What Is SBU in Government and How It Became CUI?

In the federal government, SBU stands for Sensitive But Unclassified — a designation once used for information that needed protection from public release but did not qualify as classified national security material. The label is no longer current. Executive Order 13556, signed in November 2010, retired SBU and more than 100 similar agency-specific markings and replaced them with a single government-wide system called Controlled Unclassified Information, or CUI.1Obama White House Archives. Executive Order 13556 – Controlled Unclassified Information Any document still bearing an SBU marking today should be handled under the CUI framework.2Department of the Interior. Controlled Unclassified Information (CUI) Program

Why SBU Was Retired

Before 2010, each agency invented its own vocabulary for sensitive unclassified material. The State Department used Sensitive But Unclassified. The Department of Defense used For Official Use Only. Other agencies had their own terms. The result was a patchwork of over 100 different markings across the executive branch, each carrying different handling rules, which caused confusion whenever agencies tried to share information.

Executive Order 13556 solved that by consolidating everything under one label and one rulebook. It named the National Archives and Records Administration (NARA) as the executive agent responsible for the program and for issuing government-wide policy. The detailed implementing regulation lives at 32 CFR Part 2002.3eCFR. 32 CFR Part 2002 – Controlled Unclassified Information (CUI)

The Two Handling Tiers: Basic and Specified

Not all CUI is treated the same way. The program splits information into two tiers.

CUI Basic is the default. Any CUI that isn’t otherwise designated falls here, and it follows the uniform safeguarding, marking, and dissemination rules in 32 CFR Part 2002. The same standards apply across every Basic category.

CUI Specified covers information whose underlying law or regulation imposes handling requirements beyond the Basic standard. Tax return information and certain law enforcement data are examples: statute-specific protections override or supplement the default rules. If you handle Specified material, you follow both the general CUI rules and the additional requirements in the source statute.

NARA’s CUI Registry lists every approved category and subcategory, identifies each as Basic or Specified, and links to the governing authority.4National Archives. Controlled Unclassified Information (CUI)

What Kinds of Information Are Covered

The Registry contains dozens of categories. The ones most people encounter include:

  • Personally Identifiable Information (PII): Social Security numbers, medical records, financial account details, and other data tied to specific individuals. The Privacy Act of 1974 prohibits agencies from disclosing records about individuals without written consent, except in limited circumstances.5Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals
  • Law Enforcement Sensitive: Witness statements, investigative techniques, and surveillance details whose release could compromise cases or endanger people.
  • Export-Controlled Information: Technical data covered by the International Traffic in Arms Regulations or the Export Administration Regulations. The marking is “EXPT.”6National Archives. CUI Category – Export Controlled
  • Proprietary Business Information: Trade secrets and confidential commercial data private companies provide to the government.

What ties the categories together is potential harm: releasing the information could damage a person’s privacy, a law enforcement operation, a national security interest, or a company’s competitive position.

Who Can Access It

CUI does not require a security clearance. The access standard is “lawful government purpose” — any activity, mission, or function the U.S. government authorizes or recognizes as within its legal authorities. Access is still limited to authorized holders: individuals or organizations permitted to handle the information because it’s relevant to their work.

Many agencies require nondisclosure agreements before granting access. A contracting officer may require both the company and individual employees to execute separate NDAs as a condition of receiving CUI materials.7Acquisition.gov. 2452.237-82 Access to Controlled Unclassified Information (CUI) People with access should not discuss the contents in public settings or share information with unauthorized colleagues, even inside the same organization.

Training

Federal employees must receive CUI training when they start with an agency and at least once every two years afterward. Training covers designation, categories and subcategories, proper markings, and safeguarding and dissemination procedures. Each agency’s senior agency official for CUI sets the specific policy, including how often contractors and other non-employee personnel must train.

The Department of Defense offers a mandatory course through the Center for Development of Security Excellence covering the eleven core training requirements, including marking, safeguarding, decontrolling, destroying, and reporting security incidents.8Defense Counterintelligence and Security Agency. DoD Mandatory Controlled Unclassified Information (CUI) Training

How CUI Must Be Marked

Marking is the first line of defense. It tells anyone who picks up a document exactly how to handle it, and the standards are uniform across agencies.

Every page of a CUI document carries a banner at the top and a footer at the bottom, in bold capitalized centered text. Even if only one page in a multi-page document contains CUI, every page must be marked. Pages without CUI content may be marked “CUI” or “UNCLASSIFIED” at the originator’s discretion.9Center for Development of Security Excellence. CUI Quick Marking Tips For CUI Basic, the banner reads “CUI.” For Specified information or material with limited dissemination controls, the banner adds notation, such as “CUI//SP-EXPT” for specified export-controlled information.

