If you work with the Department of Defense: or support a company that does: you have probably heard the term Controlled Unclassified Information, or CUI.

You may also have asked:

  • What actually counts as CUI?
  • Where does it show up in our daily work?
  • Are we already mishandling it without realizing it?
  • Could a mistake cost us a contract?
  • Do we really need to build an entire compliance program from scratch?

These are reasonable questions. CUI can feel confusing because it is not classified information, yet it still carries serious legal, contractual, and cybersecurity obligations.

Here is the plain-English answer:

CUI is government-related information that is not classified but still must be protected from unauthorized access, use, disclosure, or loss.

For defense suppliers, protecting CUI is not optional. It is part of protecting your customers, your contracts, your reputation, and the national security mission.

What CUI Means in Plain English

The National Archives describes CUI as information that requires safeguarding or dissemination controls under applicable law, regulation, or government-wide policy. The federal CUI Program standardizes how this information is handled.

Think of CUI this way:

It is not a secret: but it is not public.

CUI may be information that the government gives to your company, or information your company creates while performing government work. The information may relate to a defense system, a federal program, a government employee, a contract requirement, or a technical capability.

CUI is a handling designation, not a classification level like Secret or Top Secret. Classified information is governed by a different security framework. CUI still requires disciplined protection, but it is handled under a separate set of rules.

What Might Be CUI?

The exact designation depends on the information, the contract, the applicable category, and the governing requirements. Common examples in the defense supply chain may include:

  • Technical drawings, specifications, and engineering documentation
  • Unclassified Technical Information
  • Export-controlled technical data
  • Design details for weapons, aircraft, vehicles, or components
  • Test results and inspection reports
  • Vulnerability findings and security assessments
  • Statements of work and contract performance information
  • Government-furnished information
  • Personally identifiable information connected to a government program
  • Maintenance, logistics, or operational data
  • Source code, build information, or configuration data
  • Photos of equipment, facilities, or prototypes
  • Internal emails discussing protected contract details

The important point is that CUI is not limited to a file marked “CUI.”

It can appear in an email thread, a help-desk ticket, a spreadsheet, a CAD file, a photograph, a backup, or a printed document sitting on a desk.

Blue shield and checklist representing CUI protection and CMMC compliance

Where CUI Shows Up in Daily Defense Supplier Work

CUI often moves through ordinary business processes. That is exactly why it is easy to mishandle.

A typical workday might involve:

  1. Receiving a technical package from a prime contractor.
  2. Saving the files to a shared drive.
  3. Sending selected documents to an engineer or subcontractor.
  4. Discussing the project over email or video conferencing.
  5. Uploading test results to a collaboration platform.
  6. Printing drawings for a production meeting.
  7. Copying files to a laptop or removable drive.
  8. Backing everything up automatically.
  9. Using an artificial intelligence tool to summarize or analyze the content.

Every one of those steps creates a potential CUI handling decision.

You need to know:

  • Who is authorized to access the information?
  • Where is it stored?
  • How is it transmitted?
  • Which devices can process it?
  • Are backups protected?
  • Are subcontractors and vendors properly controlled?
  • Can your security team produce evidence of those protections?

The danger is not only an obvious data breach. A well-meaning employee can create exposure by forwarding a document to a personal email address, placing it in an unapproved cloud drive, using an unsanctioned AI application, or leaving a printed copy in an unsecured conference room.

What Is Not Automatically CUI?

Not every piece of information connected to a defense supplier is automatically CUI.

For example:

  • Publicly available information is generally not CUI simply because it appears in a defense contract.
  • A company’s ordinary internal business information is not automatically CUI.
  • Information being proprietary does not, by itself, make it CUI.
  • Classified information is not CUI; it falls under separate classification controls.
  • A document’s label alone does not replace the need to understand its source and governing requirements.

That said, do not make the determination based on guesswork. Review contract language, flowdown clauses, markings, customer instructions, and applicable agency guidance. When the answer is unclear, ask your contracting officer, prime contractor, security lead, or qualified compliance advisor.

A practical starting checklist is:

  • Where did the information come from?
  • Was it created for or received from the government?
  • Does a contract, regulation, or policy require protection?
  • Does it contain technical, operational, personal, or program-sensitive details?
  • Where does it live and who can access it?

Why Mishandling CUI Is a Contract Problem

Mishandling CUI is not just an IT issue. It can become a contract performance issue.

Defense contracts commonly impose requirements for safeguarding information, reporting incidents, controlling access, managing subcontractors, and maintaining secure systems. If your organization cannot demonstrate that it protects CUI, you may face:

  • Corrective actions
  • Incident response and reporting obligations
  • Customer investigations
  • Loss of customer confidence
  • Delayed payments or deliverables
  • Contract restrictions
  • Reduced eligibility for new work
  • Assessment failure
  • Suspension of work or contract termination

A CUI incident can also expose technical details to competitors, criminal groups, or nation-state actors. Even when the information is unclassified, it may reveal how a system works, where it is vulnerable, or what capabilities it has.

That is why the NIST SP 800-171 requirements focus on protecting CUI in nonfederal systems. And that is why CMMC 2.0 Level 2 exists for organizations handling CUI in the Defense Industrial Base.

