| CUI | The 9/11 Commission Report | The report prepared by a Congressionally-appointed commission that provides a root-cause analysis of the attacks on September 11, 2001. | https://govinfo.library.unt.edu/911/report/911Report.pdf |
| CUI | Intelligence Reform and Terrorism Prevention Act of 2004 | Congress's response to the 9/11 Commission Report which, in part, requires the creation of an information sharing program. This lays the foundation for the CUI Program. | https://www.congress.gov/bill/108th-congress/senate-bill/2845 |
| CUI | Designation and Sharing of Controlled Unclassified Information (CUI) | 2008 Memorandum issued by President George W. Bush which delegates authority to federal agencies to create an early version of the CUI Program. | https://georgewbush-whitehouse.archives.gov/news/releases/2008/05/20080509-6.html |
| CUI | Executive Order 13556 -- Controlled Unclassified Information | 2010 Executive Order issued by President Obama that delegates authority to the National Archives and Records Administration ("NARA") to create and manage the CUI Program that applies to all federal agencies. | https://obamawhitehouse.archives.gov/the-press-office/2010/11/04/executive-order-13556-controlled-unclassified-information |
| CUI | 32 CFR 2002 - CONTROLLED UNCLASSIFIED INFORMATION (CUI) | The regulation that defines the CUI Program that must be implemented by federal agencies. Establishes the CUI Registry as the authoritative source for laws, regulations, and government-wide policies that are approved for use as the basis for designating information as CUI. Establishes that legacy markings (e.g., For Official Use Only ("FOUO"), Sensitive but Unclassified ("SBU"), Law Enforcement Sensitive ("LES"), etc.) are no longer to be used by federal agencies. Defines NIST SP 800-171 as the requirement that must be met when non-federal information systems are handling CUI. | https://www.ecfr.gov/current/title-32/subtitle-B/chapter-XX/part-2002 |
| CUI | NARA CUI Registry | The authoritative list of laws, regulations, and government-wide policies which are approved for use as the basis for designating information as CUI. | https://www.archives.gov/cui/registry/category-list |
| CUI | DoDI 5200.48 - Controlled Unclassified Information (CUI) | March 6, 2020 Instruction issued by the Under Secretary of Defense for Intelligence and Security that defines DoD's implementation of the CUI program. | https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/520048p.PDF |
| CUI | DoDI 5230.24 - Distribution Statements on DoD Technical Information | January 10, 2023 Instruction issued by the Under Secretary of Defense for Research and Engineering that defines Controlled Technical Information ("CTI") and the application of distribution statements to CTI. | https://www.esd.whs.mil/portals/54/documents/dd/issuances/dodi/523024p.pdf |
| CUI | DoD Manual 5200.45 - Original Classification Authority and Writing a Security Classification Guide | January 17, 2025 update to DoD Manual 5200.45 issued by Acting Under Secretary of Defense for Intelligence and Security which clarifies the CUI designation authority delegated to Original Classification Authorities ("OCAs") in DoDI 5200.48 and defines the content and procedures for developing Security Classification Guides ("SCGs"). | https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/520045m.PDF?ver=KZHzn_FzOh9oJ-Mb_0cb2g%3d%3d |
| CUI | Reminder of the Prohibition of the Use of the "For Official Use Only" Marking | July 14, 2025 "Memorandum for Senior Pentagon Leadership, Commanders of the Combatant Commands, Defense Agency, and DoD Field Activity Directors" issued by the Director for Defense Intelligence, Counterintelligence, Law Enforcement, & Security which reinforces that the legacy For Official Use Only ("FOUO") marking is no longer to be used by DoD personnel. | https://www.dodcui.mil/Portals/109/Documents/Policy%20Docs/25-P-0992%20cleared%20Prohibition%20on%20Application%20of%20FOUO%20Marking%20SIGNED.pdf?ver=k2SOpQQW-RcRmIhvOdbKIQ%3d%3d |
| CUI | Clarifying Guidance for Marking and Handling Controlled Technical Information in accordance with Department of Defense Instruction 5200.48, “Controlled Unclassified Information” | February 17, 2025 "Memorandum for Senior Pentagon Leadership, Defense Agency, and DoD Field Activity Directors" which clarifies DoDI 5230.24 with respect to the use of the CUI category of Controlled Technical Information ("CTI"), and specifically the use of distribution statements on CTI, the retroactive effect of DoDI 5200.48, and the implications of CTI on research, development, test, and evaluation efforts. | https://www.dodcui.mil/Portals/109/Documents/Policy%20Docs/Clarifying%20Guidance%20for%20Marking%20and%20Handling_CTI%2020210331.pdf?ver=HXGACULisTzB7tYu7MtHIg%3d%3d |
| CMMC | Implementing the Cybersecurity Maturity Model Certification (CMMC) Program: Guidance for Detem1ining Appropriate CMMC Compliance Assessment Levels and Process for Waiving CMMC Assessment Requirements | January 17, 2025 joint "Memorandum for Senior Pentagon Leadership, Defense Agency, and DoD Field Activity Directors" issued by the Undersecretary of Defense for Research and Engineering, Undersecretary of Defense for Acquisition and Sustainment, and the Acting Chief Information Officer of the Department of Defense which describes the approach Contracting Officers and other authorized agency personnel are to use to select an appropriate CMMC level for a particular solicitation or contract and the application of the phased implementation approach defined in 32 CFR 170. | https://dodprocurementtoolbox.com/uploads/DOPSR_Cleared_OSD_Memo_CMMC_Implementation_Policy_d26075de0f.pdf |
