Controlled Unclassified Information (CUI)

Overview

Controlled Unclassified Information (CUI) is government information that requires safeguarding or dissemination controls pursuant to federal law, regulation, or government-wide policy but is not classified under Executive Order 13526 or the Atomic Energy Act.

Federal agencies use the CUI Program to provide a uniform approach for identifying, marking, safeguarding, disseminating, decontrolling, and disposing of sensitive government information.

Researchers may encounter CUI in federally sponsored research, federal contracts and subcontracts, cooperative agreements, or other activities involving information provided by or generated for the U.S. Government.

The Office of Research Security (ORS) assists faculty, staff, and students in determining whether CUI requirements apply to a research project, identifying applicable safeguarding requirements, and coordinating with the appropriate University offices to support compliance.

CONTACt ors

Federal Contract Information (FCI) and CUI are distinct categories of government information. Some projects may involve FCI, CUI, or both. ORS can assist researchers in determining which requirements apply based on the sponsor, award type, and applicable terms and conditions.


What Is Controlled Unclassified Information?

Controlled Unclassified Information is information that the Federal Government has determined requires safeguarding or dissemination controls but does not meet the standards for classification.

Unlike classified information, CUI generally does not require a security clearance for access. However, access may be limited to authorized individuals, and the information must be protected and handled in accordance with applicable federal laws, regulations, agency requirements, and award or contractual terms.

The Federal Government determines what information qualifies as CUI. Researchers should not independently designate research information as CUI unless directed or authorized to do so under applicable federal requirements.


How Is CUI Identified?

CUI requirements or information may be identified through:

  • Sponsor award terms and conditions
  • Contract or subcontract requirements
  • Information markings or banners
  • Agency instructions
  • Government-furnished information
  • Contract deliverables
  • Prime contractor communications
  • Other sponsor documentation

The presence of sensitive, proprietary, or nonpublic information does not by itself mean that the information is CUI.

If researchers receive information identified as CUI or encounter an award requirement referencing CUI, they should contact ORS before receiving, accessing, storing, processing, or transmitting the information.


Examples of CUI

Federal CUI categories and subcategories cover many types of government information. Depending on the sponsoring agency and activity, examples may include:

  • Controlled technical information
  • Certain export-controlled information
  • Critical infrastructure information
  • Certain proprietary or procurement information
  • Certain engineering and design information
  • Certain privacy-protected information
  • Other information identified within the National CUI Registry

Not all sensitive, proprietary, export-controlled, or nonpublic research information is CUI. Whether information is CUI depends on its federal designation and the applicable authority.


When Might Researchers Encounter CUI?

Researchers may encounter CUI when:

  • Performing research under certain federal contracts or subcontracts.
  • Receiving information directly from a federal agency.
  • Working on projects involving government-controlled information.
  • Collaborating with federal laboratories or government agencies.
  • Receiving CUI from a prime contractor or subcontractor.
  • Participating in projects where award terms require safeguarding of government information.

Most fundamental research conducted at Stony Brook University does not involve CUI. However, investigators should review sponsor requirements and award terms and conditions because CUI requirements are project-specific.


Typical Safeguarding Considerations

Projects involving CUI may require:

  • Access limited to authorized personnel.
  • Secure storage of electronic and physical information.
  • Specific cybersecurity safeguards.
  • Controlled transmission and sharing of information.
  • Restrictions on dissemination.
  • Use of approved research computing environments.
  • Incident reporting or other sponsor-required procedures.
  • Compliance with applicable sponsor, award, and contractual requirements.

The specific safeguards required depend on the sponsoring agency, award or contract requirements, information involved, and computing environment.

Researchers should not receive or store CUI in a research system or other computing environment until applicable requirements have been identified and the appropriate safeguards are in place.


Related Requirements

Research involving CUI may also involve:

  • Federal Contract Information (FCI)
  • Export-Controlled Information
  • Federal contract cybersecurity requirements
  • Sponsor-specific cybersecurity requirements
  • Research information protection requirements
  • Data Protection Plans
  • Technology Control Plans, when applicable

The presence of CUI does not necessarily mean that all of these requirements apply. ORS assists researchers in identifying the requirements applicable to the specific project.


How ORS Can Help

ORS assists researchers by:

  • Determining whether a project involves CUI or CUI-related requirements.
  • Reviewing sponsor, award, contract, and subcontract requirements.
  • Identifying applicable research information protection, cybersecurity, and export control requirements.
  • Determining whether project-specific safeguarding measures are required.
  • Coordinating with Research Computing & Informatics (RCI), the Information Security Office, the Office of Sponsored Programs, and other University offices, as appropriate.
  • Providing guidance throughout the proposal, award, and research lifecycle.

Federal Regulatory References

Reference Description
Executive Order 13556 – Controlled Unclassified Information Establishes the Federal Controlled Unclassified Information (CUI) Program.
32 CFR Part 2002 – Controlled Unclassified Information Establishes government-wide requirements for the designation, safeguarding, dissemination, marking, decontrol, and disposition of CUI.
National CUI Registry Identifies the official CUI categories and subcategories used by federal agencies.
National Institute of Standards and Technology (NIST) Publishes cybersecurity standards and guidance that may be incorporated into federal sponsor or contractual requirements involving CUI.

Need Assistance?

If your research project involves government information, CUI, or federal sponsor requirements related to safeguarding research information, contact the Office of Research Security before receiving, accessing, storing, processing, or transmitting the information.

ORS will assist in determining applicable requirements, identifying appropriate safeguards, and coordinating with the appropriate University offices to support compliant research.

CONTACT ORS