CUI Clearance Requirements: Purpose, Investigation, and Training

There is no such thing as a CUI clearance in the way Secret or Top Secret clearances exist. The CUI clearance requirements people search for are really an authorization framework: to access Controlled Unclassified Information, you need a lawful government purpose for the work, a background investigation at whatever level your agency or contract sets, and completion of mandatory CUI training. No single credential covers every category, and no clearance card exists to carry in your wallet.

That framework comes from Executive Order 13556 and its implementing regulation, 32 CFR Part 2002, which replaced a patchwork of older labels like “For Official Use Only” with a single government-wide program.1National Archives. About Controlled Unclassified Information2eCFR. 32 CFR Part 2002 – Controlled Unclassified Information (CUI) The National Archives and Records Administration runs the program as executive agent.3eCFR. 32 CFR 2002.6 – CUI Executive Agent (EA) A January 2025 Federal Acquisition Regulation rule extended the same requirements to civilian agency contracts, so the reach now goes well past the Department of Defense.4Federal Register. Federal Acquisition Regulation: Controlled Unclassified Information

The Three Gates for CUI Access

Under 32 CFR 2002.16, an authorized holder can share CUI with someone only if the holder reasonably expects that the recipient has a lawful government purpose and understands how to handle the information.5eCFR. 32 CFR 2002.16 – Accessing and Disseminating That single sentence carries most of the eligibility rule. In practice, three gates control access.

A Lawful Government Purpose

The regulation defines a lawful government purpose broadly: any activity, mission, or operation the U.S. Government authorizes or recognizes as within the scope of its legal authorities. That includes work performed by non-executive-branch entities such as state and local law enforcement.2eCFR. 32 CFR Part 2002 – Controlled Unclassified Information (CUI) Curiosity, career development, or “it would help me do my job better someday” do not qualify. The purpose has to be tied to an authorized mission.

A Background Investigation Set by the Agency

This is where the clearance analogy breaks down most. There is no single, universal background check tied to CUI. The investigation level depends on the agency, the sensitivity of the specific CUI category, the systems you need to touch, and the risk profile of the position. Some roles require a Tier 1 investigation, initiated by filing Standard Form 85 with the Office of Personnel Management.6U.S. Office of Personnel Management. Questionnaire for Non-Sensitive Positions, SF 85 Others set the bar at Tier 2 or higher.

CUI on its own does not automatically trigger any particular investigation. Your sponsoring agency or contracting officer decides which tier applies. Contractors sometimes stall onboarding assuming they need a specific clearance before touching any CUI; that assumption is usually wrong, and the right move is to ask the contracting officer what investigation the position actually requires.

Mandatory CUI Training

Everyone who handles CUI must complete awareness training before gaining access and repeat it on a set cycle. The federal baseline in 32 CFR Part 2002 is at least every two years. The Department of Defense goes further and requires its contractors to complete CUI training annually under DoD Instruction 5200.48.7Defense Counterintelligence and Security Agency. CUI Training Reference Guide for Industry Missing a training deadline can suspend your access until you complete the course, so check the specific policy that governs your role.

Why the Category Matters

CUI is not one uniform bucket. NARA maintains the CUI Registry, an online repository listing every approved category and subcategory along with the law, regulation, or policy that authorizes it.8National Archives. CUI Registry Category List Categories cover export-controlled technical data, privacy information, law enforcement records, tax data, and much else.

Each category falls into one of two handling tiers. CUI Basic follows the uniform protections in 32 CFR Part 2002. CUI Specified has extra handling, dissemination, or disposal rules baked into the underlying statute, and those extra rules are not optional. Federal taxpayer information, for example, is CUI Specified and carries the banner marking “CUI//SP-TAX,” which flags Internal Revenue Code restrictions on top of the CUI baseline.9National Archives. CUI Category: Federal Taxpayer Information Being cleared to see one category does not automatically mean you are authorized for another. Access is category-specific and purpose-specific.

What Access Obligates You to Do

Getting through the three gates is only the start. Access carries handling duties, and violating them counts as a mishandling incident even if no one else ever sees the information.