| CMMC | 32 CFR 170 - Cybersecurity Maturity Model Certification (CMMC) Program (without public comments) | The CMMC Program Rule, which formally defines DoD's CMMC program. This includes defining: CMMC's 3 levels, self- and third-party assessment requirements, CMMC ecosystem entities and roles, DoD's phased implementation plan, etc. | https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170 |
| CMMC | 32 CFR 170 - Cybersecurity Maturity Model Certification (CMMC) Program (with public comments) | The CMMC Program Rule, including DoD's responses to public comments. It is important to note that, while the responses to comments are informative and provide guidance, they are not authoritative instructions or requirements, nor are they automatically read into the regulatory requirements. | https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program |
| CMMC | 48 CFR 252.204-7021 etc. - CMMC Acquisition Rule ("Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041") (with public comments) | The CMMC Acquisitionion Rule, including DoD's responses to public comments. It is important to note that, while the responses to comments are informative and provide guidance, they are not authoritative instructions or requirements, nor are they automatically read into the regulatory requirements. | https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of |
| FCI | FAR 52.204-21 | Government-wide acquisition requirement which establishes a baseline set of information security requirements that must be in place when any government contractor is creating or handling non-public, unclassified information on behalf of the government under a Federal Acquisition Regulation ("FAR")-based contract. | https://www.acquisition.gov/far/52.204-21 |
| CUI, CMMC | NIST SP 800-171 | The information security requirements established by the National Institute of Standards and Technology which must be in place when non-federal systems handle CUI. | https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final |
| CUI, CMMC | DFARS 252.204-7008 - Compliance with Safeguarding Covered Defense Information Controls | DoD acquisition requirement under which contractors are affirming that, by submitting an offer, they will implement the requirements in DFARS 252.204-7012 no later than December 31, 2017. | https://www.acquisition.gov/dfars/252.204-7008-compliance-safeguarding-covered-defense-information-controls. |
| CUI, CMMC | DFARS 252.204-7012 - Safeguarding Covered Defense Information and Cyber Incident Reporting | DoD acquisition requirement which defines contractors' obligations when handling Covered Defense Information ("CDI") which includes Controlled Technical Information ("CTI") and other forms of CUI. | https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting. |
| Other | DFARS 252.204-7016 - Covered Defense Telecommunications Or Services - Representation | DoD acquisition requirement which establishes that the list of excluded parties in the System for Award Management ("SAM") (https://SAM.gov) must be reviewed by contractors to ensure that the contractor does not provide covered telecommunications equipment or services as part of it products, nor are they used in performance of services for the government. | https://www.acquisition.gov/dfars/252.204-7016-covered-defense-telecommunications-equipment-or-services%E2%80%94representation. |
| Other | DFARS 252.204-7017 - Prohibition on the Acquisition of Covered Defense Telecommunication Equipment or Services - Representation | DoD acquisition requirement which states that if a contractor is supplying or using covered telecommunication equipment in performance of a contract, additional representations are required. Those representations are defined in this clause. | https://www.acquisition.gov/dfars/252.204-7017-prohibition-acquisition-covered-defense-telecommunications-equipment-or-services%E2%80%94representation. |
| Other | DFARS 252.204-7018 - Prohibition on the Acquisition of Covered Defense Telecommunications Equipment or Services | DoD acquisition requirement which establishes the policy and procedures for limiting the use of covered defense telecommunication equipment. | https://www.acquisition.gov/dfars/252.204-7018-prohibition-acquisition-covered-defense-telecommunications-equipment-or-services. |
| CUI | DFARS 252.204-7019 - Notice of NISTSP 800-171 DoD Assessment Requirements | DoD acquisition requirement which establishes the need for contractors that handle CUI to perform a self-assessment of their information security programs and to report a corresponding score to the Supplier Performance Risk System ("SPRS"). | https://www.acquisition.gov/dfars/252.204-7019-notice-nistsp-800-171-dod-assessment-requirements. |
| CUI | DFARS 252.204-7019 - Notice of NISTSP 800-171 DoD Assessment Requirements | DoD acquisition requirement which establishes the need for contractors that handle CUI to perform a self-assessment of their information security programs and to report a corresponding score to the Supplier Performance Risk System ("SPRS"). | https://www.acquisition.gov/dfars/252.204-7020-nist-sp-800-171dod-assessment-requirements. |
| CMMC | DFARS 252.204-7021 - Cybersecurity Maturity Model Certification Requirements. | DoD acquisition requirement which is used to add CMMC requirements to DoD contracts. | https://www.acquisition.gov/dfars/252.204-7021-cybersecurity-maturity-model-certification-requirements. |
| CUI, CMMC | DFARS 252.204-7024 - Notice on the Use of the Supplier Performance Risk System. | DoD acquisition requirement which advises contractors about how information contained in the Supplier Performance Risk System ("SPRS") will be used by Contracting Officers. | https://www.acquisition.gov/dfars/252.204-7024-notice-use-supplier-performance-risk-system. |
| CUI | DoD CUI Top 10 | The top 10 categories of CUI accessed by DoD personnel. | https://www.dodcui.mil/Top-10-CUI-Categories/ |