GSA Ready Now
Federal contractor reviewing contract documents to determine CUI handling requirements
Back to Blog
Compliance Jul 27, 2026 9 min read

Do You Actually Handle CUI? Most Contractors Guess, and Most Guess Wrong

Focus keyword: do I handle CUI

The single most expensive mistake in federal contract security is answering "do we handle CUI" from memory instead of from evidence. Contractors who guess low buy nothing and discover the gap during an incident or a flow-down demand. Contractors who guess high spend real money hardening systems that never touch a government data set.

The question is answerable. It just requires looking at four specific things rather than relying on what someone said at a conference.

What Actually Counts as CUI, and Who Gets to Decide?

Controlled Unclassified Information is a government-wide program created by Executive Order 13556 in 2010 and implemented for federal agencies by NARA in 32 CFR Part 2002. It covers information that is not classified but that law, regulation, or government-wide policy says must be protected or restricted. The categories are published in the NARA CUI Registry, which is the authoritative list. If a category is not in the Registry, it is not CUI.

Two things follow from that, and both are routinely missed.

  • You do not decide what is CUI. The government does. A designating agency determines that information falls into a Registry category and is responsible for marking it. Your role is to protect what you receive or create on the government's behalf, not to invent designations.
  • The Registry is broader than most contractors assume. It is not a defense list. It includes categories such as Procurement and Acquisition, Privacy, Financial, Law Enforcement, Critical Infrastructure, and Export Control. A civilian services contractor with no defense work at all can absolutely be inside one of those categories.

Why Do So Many Contractors Get This Wrong?

Five patterns account for nearly all of it.

  • They confuse FCI with CUI. Federal Contract Information is a different, broader, and currently enforceable thing. FAR 52.204-21 already sits in a very large share of federal contracts and requires fifteen basic safeguarding controls for FCI. Many contractors who say "we handle CUI" actually handle FCI, and many who say "we handle nothing" have had 52.204-21 in their contracts for years.
  • They assume unmarked means not CUI. Agencies are supposed to mark CUI. In practice, marking is inconsistent. Receiving an unmarked file does not automatically strip the information of its protected status, and the practical answer is to ask the contracting officer in writing rather than to assume.
  • They forget about information they create. CUI is generally understood to include information an entity creates or possesses for or on behalf of the government, not only information the government hands over. Deliverables, analyses, and system outputs can carry the designation.
  • They think their role insulates them. Resellers, staffing firms, and consultants often assume that being a pass-through means the question does not reach them. It frequently does, through prime flow-downs and through the simple fact that consultants touch proposal, pricing, and personnel data.
  • They assume CMMC settles the question. It does not, and that is addressed in the next section.

Does CMMC Answer This If I Sell to Civilian Agencies?

No. CMMC is a Department of Defense program applied through DoD contracts. It is not a civilian agency requirement, and there is no equivalent civilian certification. Nobody can certify you as CUI compliant for GSA, DHS, HHS, or VA work, because there is nothing to certify against in that form.

What civilian agencies do use is agency-specific acquisition regulation clauses. Several civilian agencies have added their own CUI safeguarding and incident reporting clauses to their supplements over the last several years, and those are contractual obligations today where they appear. This is the layer contractors most often miss, because they are watching the FAR and the defense press instead of reading their own award documents.

How Do You Actually Work It Out?

Do these four things in order. This is a reading exercise before it is a technical one.

  1. 1

    Read your clause list

    Pull every active contract, task order, and BPA. Look for FAR 52.204-21 first, then for any agency supplement clause referencing controlled unclassified information, safeguarding, or incident reporting. Look at your prime subcontract agreements separately, because flow-downs often add obligations the prime negotiated upstream.

  2. 2

    Read your statements of work

    Look for language about the data you will receive, the systems you will access, and what you will produce. Access to an agency system, handling of personally identifiable information about federal employees or the public, and production of procurement sensitive analysis are all signals worth chasing.