Portion marking within a document is optional, but the rule is all or nothing: if you mark any portion, you must mark all of them. CUI portions get a “(CUI)” prefix, unclassified portions get “(U).”10DoD CUI Program. Portion Marking

When carrying CUI documents outside an office or approved telework location, place them in an opaque envelope with Standard Form 901, the official CUI cover sheet, on top.11DoD CUI Program. CUI Cover Sheets Emails containing CUI need a banner as the first line and a footer as the last. When an email is only a transmittal for a CUI attachment and contains no CUI itself, it still needs “CUI” as the first and last line plus the statement: “This email is unclassified when CUI Document is Removed.”12DoD CUI Program. Controlled Unclassified Information Markings

Storing, Sending, and Destroying CUI

Physical documents must be stored so unauthorized people cannot reach them: locked file cabinets, safes, or secure rooms with badge or biometric entry. Documents in use should never be left unattended in open workspaces. Facilities storing CUI should use reinforced doors, restricted entry points, and monitored access controls, and visitors, maintenance staff, and custodial workers should be escorted in those areas.

Electronic transmission requires encryption. Federal agencies and their contractors must use cryptographic modules validated under the Federal Information Processing Standards. FIPS 140-2 validated modules remain acceptable for existing systems through September 21, 2026, after which all new validations must meet FIPS 140-3.13NIST CSRC. Cryptographic Module Validation Program

When CUI has met its retention requirement, destruction must make reconstruction impossible. Paper CUI is destroyed using cross-cut shredders that produce particles no larger than 1 mm by 5 mm, or by pulping or incineration.14National Archives. CUI Notice 2019-03 – Destroying Controlled Unclassified Information (CUI) in Paper Form Electronic media — hard drives, USB drives, memory cards — must be sanitized following NIST Special Publication 800-88, using one of three approaches: clearing, purging, or physical destruction.15National Archives. Controlled Unclassified Information Destruction

Rules for Contractors

Private companies handling CUI under government contracts carry compliance obligations that go beyond internal agency rules.

Contractors operating information systems that process, store, or transmit CUI must implement the security controls in NIST Special Publication 800-171. Revision 3, published in May 2024, organizes requirements across 17 security control families covering access control, encryption, incident response, and supply chain risk management.16NIST CSRC. NIST SP 800-171 Rev 3 – Protecting Controlled Unclassified Information

Defense contractors must also comply with DFARS clause 252.204-7012, which requires adequate security for covered defense information and rapid reporting — within 72 hours — of any cyber incident affecting CUI on contractor systems. The requirement flows down to subcontractors through the contract chain.17Acquisition.gov. DFARS 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting

The Department of Defense’s Cybersecurity Maturity Model Certification adds a verification layer on top. Phase 1 implementation began in November 2025 and runs through November 2026, focused on Level 1 and Level 2 self-assessments. Contractors handling CUI generally need to meet at least Level 2, which aligns with the NIST SP 800-171 requirements.18DoD CIO. Cybersecurity Maturity Model Certification

What Happens If You Mishandle It

Consequences depend on the circumstances and the agency. Where the law or regulation governing a specific CUI category sets its own sanctions — the penalties for unauthorized disclosure of tax return information, for instance — agencies follow those provisions.19eCFR. 32 CFR 2002.56 – Sanctions for Misuse of CUI Beyond category-specific penalties, agencies have broad authority to impose administrative discipline.

Typical consequences for employees include formal reprimand, suspension, loss of CUI access, termination, and permanent revocation of facility access. For contractors, noncompliance can trigger contract challenges, loss of an existing award, and future ineligibility for government contracts. Deliberate misrepresentation of compliance status can bring fraud charges and criminal penalties.

Decontrol and Public Records

CUI doesn’t stay designated forever. Agencies should remove the CUI designation as soon as the information no longer requires safeguarding or dissemination controls, unless doing so would conflict with the governing law or regulation.20National Archives. CUI Registry – Decontrol Decontrol relieves authorized holders from CUI handling obligations, but it doesn’t automatically clear the information for public release. Review may still be required.

One boundary worth stating plainly: a CUI marking is not a shield against Freedom of Information Act requests. FOIA gives the public the right to request federal agency records.21Office of the Law Revision Counsel. 5 USC 552 – Public Information; Agency Rules, Opinions, Orders, Records, and Proceedings Agencies evaluate each request against the specific FOIA exemptions — such as those protecting personal privacy, law enforcement records, or confidential business information. If no exemption applies, the agency must release the records even if they carry a CUI marking. The designation only signals how the information must be handled within government.