# Controlled Unclassified Information (implementing rule)
Short Answer
32 C.F.R. Part 2002 is the government-wide rule for the Controlled Unclassified Information Program. It matters to contractors because agency CUI markings, contract clauses, data-handling instructions, flowdowns, and safeguarding requirements depend on the rule’s definitions and program structure.
Why this matters for government contractors
CUI is not a contractor-created marketing category and it is not classified information. Under the CUI rule, CUI is unclassified information that the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, when a law, regulation, or government-wide policy requires or permits safeguarding or dissemination controls. That definition is the starting point for deciding whether NIST SP 800-171, DFARS 252.204-7012, CMMC, agency CUI clauses, or other handling rules may be triggered.
For contractors, the rule matters because the government-wide CUI Program is supposed to standardize categories, markings, dissemination controls, decontrol, and destruction. In practice, contractors need to read the contract, attachments, security classification guides, CUI markings, data inventories, and agency instructions together.
What the regulation does
Part 2002 tells agencies how to designate, mark, safeguard, disseminate, decontrol, and destroy CUI. It also establishes the CUI Registry structure and the concept that CUI categories and subcategories are the exclusive designations for unclassified information requiring safeguarding or dissemination controls. The rule directly governs executive agencies, but contractors are affected when they are authorized holders or when contract terms require handling CUI for the government.
How it reaches contractors
The rule reaches contractors indirectly through contracts, markings, agency instructions, flowdowns, and data itself. A contractor may receive CUI from the government, generate CUI in performance, or possess CUI on behalf of the government. The obligation to protect it usually comes through a contract clause, agency supplement, program instruction, or other binding authority that identifies the data and requires safeguards.
Procurement and cybersecurity significance
CUI identification is often the first step in deciding which cybersecurity obligations apply. Contractors should not wait until a CMMC assessment to determine whether they have CUI. They should ask during proposal and contract intake: what information will we receive or generate, who has authority to mark it, what CUI category applies, what systems will hold it, and what flowdown is required?
Relationship to other GovConCyber requirements
Part 2002 connects to Executive Order 13556, NIST SP 800-171, DFARS 252.204-7012, CMMC, the proposed FAR CUI rule, agency-specific CUI clauses, Privacy Act data, export-controlled information, SSI, tax information, statistical information, and classified-information boundaries. It should not be treated as a stand-alone contractor control set; it is the program rule that supports data identification and handling.
What contractors should do
- Inventory CUI received, generated, stored, processed, or transmitted under federal work.
- Record CUI categories, markings, source agency, contract references, and system locations.
- Confirm whether NIST SP 800-171, DFARS, CMMC, agency clauses, export controls, SSI, Privacy Act, or other rules apply.
- Train staff to recognize CUI markings and authorized sharing limits.
- Maintain decontrol, destruction, and incident-escalation procedures.
- Flow CUI handling requirements to subcontractors that receive or generate CUI.
Current status
Current government-wide regulation. It directly governs agencies, but contractor obligations generally arise through contract, marking, data-handling instruction, or other binding incorporation.
Primary citations
- 32 C.F.R. Part 2002.
- 32 C.F.R. §§ 2002.1, 2002.4, 2002.10, 2002.12.
- Exec. Order No. 13556, 75 Fed. Reg. 68675 (Nov. 9, 2010).
---
Source type: federal_regulation. Implementation status: in_force.