Screen shot of a letter to Mr. Michael Thomas, Director of the Information Security Oversight Office at NARA

The United States Government creates a lot of information. Much of that information is intended for public consumption, because transparency is core to the trust between the citizens and the government.

Like with any organization, however, there are some things that need to be kept in confidence. In fact, there is a lot of information that should only be available to certain people within a particular agency. Examples include employee bank account information for direct deposits of their paychecks, employee social security numbers for tax reporting purposes, proposals submitted by contractors with pricing and other information, blueprints for government facilities, and various types of research.

Since its founding, the government has struggled to find the balancing point between things that should be kept in confidence and things that should be public. After the terrorist attacks on New York City and the Pentagon on September 11, 2001, Congress decided that we were still balanced too far in favor of confidentiality. The 9/11 Commission found that federal agencies had the information needed to prevent the attacks, but they kept the information siloed and did not share it with those who would benefit from knowing it. As a result, Congress instructed the President to overhaul the government’s approach to handling classified and unclassified information, with the goal of ensuring that information is more actively shared within the government and with the American people.

The Controlled Unclassified Information (“CUI”) program was created specifically as a result of this charge by Congress. The CUI program establishes a standardized approach for defining what is and properly identifying sensitive information, and establishes a consistent set of safeguarding rules that all agencies must adopt. The goal of the CUI program is to create a safe environment where information can be shared by and between federal agencies, as well as, where appropriate, with non-federal entities including state and local governments and government contractors.

September 11, 2026 will be the twenty-fifth anniversary of the 9/11 attacks, yet more than half of federal agencies still have not implemented the CUI program within their agencies. Thankfully, after nearly a decade of refinement, the FAR Council has finally allowed the publication of a draft FAR CUI Rule for public comments. The draft FAR CUI Rule establishes a consistent set of requirements that must be in all federal contracts that involve the handling of CUI.

The CUI Institute, in combination with industry experts, submitted a set of comments that included not only recommended changes to the FAR CUI Rule, but also clarifications to the CUI program itself and recommended actions for Congress and the White House to help ensure this critical program is finally adopted by all federal agencies.

Copies of our comments can be found here: