The CUI Registry, read from the defense side
The National Archives keeps the authoritative list of what counts as CUI: 20 organizational index groupings holding 128 categories, each with a marking and the law or regulation behind it. Most of it will never touch a defense contractor. This page says which parts will, then lists all of it.
Read this first
The registry tells you what CUI can be. It does not tell you what you hold. The designating agency decides that and marks it; your contract tells you which categories to expect. If you are unsure whether something in front of you is CUI at all, start with the worksheet. If you know it is CUI and want to know which kind, the categories below are the vocabulary the contracting officer will use.
What a defense contractor actually meets
Ten of the twenty groupings turn up in defense work, in roughly this order of likelihood. The notes are ours; the category names, markings and definitions on the linked pages are NARA's.
- Defense5 categories CTIDCRITNNPIPSIDCNI The categories DFARS 252.204-7012 is built around. If you hold drawings, specifications, test data, source code or manuals for a defense article, the first category here, Controlled Technical Information, is almost certainly what you have.
- Export Control2 categories EXPTEXPTR ITAR and EAR data. It is CUI when it comes to you under a federal contract, and it carries its own access rules on top: who may see it is decided by citizenship and licence, not only by need-to-know.
- Procurement and Acquisition3 categories PROCURESBIZSSEL Source selection and proposal information. Common in the run-up to an award and easy to overlook because it looks like ordinary business paperwork.
- Proprietary Business Information6 categories CONREGPROPINOCCMTOSERVMFCPOST Your own and other vendors' proprietary data once the government holds it. A prime's cost data flowing down to a subcontractor lands here.
- Privacy9 categories CONTRACTDRECPRVCYGENETICHLTHPRIIGMILPERSSTUD Personnel and health records the government shares with you, including the records of your own cleared staff in some programs.
- North Atlantic Treaty Organization (NATO)2 categories NATO Restricted and NATO Unclassified appear on multinational programs and carry their own handling rules alongside the CUI marking.
- International Agreements1 category INTL Information exchanged under an agreement with a foreign government. Foreign military sales and cooperative programs are the usual route.
- Critical Infrastructure11 categories CRITANCVICEIIEMGTCRITISVIPHYSPCIISAFETSCAWATER Facility and system vulnerability information. Defense installations and their contractors receive it for site and utility work.
- Nuclear5 categories NUCRECCOMSRISGIUCNI Rare outside the nuclear enterprise, but naval nuclear propulsion sits in the Defense grouping and the general nuclear categories can appear on the same programs.
- Intelligence8 categories AGFISAFISABINTELGEOIFNCIDOPSEC Seldom in the industrial base outside cleared programs; listed so the markings are recognisable when they appear.
CUI Basic and CUI Specified
Every category is one or the other, and a few are both depending on which authority applies. The difference matters because Specified categories carry handling rules from their own law or regulation on top of the baseline. NARA's definitions, verbatim from 32 CFR 2002.4:
32 CFR 2002.4 · Definitions(j) CUI Basic is the subset of CUI for which the authorizing law, regulation, or Government-wide policy does not set out specific handling or dissemination controls. Agencies handle CUI Basic according to the uniform set of controls set forth in this part and the CUI Registry. CUI Basic differs from CUI Specified (see definition for CUI Specified in this section), and CUI Basic controls apply whenever CUI Specified ones do not cover the involved CUI.
(r) CUI Specified is the subset of CUI in which the authorizing law, regulation, or Government-wide policy contains specific handling controls that it requires or permits agencies to use that differ from those for CUI Basic. The CUI Registry indicates which laws, regulations, and Government-wide policies include such specific requirements. CUI Specified controls may be more stringent than, or may simply differ from, those required by CUI Basic; the distinction is that the underlying authority spells out specific controls for CUI Specified information and does not for CUI Basic information. CUI Basic controls apply to those aspects of CUI Specified where the authorizing laws, regulations, and Government-wide policies do not provide specific guidance.
(h) Controlled Unclassified Information (CUI) is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. However, CUI does not include classified information (see paragraph (e) of this section) or information a non-executive branch entity possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency. Law, regulation, or Government-wide policy may require or permit safeguarding or dissemination controls in three ways: Requiring or permitting agencies to control or protect the information but providing no specific controls, which makes the information CUI Basic; requiring or permitting agencies to control or protect the information and providing specific controls for doing so, which makes the information CUI Specified; or requiring or permitting agencies to control the information and specifying only some of those controls, which makes the information CUI Specified, but with CUI Basic controls where the authority does not specify.
(t) Designating CUI occurs when an authorized holder, consistent with this part and the CUI Registry, determines that a specific item of information falls into a CUI category or subcategory. The authorized holder who designates the CUI must make recipients aware of the information's CUI status in accordance with this part.
For a contractor the practical reading is this: a Basic category is protected by the CUI baseline, which for DoD contracts means NIST SP 800-171 through DFARS 252.204-7012. A Specified category is protected by that and whatever its authority says, which is why Controlled Technical Information and Export Controlled data carry additional dissemination rules. How the markings work.
All 20 organizational index groupings
Sources
Category names, markings, descriptions and authorities were read from NARA's CUI Registry on 2026-09-08 by a script that visits every category page; nothing was typed in. Definitions and handling rules are from 32 CFR Part 2002 as published on eCFR for 2026-08-29. The "defense side" notes are Foxx Cyber's editorial reading. Where this page and the registry disagree, the registry is right.