GSA Ready Now
Decision flow chart showing the steps to determine whether information is CUI: contract clauses, document markings, CUI Registry check, contracting officer, ending in CUI, FCI only, or neither
Back to Blog
Compliance Oct 5, 2026 8 min read

Do You Actually Handle CUI? Why Contractors Often Guess Wrong

Focus keyword: do I handle CUI

You can't tell whether you handle Controlled Unclassified Information (CUI) by how sensitive the information feels. You find out by reading your contract, checking the markings on what the agency gives you and comparing the information against the official CUI Registry. Contractors who skip those steps tend to make one of two mistakes. Some treat everything as CUI and overspend on controls. Others treat nothing as CUI and end up exposed.

This matters more this week. An explainer on how the FAR CUI rule affects federal contractors was published and is worth reading. Keep its status in mind, though: the FAR CUI rule is a proposed rule. It isn't yet a requirement in your contracts. Your obligations today come from the CUI program regulation that governs agencies, plus whatever clauses are actually in your contract.

What Actually Counts as CUI?

CUI is a defined term, not a general description. Executive Order 13556 created the CUI program, and the National Archives (NARA) implements it at 32 CFR Part 2002. Under that regulation, CUI is information the government creates or possesses, or that someone creates or possesses for or on behalf of the government, that a law, regulation or government-wide policy requires or permits to be handled with safeguarding or dissemination controls.

The key point is that information is only CUI if it falls into a category listed in NARA's CUI Registry. Being confidential, embarrassing or commercially valuable isn't enough. If you can't match the information to a Registry category, it is not CUI, whatever your instinct says.

Is Federal Contract Information the Same Thing as CUI?

No. Mixing the two up is one of the most common reasons contractors guess wrong.

Federal Contract Information (FCI) is defined in FAR 52.204-21. It covers information that isn't intended for public release and that is provided by or generated for the government under a contract to develop or deliver a product or service. It excludes information the government has made public and simple transactional information, such as what is needed to process payments. Where that clause is in your contract, it requires 15 basic safeguarding requirements on the information systems that hold FCI, and it is in force today.

Many contractors who perform services for an agency handle FCI. Far fewer handle CUI. Holding FCI doesn't mean you hold CUI, and being able to protect FCI doesn't mean you would meet the much larger set of controls in NIST SP 800-171.

Why Do So Many Contractors Get the Answer Wrong?

The mistakes follow a few predictable patterns:

  • "It's sensitive, so it must be CUI." Your own pricing, trade secrets and internal plans are yours. Keeping them confidential doesn't make them CUI on your own systems. The CUI framework is about government information and information handled for the government.
  • "Nothing is marked, so nothing is CUI." Agencies are responsible for marking CUI, but marking is imperfect. You may still see older labels such as "For Official Use Only" or "Sensitive But Unclassified," and some documents arrive unmarked. A missing banner tells you the agency didn't mark the document. It doesn't settle whether the content is CUI.
  • "The system I logged into says CUI, so I handle CUI." SAM.gov, for example, shows a banner saying the system contains CUI. Logging into a system that holds CUI somewhere doesn't mean the solicitation you downloaded is CUI. Look at the markings on the specific document. Some solicitation attachments are access-restricted and marked accordingly, and those deserve attention.
  • "We do defense work, so the same rules apply." DFARS 252.204-7012 and the Cybersecurity Maturity Model Certification (CMMC) program are Department of War requirements for defense contracts. They don't carry over to your civilian agency contracts. The reverse is also true: your civilian obligations don't come from CMMC.

How Do I Work Out Whether My Contract Involves CUI?

Work through these steps in order and write down what you find at each one.

  1. 1

    Read the contract and every task order.

    Look for clauses on safeguarding, CUI or sensitive information. Some civilian agencies, such as the Department of Homeland Security, have clauses in their own FAR supplements on safeguarding sensitive information. Read your agency's clauses, not just the base FAR.

  2. 2

    List what information comes in and what goes out.

    Note what the agency gives you and what you create for the agency under the contract. CUI can arise in both directions.

  3. 3

    Check the markings.

