To obtain access to CUI, you must have four things in place: a lawful government purpose for needing the information, completed CUI awareness training, a favorable and current background investigation at the tier your position requires, and, if you work outside the federal executive branch, a written agreement between your organization and the sharing agency that spells out CUI handling obligations. Contractors who will store or process CUI on their own information systems carry an additional layer of cybersecurity requirements on top of those four. Miss any one condition and the access request stalls.
Controlled Unclassified Information is government information that needs protection but does not meet the standard for classified national security information. Executive Order 13556 built a single framework so every executive branch agency handles this sensitive-but-unclassified material the same way, and the National Archives and Records Administration runs the program and publishes the CUI Registry of approved categories.1National Archives. About Controlled Unclassified Information (CUI) The four access conditions below apply across that framework.
A Lawful Government Purpose
The gateway condition is a lawful government purpose. Under 32 CFR 2002.16, agencies may share CUI only when doing so furthers an activity, mission, or operation that the federal government authorizes or recognizes as within the scope of its legal authorities, including those of non-executive branch entities like state and local law enforcement.2eCFR. 32 CFR 2002.16 – Accessing and Disseminating In practical terms, you have to need the information for a specific contract, grant, regulatory function, or other authorized task.
Holding a security clearance or a senior title does not by itself satisfy this standard. Agencies evaluate each request against the particular project or mission you are supporting, and if the data does not directly relate to your authorized work, expect a denial. That is the mechanism keeping CUI confined to people who genuinely need it for official business rather than curiosity.
Completed CUI Awareness Training
Every person who will handle CUI must first complete awareness training covering how to recognize, mark, safeguard, and eventually destroy or decontrol the information. The CUI Executive Agent at NARA develops training modules for a broad government audience, and your agency or contracting organization then delivers the training through its own system.
Department of Defense personnel take IF141.16, “DOD Mandatory Controlled Unclassified Information (CUI) Training,” offered through the Defense Counterintelligence and Security Agency’s Center for Development of Security Excellence. The course works through eleven training requirements ranging from access and marking to incident reporting and destruction.3Defense Counterintelligence and Security Agency. DOD Mandatory Controlled Unclassified Information (CUI) Training IF141.16 Other agencies run their own courses on similar content tailored to their categories. In most cases you cannot even submit an access request until your training completion is on file.
No government-wide regulation currently mandates a specific recertification cycle across all agencies. Individual agencies and DoD components may set their own recurring schedules, so your security office is the one to ask about a refresh timeline.
A Favorable Background Investigation
CUI is not classified, but a favorable background investigation is still generally required before access is granted. The investigation confirms your identity and screens your history for conduct that would raise trustworthiness concerns.
Federal investigations run in tiers. What used to be called a National Agency Check with Inquiries is now a Tier 1 investigation, the minimum for non-sensitive federal positions. Higher-risk positions or access to more sensitive CUI categories may require a Tier 2 (formerly MBI) or Tier 3 (formerly ANACI/NACLC) investigation, which add interviews, deeper record searches, and broader scope. The sponsoring agency decides which tier fits the position’s risk level and the CUI categories involved.
Personnel security offices run the checks and log the results in the agency’s security database. The investigation must also be current. If yours has lapsed, you will need a reinvestigation before access is approved.
A Written Agreement If You Are Outside the Federal Executive Branch
If you work as a contractor, grantee, licensee, or state or local government employee, your access depends on a written agreement between your organization and the federal agency sharing the information. Contracts, grants, memoranda of understanding, and information-sharing agreements all qualify, and each must contain provisions spelling out CUI handling requirements.4General Services Administration. GSA Controlled Unclassified Information (CUI) Program Guide
When a formal written agreement is not feasible but CUI still has to move, the authorized holder must at minimum communicate to the recipient that the government strongly encourages protection in accordance with 32 CFR Part 2002 and the CUI Registry. In practice, most organizations insist on written terms before releasing anything.
In 2020 the Information Security Oversight Office issued an optional CUI non-disclosure agreement template that agencies can use or modify when they decide a CUI-specific NDA fits the situation. That template is separate from the Standard Form 312, which covers classified information only and does not apply to CUI. If your agency asks you to sign a CUI NDA, it will come from that optional template or an agency-developed equivalent, not the SF-312.5National Archives. Optional Non-Disclosure Agreement Template Issued
Cybersecurity Requirements If Your Systems Will Hold the Data
Federal employees process CUI on federal systems that already meet the security controls in FIPS 199, FIPS 200, and NIST SP 800-53.6eCFR. 32 CFR 2002.14 – Safeguarding Contractors and other non-federal organizations that store, process, or transmit CUI on their own systems have to meet NIST SP 800-171 instead, which translates those federal controls into requirements suitable for non-federal environments.
DFARS 252.204-7012
Defense contractors run into CUI cybersecurity obligations mainly through the DFARS 252.204-7012 clause in their contracts. On top of implementing NIST SP 800-171, the clause requires contractors to report cyber incidents to the DoD, submit any discovered malicious software to the DoD Cyber Crime Center, and facilitate damage assessments when the DoD requests one. The clause flows down to subcontractors unchanged whenever the subcontractor will handle CUI or provide operationally critical support.7Department of Defense. Safeguarding Covered Defense Information – The Basics
CMMC Level 2
The Cybersecurity Maturity Model Certification program adds verification on top of NIST SP 800-171 self-assessment. Under the final rule published in October 2024, DoD contractors whose systems will process, store, or transmit CUI must achieve a CMMC Level 2 certification before contract award. Level 2 assessments are conducted by accredited third-party assessment organizations that evaluate whether the contractor has actually implemented the required controls, not just documented them.8Federal Register. Cybersecurity Maturity Model Certification (CMMC) Program Prime contractors carrying a Level 3 requirement must flow down at least Level 2 to any subcontractor handling CUI. If a subcontractor will not comply, CUI should not sit on that subcontractor’s systems.
Dissemination Markings Can Still Block Access to Specific Documents
Meeting the four core conditions makes you an authorized holder in general, but some CUI carries limited dissemination control markings that narrow who can see a particular document. These appear alongside the CUI banner:
- FED ONLY: restricted to federal employees and military personnel; contractors cannot receive it.
- FEDCON: open to federal employees and contractors, but only when the sharing furthers the contractual purpose.
- NOCON: barred from contractors, though it may be shared with state, local, or tribal government employees.
- NOFORN: cannot be shared with foreign governments, foreign nationals, or international organizations in any form.
- DL ONLY: restricted to the individuals or organizations on an accompanying dissemination list.
Other controls exist for attorney-client privileged material, attorney work product, and foreign release to specific countries. The full list is maintained by the DoD CUI program office.9DoD CUI. Limited Dissemination Controls The practical point: if a document is marked FED ONLY and you are a contractor, no amount of training or investigation will get you access to that document. Any access request has to account for the dissemination restrictions on the specific material you need, not just the four baseline conditions.