The simple relationship is:

  • CUI is the information.
  • NIST SP 800-171 is the security requirements framework.
  • CMMC 2.0 Level 2 is the assessment and certification requirement for applicable contracts.

For the Rev. 2 framework commonly used in CMMC Level 2 planning, that means 110 security requirements and 320 assessment objectives.

You Do Not Need to Put Your Entire Business Inside the Enclave

Many suppliers assume that CMMC compliance means rebuilding every system, application, laptop, and business process they operate.

That is not always necessary.

A better approach is often to identify the CUI boundary and place the systems that store, process, transmit, or protect CUI inside a properly designed environment.

This is where CPE Level 2 makes the process practical.

Instead of asking your entire business to become a massive compliance project, you can create a purpose-built CUI environment with the controls, policies, infrastructure, monitoring, and procedures needed for the protected workload.

Secure server environment illustrating an isolated CUI protected enclave

How CPE Level 2 Helps Protect CUI

CPE Level 2 combines hardware, software, security configuration, organizational policies, procedures, training, monitoring, and managed operations into one integrated solution.

That matters because CMMC is not satisfied by buying a firewall and hoping for the best.

A practical CUI environment needs to address:

  • Access control and least privilege
  • Multi-factor authentication
  • Network segmentation
  • Secure configuration and hardening
  • Encryption for data at rest
  • Secure communications
  • Audit logging and accountability
  • Vulnerability management
  • Security awareness and insider-threat training
  • Incident response
  • Media protection
  • Physical security
  • Backup and recovery
  • Continuous monitoring
  • Evidence collection for assessment readiness

CPE Level 2 is designed around 100% coverage of the 110 CMMC 2.0 Level 2 security requirements and 320 assessment objectives in the applicable Rev. 2 scope.

It also includes practical operational support, such as:

  • Required security policies and procedures
  • Employee and contractor security awareness training
  • Security patching and maintenance
  • Integrated onsite and offsite backup
  • Ongoing functional and security monitoring
  • Monthly virtual CISO guidance
  • Procedures for protecting hard-copy CUI
  • Support during assessment and audit activities

Implementation is commonly achieved in approximately 4–8 weeks, depending on the organization, scope, and deployment approach.

What About AI and CUI?

This is an area where defense suppliers need to be especially careful.

Generic AI tools cannot be trusted with client data by default. Uploading CUI into a public or unapproved AI service can create an unauthorized disclosure, even if the tool is being used for something harmless like summarizing a document.

Planet Security takes a different approach by using AI-obfuscated data in AI-enabled workflows. The objective is to gain the productivity benefits of AI without handing sensitive client or government information directly to Big-Tech systems.

That distinction is critical:

AI can support secure operations: but only when the data handling model is secure first.

Peace of Mind Without Starting From Zero

The real value of CPE Level 2 is not simply the technology. It is the reduction of uncertainty.

You do not have to assemble a separate vendor for every control family. You do not have to spend months trying to determine whether your policies, servers, backups, and monitoring tools fit together. You do not have to build an entire compliance program from scratch before you can protect the CUI workload that matters most.

You get a defined environment, a documented security architecture, ongoing operations, and a practical path toward assessment readiness.

That does not eliminate your responsibilities. Your organization still needs to use the enclave correctly, manage authorized personnel, follow procedures, and maintain accurate business practices. But it gives you a strong foundation instead of a blank page.

Planet Security CPE Level 2 deployment roadmap for defense suppliers

Frequently Asked Questions

Is CUI the same as classified information?

No. CUI is unclassified information that requires safeguarding or dissemination controls. Classified information follows a different security and handling framework.

Does every defense supplier handle CUI?

No. It depends on the contracts, data, systems, and obligations involved. However, many defense suppliers receive or create CUI through prime contracts, subcontracts, engineering work, testing, logistics, and support activities.

Can CUI be sent by email?

It can be transmitted only through an appropriately protected and authorized process. Ordinary email, personal accounts, unapproved file-sharing services, and consumer collaboration tools may create unacceptable exposure.

What should we do if we cannot tell whether a file is CUI?

Start with the contract, customer instructions, markings, and applicable agency guidance. Then ask your contracting officer, prime contractor, or qualified security advisor. Do not treat uncertainty as permission to share the data freely.

Does CPE Level 2 automatically guarantee that we pass a CMMC assessment?

No solution can replace responsible operations and organizational accountability. CPE Level 2 provides an integrated environment and support model designed to address the applicable CMMC 2.0 Level 2 requirements, objectives, evidence, and operational practices. Your organization must still operate the environment properly and meet its contractual obligations.

Can we use AI tools with CUI?

Do not place CUI into generic AI tools without verified authorization and protections. Planet Security emphasizes AI-obfuscated data to help support AI-enabled workflows while reducing exposure of client and government information.

Protect CUI Before It Becomes a Crisis

CUI confusion is common. CUI exposure is preventable.

The right first step is to identify what information you handle, where it moves, who needs access, and what your contracts require. From there, a purpose-built environment such as CPE Level 2 can give your organization a faster, more practical way to protect CUI without turning every part of the business into a compliance experiment.

There is no substitute for knowing where your CUI is and controlling it deliberately.

We welcome a discussion on how we may assist in your CMMC success story!

Learn more about CPE Level 2 or call 702.634.7233.


planetsecurity.net 702.634.7233 QR code for Planet Security
Scroll to Top