  3. 3

    Map where the data actually lives

    Email, shared drives, a CRM, a laptop in someone's home office, a subcontractor's environment. Most contractors discover during this step that the data set is smaller than they feared and in more places than they expected.

  4. 4

    Ask the contracting officer, in writing

    If steps one through three leave you uncertain, that is not a failure. Send a written question asking whether the agency considers any information under the contract to be CUI, which Registry categories apply, and how it will be marked. Keep the answer. It is the cleanest evidence you will ever have on this question.

What Does the Proposed FAR CUI Rule Change About This?

The FAR Council published a proposed rule on June 23, 2026 that would rewrite the government-wide approach to CUI safeguarding and incident reporting. It is a proposal. It is not in force, it is not a requirement you can violate today, and its final content is genuinely unsettled.

What matters for the "do I handle CUI" question is the direction of travel. The proposed framework contemplates the government telling contractors, at solicitation and award, whether CUI is involved and what categories apply, rather than leaving contractors to infer it. If something along those lines is finalized, the identification problem gets meaningfully easier for everyone.

If you want to comment on how identification and marking should work in practice, check the docket on regulations.gov for the exact closing date. Contractor comments on the practical burden of unmarked data have historically been among the more useful ones on record.

What Should You Do While It Is Still a Proposal?

Nothing dramatic, and nothing certification shaped.

Finish the four-step assessment above and write down the answer with the evidence behind it. If FAR 52.204-21 is in your contracts, satisfy those fifteen requirements, because that obligation exists now. If an agency supplement clause applies to you, comply with the clause you actually signed. If CUI is present, NIST SP 800-171 is the standard the government has consistently pointed to for protecting CUI on nonfederal systems, and working toward it is a defensible position regardless of how the FAR rule lands.

If you find no CUI, document that conclusion and set a date to revisit it. The answer changes when your contracts change.

Frequently Asked Questions

What is the difference between FCI and CUI?

Federal Contract Information is information provided by or generated for the government under a contract that is not intended for public release. Controlled Unclassified Information is information that law, regulation, or government-wide policy requires to be safeguarded, and its categories are listed in the NARA CUI Registry. FCI protection is already required by FAR 52.204-21 in a large share of federal contracts. CUI is narrower in definition but carries heavier expectations where it applies.

If information is not marked as CUI, am I off the hook?

Not necessarily. Agencies are responsible for identifying and marking CUI, but marking practice is inconsistent, and information does not lose its protected character because someone forgot a banner. The safe approach is to ask the contracting officer in writing whether the information is CUI and to keep the response on file.

Does CMMC apply to my GSA Schedule contract?

CMMC is a Department of Defense program applied through DoD contracts. It does not apply to civilian agency work by virtue of holding a GSA Schedule. If you sell to both DoD and civilian customers, you may face CMMC on the defense side and different, agency-specific obligations on the civilian side.

Is the FAR CUI rule in effect?

No. The FAR Council published a proposed rule on June 23, 2026 and it remains a proposal. It is not enforceable, and its final requirements, effective dates, and clause language are not settled. Plan for the direction, but do not represent it as a current obligation.

Can I get certified as CUI compliant for civilian agency work?

No. There is no civilian equivalent of CMMC and no certification body that can issue a government-recognized CUI certification for civilian contracts. What exists is contractual compliance with the clauses in your award, plus documented alignment with the standards the government references, which for CUI on nonfederal systems is NIST SP 800-171.

Do my subcontractors and consultants need to worry about this?

Yes, if they touch the information. Obligations flow down through subcontract agreements, and consultants who handle proposal, pricing, or personnel data are often inside the same data flow as the prime. Include them in your data mapping rather than assuming the question stops at your own network boundary.

Want a second set of eyes on your clause list before you spend a dollar on controls? We will walk your contracts with you and tell you exactly where you stand.

Talk to a Compliance Specialist

Find Out If You're Ready for a GSA Contract

Take the free 19-question GSA readiness assessment and get a personalized score with a clear action plan — in minutes.

Start Free Assessment