Treat this as CUI.
This has the marks of covered defense information. Your obligation is to protect it under all 110 requirements of NIST SP 800-171 Rev. 2 and to report cyber incidents affecting it to DoD within 72 hours.
What to do
- Confirm DFARS 252.204-7012 is in your contract and note the clause reference.
- Write down where this information lives: every system, share, laptop, and cloud service. That list is your CUI boundary.
- Ask the contracting officer in writing to confirm the CUI category and required markings, and file the reply.
- Mark it, restrict access to it, and encrypt it at rest and in transit with FIPS-validated cryptography.
- Assess yourself against all 110 requirements and post the score to SPRS.
DFARS 252.204-7012 §(b)(2) and §(c); NIST SP 800-171 Rev. 2; 32 CFR 170 for the CMMC level.
Which category?
The contracting officer confirms the category; the registry is the vocabulary they will use. A defense contractor most often holds one of these:
- Controlled Technical Information
- Export Controlled
- Source Selection
- General Proprietary Business Information
- General Privacy
Every category, with NARA's definition and authorities, is in the registry. How the banner is built is in 32 CFR 2002.20.
Foxx Cyber, who publish this guide, build Bedrock CMMC, which does the boundary, system security plan, scoring and POA&M work this outcome describes.
Requirements this outcome points you to
Not the outcome you expected?
Run the worksheet again for one specific set of information, or read the other outcomes.
Whether information is CUI is the government's decision. This page sorts your situation; it does not designate anything. See FCI, CUI and CDI.