Separate it, then treat the CUI part as CUI.
Mixed containers pull everything around them into scope. The cheapest fix is almost always separation, not expanding your boundary to cover the whole company.
What to do
- Identify the specific CUI elements inside the file, folder, or mailbox.
- Move them into a defined enclave with its own access control.
- Clean the original location and confirm no copies remain in backups or shared drives.
- Record the separation decision. An assessor will ask how you scoped it.
- Apply all 110 requirements to the enclave only.
Scoping guidance in the CMMC rule at 32 CFR 170.19; NIST SP 800-171 Rev. 2 §3.1.3 on controlling CUI flow.
Which category?
The contracting officer confirms the category; the registry is the vocabulary they will use. A defense contractor most often holds one of these:
Every category, with NARA's definition and authorities, is in the registry. How the banner is built is in 32 CFR 2002.20.
Foxx Cyber, who publish this guide, build Bedrock CMMC, which does the boundary, system security plan, scoring and POA&M work this outcome describes.
Requirements this outcome points you to
Not the outcome you expected?
Run the worksheet again for one specific set of information, or read the other outcomes.
Whether information is CUI is the government's decision. This page sorts your situation; it does not designate anything. See FCI, CUI and CDI.