    Look for "CUI" or "CONTROLLED" banners, category markings and older labels. Note anything that looks sensitive but has no marking.

  4. 4

    Compare against the CUI Registry.

    For each type of information, ask whether it fits a Registry category. If it fits none, it isn't CUI.

  5. 5

    Ask the contracting officer in writing.

    If you're unsure after the first four steps, ask. The contracting officer, not your program contact, is the person who can state the government's position. Keep the written answer.

  6. 6

    Repeat when the work changes.

    A new task order, a new data feed or a new agency customer can change the answer.

The CUI regulation tells agencies to set out CUI handling requirements in their agreements with non-federal entities where feasible. That is why the contract is your first stop, and why a clear written answer from the contracting officer is worth having.

What Would the Proposed FAR CUI Rule Change?

The FAR Council first published this proposed rule on January 15, 2025 (FAR Case 2017-016), then released an updated version of it on June 23, 2026 as part of the broader "Revolutionary FAR Overhaul," which superseded the 2025 text. Comments on the updated version closed July 23, 2026. Its biggest practical change goes straight at the guessing problem: the agency would identify the CUI involved in a contract on a new standard form. The proposal also covers what a contractor should do when it comes across information that looks like CUI but wasn't identified as such. And it would apply NIST SP 800-171 as the safeguarding standard for CUI on contractor systems.

None of this binds you yet. It is a proposal, and the final text could differ from what was published for comment. As proposed, it doesn't create a civilian certification program like CMMC, and civilian contractors shouldn't expect one. At the time of writing it remains a proposed rule, with the FAR Council saying it intends to finalize the broader FAR Overhaul rules, including this one, before the end of 2026. Check the Federal Register before relying on any final version.

What Should I Do While the Rule Is Still Proposed?

Get to an accurate answer for each contract you hold today. If you find you don't handle CUI, record why, so you can show your reasoning later. If you find you do, read the requirements in your actual contract and compare your current practices to NIST SP 800-171 so you know where the gaps are. Either way, you'll be in a better position when the FAR rule is finalized than a contractor who is still guessing.

Frequently Asked Questions

How do I know if my federal contract involves CUI?

Check four things: the clauses in your contract and task orders, the markings on information the agency gives you, whether that information fits a category in NARA's CUI Registry, and a written answer from your contracting officer if any doubt remains. The sensitivity of the information doesn't decide the question. Only a CUI Registry category does.

What is the difference between FCI and CUI?

Federal Contract Information is non-public information provided by or generated for the government under a contract, and FAR 52.204-21 sets 15 basic safeguarding requirements for it where the clause applies. CUI is a narrower set of information that falls into a category in NARA's CUI Registry. Handling FCI doesn't by itself mean you handle CUI.

Is the FAR CUI rule in effect?

No. The FAR CUI rule (FAR Case 2017-016) was first proposed on January 15, 2025, updated and reissued on June 23, 2026 as part of the Revolutionary FAR Overhaul, with the comment period closing July 23, 2026. At the time of writing it remains proposed, not final. Civilian contractors' current CUI obligations come from the clauses actually in their contracts.

Does CMMC apply to civilian agency contracts?

No. CMMC is a Department of War program for defense contracts, and DFARS 252.204-7012 is a defense clause. Civilian agency obligations come from the FAR, agency FAR supplements and contract terms. As proposed, the FAR CUI rule doesn't create a civilian certification.

If a document isn't marked CUI, can I assume it isn't CUI?

Not safely. Agencies are responsible for marking CUI, but some documents arrive unmarked or carry older labels such as "For Official Use Only." If something looks like it may fit a CUI Registry category, ask your contracting officer in writing.

Is my company's own proprietary data CUI?

Generally, no. Your own pricing, trade secrets and internal information don't become CUI on your systems just because they are confidential. The CUI framework covers information the government creates or possesses, or that is created or possessed for or on behalf of the government.

If you'd like a second set of eyes on whether your contracts involve CUI, contact GSA Ready Now to talk it through.

Talk to a Compliance Specialist

Find Out If You're Ready for a GSA Contract

Take the free 19-question GSA readiness assessment and get a personalized score with a clear action plan — in minutes.

Start Free Assessment