Marking

Every CUI document requires a banner marking centered at the top and bottom of every page, reading “CUI” or “CONTROLLED” at minimum. For CUI Specified, the banner has to include the category, such as “CUI//SP-TAX.” A designation indicator on the first page or cover identifies the designating agency and office, category, any dissemination controls, and a point of contact. Portion markings are optional for CUI Basic but required for Specified.2eCFR. 32 CFR Part 2002 – Controlled Unclassified Information (CUI) NARA’s CUI Marking Handbook shows correctly marked examples and is worth reading before you mark anything for the first time.10National Archives. CUI Marking Handbook One common error: markings must never appear on the outside of a mailing envelope, which would expose the existence of controlled material to anyone handling the package.

Physical Safeguarding

When CUI is not actively in use, it has to be stored somewhere unauthorized people cannot easily reach: a locked office, a restricted-access area, or a locked container. CUI Specified sometimes requires higher-grade storage such as GSA-approved security containers, depending on what the authorizing law demands. Leaving CUI on your desk in an unlocked office overnight is a violation, even if no one reads it. The standard is protection from reasonable risk, not proof of exploitation.

Digital Safeguarding

Any system used to process, store, or transmit CUI electronically must meet a “no less than moderate” confidentiality impact level under FIPS Publication 199, with security controls drawn from NIST SP 800-53.5eCFR. 32 CFR 2002.16 – Accessing and Disseminating For cryptography, FIPS 140-3 officially superseded FIPS 140-2 in 2019. FIPS 140-2 validations move to the historical list on September 21, 2026; modules already on that list remain acceptable for existing systems, but new procurements should target FIPS 140-3 validated products.11Computer Security Resource Center. FIPS 140-3 Transition Effort

Sharing

Sharing CUI is allowed, and often encouraged, when it serves a lawful government purpose. Before sending it by any means, you must reasonably expect the recipient meets the same authorization and understanding standard that applied to you. Email, text messaging, fax, and voicemail systems used for CUI must meet the moderate-confidentiality requirements above, which usually means encrypted email or a secure file-transfer portal that verifies recipient identity and logs access. Physical shipments through USPS or a commercial carrier should use in-transit tracking, be addressed to a specific named recipient rather than a general office, and carry no external markings indicating the contents are controlled.2eCFR. 32 CFR Part 2002 – Controlled Unclassified Information (CUI)

Extra Requirements for Government Contractors

Contractors and subcontractors carry obligations beyond the baseline. DFARS 252.204-7012 requires implementation of the 110 security controls in NIST SP 800-171 Revision 2, covering access control, audit logging, incident response, and system integrity. Contractors must also report cyber incidents to the DoD Cyber Crimes Center and retain incident data for at least 90 days. Cloud service providers used to store, process, or transmit covered defense information must meet the FedRAMP Moderate baseline or an equivalent, and equivalency requires full implementation of all 323 FedRAMP Moderate controls with zero findings from a recognized assessor.

CMMC Certification

The Cybersecurity Maturity Model Certification program adds a verification layer on top of NIST 800-171 compliance. CMMC Level 2 applies to contractors handling CUI and requires demonstrating compliance with the same 110 controls, either through a self-assessment or through an independent assessment by a certified third-party assessor organization (C3PAO), depending on the contract.12Department of Defense Chief Information Officer. About CMMC

The rollout is phased. Phase 1 began November 10, 2025, and covers Level 1 and Level 2 self-assessments appearing in solicitations. Phase 2 begins November 10, 2026, when solicitations may require Level 2 certification from a C3PAO.12Department of Defense Chief Information Officer. About CMMC Assessments are valid for three years with an annual affirmation. A Plan of Action and Milestones for unmet controls has to be closed within 180 days before conditional status expires. Contractors handling CUI tied to critical programs or high-value assets face CMMC Level 3, which adds enhanced controls from NIST SP 800-172 aimed at advanced persistent threats. Most contractors dealing with routine CUI fall under Level 2.

What Happens If You Get It Wrong

The CUI regulation does not create its own criminal penalties. If the underlying statute for a category includes sanctions, those still apply in full. Federal taxpayer information mishandled in violation of the Internal Revenue Code, for instance, carries penalties entirely independent of the CUI framework.

Beyond statutory sanctions, agency heads can impose administrative consequences on personnel who misuse CUI, including reprimands, suspension of access, demotion, or termination. For contractors, mishandling can trigger contract termination, debarment from future government work, and loss of CMMC certification status. CUI sits below the classified threshold, but the consequences are not minor, especially where the data involves personal privacy, law enforcement operations, or export-controlled technology.