Three letters appear in almost every CMMC conversation: CUI. If you hold or expect to hold DoD contracts, you need to understand what CUI is, whether your business handles it, and why it determines your CMMC compliance requirements.
Most explanations of CUI are written for government agencies and large defense primes, not for a small manufacturer trying to figure out if the drawings their prime contractor sends them qualify. This post is written for you.
Have questions about this topic?
Book a call with us and get your questions answered directly.
Book a Call with Us →What Does CUI Stand For?
CUI stands for Controlled Unclassified Information. It is information the U.S. government creates or possesses (or that a contractor creates on behalf of the government) that requires safeguarding, but is not classified. CUI is not top-secret. It does not require a security clearance. But it requires specific protections because its exposure could harm government operations, national security, or individual privacy. See the CUI Registry at the National Archives for the full category list.
What Does CUI Actually Look Like for a Manufacturer?
CUI in a manufacturing context typically includes:
- Technical drawings, blueprints, and design specifications received from a DoD prime contractor or the government
- Engineering specifications, materials lists, and manufacturing process documents for defense components
- Test data, quality control results, and inspection records tied to defense contracts
- Contract details, statements of work, and project communications with sensitive technical content
- Software source code or technical documentation for systems used in defense applications
A simple test: if the document came from your prime contractor and it is not publicly available, there is a reasonable chance it contains CUI. When in doubt, treat it as CUI and protect it accordingly.
Why Does CUI Determine Your CMMC Level?
CMMC Level 2 exists specifically to protect CUI in the defense supply chain. If your business handles CUI, regardless of how small you are or how indirectly you are connected to the DoD, Level 2 applies to you. Level 2 requires all 110 NIST SP 800-171 controls, verified by a third-party assessor. See our CMMC Level 1 vs. Level 2 guide for the full breakdown.
How Do I Know If My Business Handles CUI?
Look for these indicators:
- Your contract includes DFARS clause 252.204-7012
- You receive technical documents from a prime contractor marked ‘CUI’, ‘FOUO’, or ‘Controlled’
- Your work involves manufacturing or testing components described in documents received from the government or a prime
- Your prime contractor has told you that you need CMMC Level 2 compliance
What Do I Need to Do to Protect CUI?
Protecting CUI under CMMC Level 2 means implementing all 110 NIST SP 800-171 controls. The practical starting point is scoping: understanding exactly where CUI lives in your systems, which personnel have access, and how it flows through your organization. A CMMC gap assessment is the structured process for doing this work.
Start with a Free CUI Assessment
CGA’s CMMC Gap Assessment Grant funds a comprehensive evaluation of your organization’s CUI handling and overall CMMC readiness. Apply now to secure your grant.
Apply Now →Download Our Free CMMC Guide
Cyber Grants Alliance publishes a plain-language CMMC Guide for DIB manufacturers. Get a clear picture of the requirements, timeline, and your options.
Get the Guide →