Controlled Unclassified Information (CUI)
Overview
Controlled Unclassified Information (CUI) is government information that requires safeguarding or dissemination controls pursuant to federal law, regulation, or government-wide policy but is not classified under Executive Order 13526 or the Atomic Energy Act.
Federal agencies use the CUI Program to provide a uniform approach for identifying, marking, safeguarding, disseminating, decontrolling, and disposing of sensitive government information.
Researchers may encounter CUI in federally sponsored research, federal contracts and subcontracts, cooperative agreements, or other activities involving information provided by or generated for the U.S. Government.
The Office of Research Security (ORS) assists faculty, staff, and students in determining whether CUI requirements apply to a research project, identifying applicable safeguarding and cybersecurity requirements, and coordinating with the appropriate University offices to assess whether and how the requirements can be supported.
Federal Contract Information (FCI) and CUI are distinct categories of government information. Some projects may involve FCI, CUI, or both. ORS can assist researchers in determining which requirements apply based on the sponsor, award type, and applicable terms and conditions.
What Is Controlled Unclassified Information?
Controlled Unclassified Information is information that the Federal Government has determined requires safeguarding or dissemination controls but does not meet the standards for classification.
Unlike classified information, CUI generally does not require a security clearance for access. However, access may be limited to authorized individuals, and the information must be protected and handled in accordance with applicable federal laws, regulations, agency requirements, and award or contractual terms.
The Federal Government determines what information qualifies as CUI. Researchers should not independently designate research information as CUI unless directed or authorized to do so under applicable federal requirements.
How Is CUI Identified?
CUI requirements or information may be identified through:
- Sponsor award terms and conditions
- Contract or subcontract requirements
- Information markings or banners
- Agency instructions
- Government-furnished information
- Contract deliverables
- Prime contractor communications
- Other sponsor documentation
The presence of sensitive, proprietary, or nonpublic information does not by itself mean that the information is CUI.
If researchers are notified that a project may involve CUI, encounter an award or contractual requirement referencing CUI, or are asked to receive CUI, they should contact ORS before receiving, accessing, storing, processing, or transmitting the information.
Examples of CUI
Federal CUI categories and subcategories cover many types of government information. Depending on the sponsoring agency and activity, examples may include:
- Controlled technical information
- Certain export-controlled information
- Critical infrastructure information
- Certain proprietary or procurement information
- Certain engineering and design information
- Certain privacy-protected information
- Other information identified within the National CUI Registry
Not all sensitive, proprietary, export-controlled, or nonpublic research information is CUI. Whether information is CUI depends on its federal designation and the applicable authority.
When Might Researchers Encounter CUI?
Researchers may encounter CUI when:
- Performing research under certain federal contracts or subcontracts.
- Receiving information directly from a federal agency.
- Working on projects involving government-controlled information.
- Collaborating with federal laboratories or government agencies.
- Receiving CUI from a prime contractor or subcontractor.
- Participating in projects where award terms require safeguarding of government information.
Most fundamental research conducted at Stony Brook University does not involve CUI. However, investigators should review sponsor requirements and award terms and conditions because CUI requirements are project-specific.
Typical Safeguarding Considerations
Projects involving CUI may be subject to requirements including:
- Access limited to authorized personnel.
- Specific cybersecurity and information protection safeguards.
- Secure storage, processing, and transmission requirements.
- Controlled sharing and dissemination.
- Physical security and access controls.
- Restrictions on devices, systems, networks, or removable media.
- Incident reporting requirements.
- Applicable federal cybersecurity standards.
- Sponsor-, award-, or contract-specific safeguarding requirements.
The specific safeguards required depend on the sponsoring agency, award or contract requirements, type of CUI involved, and applicable federal requirements.
Researchers should not receive, access, store, process, or transmit CUI using University systems, devices, networks, or other computing resources unless the applicable requirements have been reviewed and ORS has confirmed that the proposed activity can be supported.
Contact ORS as early as possible if a proposed or existing research activity may involve CUI.
CUI Research Computing at Stony Brook University
Stony Brook University does not currently maintain a general-purpose research computing environment for receiving, storing, processing, or transmitting CUI.
Researchers considering a project that may involve CUI should contact ORS as early as possible and before making commitments regarding the University's ability to receive or safeguard CUI. ORS will review the applicable sponsor, contractual, cybersecurity, and information protection requirements and coordinate with the appropriate University offices to assess whether and how the proposed activity can be supported.
Depending on the project, this assessment may include consideration of sponsor-, Government-, or externally provided environments or other arrangements permitted by the applicable requirements.
Related Requirements
Research involving CUI may also involve:
- Federal Contract Information (FCI)
- Export-Controlled Information
- Federal contract cybersecurity requirements
- Sponsor-specific cybersecurity requirements
- Research information protection requirements
- Data Protection Plans
- Technology Control Plans, when applicable
The presence of CUI does not necessarily mean that all of these requirements apply. ORS assists researchers in identifying the requirements applicable to the specific project.
How ORS Can Help
ORS assists researchers by:
- Determining whether a proposed or existing research activity involves CUI or CUI-related requirements.
- Reviewing sponsor, solicitation, award, contract, and subcontract requirements.
- Identifying applicable CUI safeguarding, cybersecurity, research information protection, and export control requirements.
- Assessing applicable requirements against current University capabilities in coordination with the appropriate University offices.
- Identifying whether a Data Protection Plan, Technology Control Plan, System Security Plan, or other project-specific documentation may be required.
- Evaluating whether sponsor-, Government-, or externally provided environments or other permissible arrangements may support the proposed activity.
- Coordinating with Research Computing & Informatics (RCI), DoIT, the Office of Sponsored Programs, and other appropriate University offices.
- Providing guidance throughout the proposal, award, and research lifecycle.
Federal Regulatory References
| Reference | Description |
|---|---|
| Executive Order 13556 – Controlled Unclassified Information | Establishes the Federal Controlled Unclassified Information (CUI) Program. |
| 32 CFR Part 2002 – Controlled Unclassified Information | Establishes government-wide requirements for the designation, safeguarding, dissemination, marking, decontrol, and disposition of CUI. |
| National CUI Registry | Identifies the official CUI categories and subcategories used by federal agencies. |
| National Institute of Standards and Technology (NIST) | Publishes cybersecurity standards and guidance that may be incorporated into federal sponsor or contractual requirements involving CUI. |
Frequently Asked Questions
Does Stony Brook University currently have a CUI research computing environment?
Stony Brook University does not currently maintain a general-purpose research computing environment for receiving, storing, processing, or transmitting CUI. Researchers considering activities that may involve CUI should contact ORS as early as possible so that applicable requirements and current University capabilities can be evaluated before commitments are made.
Can I receive or store CUI on my University computer, research storage, or other University system?
Researchers should not receive, access, store, process, or transmit CUI using University devices, systems, networks, storage, or other computing resources unless the applicable requirements have been reviewed and ORS has confirmed that the proposed activity can be supported.
Need Assistance?
If your research project may involve CUI or federal sponsor requirements related to safeguarding government information, contact the Office of Research Security as early as possible and before making commitments regarding the University's ability to receive or safeguard CUI.
ORS will assist in identifying applicable requirements and coordinate with the appropriate University offices to assess current University capabilities and determine whether and how the proposed activity can be supported.