Key CMMC- and CUI-Related Laws, Regulations, and Government-Wide Policies

RelevanceDocument NameDescriptionLink
CUIThe 9/11 Commission ReportThe report prepared by a Congressionally-appointed commission that provides a root-cause analysis of the attacks on September 11, 2001.https://govinfo.library.unt.edu/911/report/911Report.pdf
CUIIntelligence Reform and Terrorism Prevention Act of 2004Congress's response to the 9/11 Commission Report which, in part, requires the creation of an information sharing program. This lays the foundation for the CUI Program.https://www.congress.gov/bill/108th-congress/senate-bill/2845
CUIDesignation and Sharing of Controlled Unclassified Information (CUI)2008 Memorandum issued by President George W. Bush which delegates authority to federal agencies to create an early version of the CUI Program.https://georgewbush-whitehouse.archives.gov/news/releases/2008/05/20080509-6.html
CUIExecutive Order 13556 -- Controlled Unclassified Information2010 Executive Order issued by President Obama that delegates authority to the National Archives and Records Administration ("NARA") to create and manage the CUI Program that applies to all federal agencies.https://obamawhitehouse.archives.gov/the-press-office/2010/11/04/executive-order-13556-controlled-unclassified-information
CUI32 CFR 2002 - CONTROLLED UNCLASSIFIED INFORMATION (CUI)The regulation that defines the CUI Program that must be implemented by federal agencies. Establishes the CUI Registry as the authoritative source for laws, regulations, and government-wide policies that are approved for use as the basis for designating information as CUI. Establishes that legacy markings (e.g., For Official Use Only ("FOUO"), Sensitive but Unclassified ("SBU"), Law Enforcement Sensitive ("LES"), etc.) are no longer to be used by federal agencies. Defines NIST SP 800-171 as the requirement that must be met when non-federal information systems are handling CUI.https://www.ecfr.gov/current/title-32/subtitle-B/chapter-XX/part-2002
CUINARA CUI RegistryThe authoritative list of laws, regulations, and government-wide policies which are approved for use as the basis for designating information as CUI.https://www.archives.gov/cui/registry/category-list
CUIDoDI 5200.48 - Controlled Unclassified Information (CUI)March 6, 2020 Instruction issued by the Under Secretary of Defense for Intelligence and Security that defines DoD's implementation of the CUI program.https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/520048p.PDF
CUIDoDI 5230.24 - Distribution Statements on DoD Technical InformationJanuary 10, 2023 Instruction issued by the Under Secretary of Defense for Research and Engineering that defines Controlled Technical Information ("CTI") and the application of distribution statements to CTI.https://www.esd.whs.mil/portals/54/documents/dd/issuances/dodi/523024p.pdf
CUIDoD Manual 5200.45 - Original Classification Authority and Writing a Security Classification GuideJanuary 17, 2025 update to DoD Manual 5200.45 issued by Acting Under Secretary of Defense for Intelligence and Security which clarifies the CUI designation authority delegated to Original Classification Authorities ("OCAs") in DoDI 5200.48 and defines the content and procedures for developing Security Classification Guides ("SCGs").https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/520045m.PDF?ver=KZHzn_FzOh9oJ-Mb_0cb2g%3d%3d
CUIReminder of the Prohibition of the Use of the "For Official Use Only" MarkingJuly 14, 2025 "Memorandum for Senior Pentagon Leadership, Commanders of the Combatant Commands, Defense Agency, and DoD Field Activity Directors" issued by the Director for Defense Intelligence, Counterintelligence, Law Enforcement, & Security which reinforces that the legacy For Official Use Only ("FOUO") marking is no longer to be used by DoD personnel.https://www.dodcui.mil/Portals/109/Documents/Policy%20Docs/25-P-0992%20cleared%20Prohibition%20on%20Application%20of%20FOUO%20Marking%20SIGNED.pdf?ver=k2SOpQQW-RcRmIhvOdbKIQ%3d%3d
CUIClarifying Guidance for Marking and Handling Controlled Technical Information in accordance with Department of Defense Instruction 5200.48, “Controlled Unclassified Information”February 17, 2025 "Memorandum for Senior Pentagon Leadership, Defense Agency, and DoD Field Activity Directors" which clarifies DoDI 5230.24 with respect to the use of the CUI category of Controlled Technical Information ("CTI"), and specifically the use of distribution statements on CTI, the retroactive effect of DoDI 5200.48, and the implications of CTI on research, development, test, and evaluation efforts.https://www.dodcui.mil/Portals/109/Documents/Policy%20Docs/Clarifying%20Guidance%20for%20Marking%20and%20Handling_CTI%2020210331.pdf?ver=HXGACULisTzB7tYu7MtHIg%3d%3d
CMMCImplementing the Cybersecurity Maturity Model Certification (CMMC) Program: Guidance for Detem1ining Appropriate CMMC Compliance Assessment Levels and Process for Waiving CMMC Assessment RequirementsJanuary 17, 2025 joint "Memorandum for Senior Pentagon Leadership, Defense Agency, and DoD Field Activity Directors" issued by the Undersecretary of Defense for Research and Engineering, Undersecretary of Defense for Acquisition and Sustainment, and the Acting Chief Information Officer of the Department of Defense which describes the approach Contracting Officers and other authorized agency personnel are to use to select an appropriate CMMC level for a particular solicitation or contract and the application of the phased implementation approach defined in 32 CFR 170.https://dodprocurementtoolbox.com/uploads/DOPSR_Cleared_OSD_Memo_CMMC_Implementation_Policy_d26075de0f.pdf
