretation and any question touching False Claims Act exposure should go to your attorney.
