Controlled Unclassified Information (CUI) is information the U.S. federal government creates or holds that is not classified under Executive Order 13526 or the Atomic Energy Act, but still requires safeguarding or dissemination controls under law, regulation, or government-wide policy. If you are a defense contractor and you touch CUI, you inherit a specific set of protection duties, mostly through NIST SP 800-171 and CMMC.
What counts as CUI?
CUI is a category, not a single type of data. The National Archives (NARA) maintains the CUI Registry, which sorts it into groupings such as Controlled Technical Information, export-controlled data tied to ITAR and the EAR, critical infrastructure information, privacy data, and law enforcement records. In a defense manufacturing context the common form is Controlled Technical Information: drawings, specifications, G-code, and process sheets that describe how a part is made.
The label matters because it defines your assessment boundary. Every system that stores, processes, or transmits CUI falls inside scope, and in OT environments that often means machines nobody thinks of as computers.
Who must protect CUI?
Any non-federal organization that handles CUI on behalf of the government, which in practice means the defense industrial base: primes, subcontractors, and suppliers down the flowdown chain. The requirement rides in on contract clauses, chiefly DFARS 252.204-7012, and it is enforced through CMMC. You do not get to opt out because you are small; a two-person shop machining a controlled part carries the same safeguarding duty as the prime that awarded the work.
Which frameworks govern CUI?
- NIST SP 800-171 is the core. Its 110 controls across 14 families (access control, incident response, system and information integrity, and the rest) define what "safeguarding CUI" concretely means for a non-federal system.
- CMMC is the verification layer on top. It takes the NIST SP 800-171 controls and requires third-party assessment at Level 2 so the DoD can trust that contractors actually implemented them rather than just claiming to.
- NIST SP 800-172 adds enhanced controls for CUI facing advanced persistent threats, relevant at higher assurance levels.
The NIS2 Directive in Europe does not use the term CUI, but its emphasis on protecting sensitive data in critical sectors solves a parallel problem for EU operators.
Why does CUI matter for OT and industrial environments?
Because the CUI on a defense manufacturer's floor usually lives on OT, not just in the ERP. A controlled drawing becomes a program that runs on a CNC controller. A test procedure runs on embedded test equipment. Those machines are old, cannot run security agents, and were never designed to protect anything. An attacker who reaches them can steal the intellectual property that defines a weapons system component, or quietly alter a process and ship out defective parts.
Scoping CUI in OT is genuinely hard. The clean answer is a CUI enclave: carve the systems that touch CUI into a segmented, access-controlled boundary so you protect the machines that matter instead of trying to harden the entire plant.
How is CUI different from classified information?
Classified information (Confidential, Secret, Top Secret) is protected under Executive Order 13526, carries clearance requirements, and lives on accredited systems. CUI is unclassified. It has no clearance regime and can sit on ordinary commercial systems, which is exactly why it is more exposed: far more people and far more machines touch CUI, and the controls around it depend entirely on the contractor implementing NIST SP 800-171 correctly.
How Access Gate helps
Access Gate builds the CUI enclave in software. It draws an identity-enforced overlay around the exact systems that handle CUI, including the OT assets that cannot protect themselves, so only authenticated, authorized users and services reach them, and it forwards the access evidence a CMMC assessor asks for. See our defense and government solutions.