CMMC32 CFR 170 - Cybersecurity Maturity Model Certification (CMMC) Program (without public comments)The CMMC Program Rule, which formally defines DoD's CMMC program. This includes defining: CMMC's 3 levels, self- and third-party assessment requirements, CMMC ecosystem entities and roles, DoD's phased implementation plan, etc.https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170
CMMC32 CFR 170 - Cybersecurity Maturity Model Certification (CMMC) Program (with public comments)The CMMC Program Rule, including DoD's responses to public comments. It is important to note that, while the responses to comments are informative and provide guidance, they are not authoritative instructions or requirements, nor are they automatically read into the regulatory requirements.https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program
CMMC48 CFR 252.204-7021 etc. - CMMC Acquisition Rule ("Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041") (with public comments)The CMMC Acquisitionion Rule, including DoD's responses to public comments. It is important to note that, while the responses to comments are informative and provide guidance, they are not authoritative instructions or requirements, nor are they automatically read into the regulatory requirements.https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of
FCIFAR 52.204-21Government-wide acquisition requirement which establishes a baseline set of information security requirements that must be in place when any government contractor is creating or handling non-public, unclassified information on behalf of the government under a Federal Acquisition Regulation ("FAR")-based contract.https://www.acquisition.gov/far/52.204-21
CUI, CMMCNIST SP 800-171The information security requirements established by the National Institute of Standards and Technology which must be in place when non-federal systems handle CUI.https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final
CUI, CMMCDFARS 252.204-7008 - Compliance with Safeguarding Covered Defense Information ControlsDoD acquisition requirement under which contractors are affirming that, by submitting an offer, they will implement the requirements in DFARS 252.204-7012 no later than December 31, 2017.https://www.acquisition.gov/dfars/252.204-7008-compliance-safeguarding-covered-defense-information-controls.
CUI, CMMCDFARS 252.204-7012 - Safeguarding Covered Defense Information and Cyber Incident ReportingDoD acquisition requirement which defines contractors' obligations when handling Covered Defense Information ("CDI") which includes Controlled Technical Information ("CTI") and other forms of CUI.https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.
OtherDFARS 252.204-7016 - Covered Defense Telecommunications Or Services - RepresentationDoD acquisition requirement which establishes that the list of excluded parties in the System for Award Management ("SAM") (https://SAM.gov) must be reviewed by contractors to ensure that the contractor does not provide covered telecommunications equipment or services as part of it products, nor are they used in performance of services for the government.https://www.acquisition.gov/dfars/252.204-7016-covered-defense-telecommunications-equipment-or-services%E2%80%94representation.
OtherDFARS 252.204-7017 - Prohibition on the Acquisition of Covered Defense Telecommunication Equipment or Services - RepresentationDoD acquisition requirement which states that if a contractor is supplying or using covered telecommunication equipment in performance of a contract, additional representations are required. Those representations are defined in this clause.https://www.acquisition.gov/dfars/252.204-7017-prohibition-acquisition-covered-defense-telecommunications-equipment-or-services%E2%80%94representation.
OtherDFARS 252.204-7018 - Prohibition on the Acquisition of Covered Defense Telecommunications Equipment or ServicesDoD acquisition requirement which establishes the policy and procedures for limiting the use of covered defense telecommunication equipment.https://www.acquisition.gov/dfars/252.204-7018-prohibition-acquisition-covered-defense-telecommunications-equipment-or-services.
CUIDFARS 252.204-7019 - Notice of NISTSP 800-171 DoD Assessment RequirementsDoD acquisition requirement which establishes the need for contractors that handle CUI to perform a self-assessment of their information security programs and to report a corresponding score to the Supplier Performance Risk System ("SPRS").https://www.acquisition.gov/dfars/252.204-7019-notice-nistsp-800-171-dod-assessment-requirements.
CUIDFARS 252.204-7019 - Notice of NISTSP 800-171 DoD Assessment RequirementsDoD acquisition requirement which establishes the need for contractors that handle CUI to perform a self-assessment of their information security programs and to report a corresponding score to the Supplier Performance Risk System ("SPRS").https://www.acquisition.gov/dfars/252.204-7020-nist-sp-800-171dod-assessment-requirements.
CMMCDFARS 252.204-7021 - Cybersecurity Maturity Model Certification Requirements.DoD acquisition requirement which is used to add CMMC requirements to DoD contracts.https://www.acquisition.gov/dfars/252.204-7021-cybersecurity-maturity-model-certification-requirements.
CUI, CMMCDFARS 252.204-7024 - Notice on the Use of the Supplier Performance Risk System.DoD acquisition requirement which advises contractors about how information contained in the Supplier Performance Risk System ("SPRS") will be used by Contracting Officers.https://www.acquisition.gov/dfars/252.204-7024-notice-use-supplier-performance-risk-system.
CUIDoD CUI Top 10The top 10 categories of CUI accessed by DoD personnel.https://www.dodcui.mil/Top-10-CUI-Categories/