Skip to content

Insights

CMMC Requirements: CUI Basic Versus CUI Specified

Key Takeaways

  • Know Your CUI Category: CUI Basic and CUI Specified have different safeguarding requirements, making it important to understand what types of CUI your contracts involve.
  • CSP Selection Matters: CUI Basic may be supported by Microsoft GCC, while CUI Specified may require a U.S. sovereign environment such as GCC High or AWS GovCloud.
  • Review Contract Requirements: CUI markings and handling requirements are determined by the applicable laws, regulations, and contract terms, so organizations should review requirements with their contracting officer or COR.
  • Plan for Future Contracts: Even if an organization currently handles only CUI Basic, future contracts may introduce CUI Specified requirements that could require changes to the CMMC environment.

For organizations in the Defense Industrial Base (DIB) that are required to achieve CMMC compliance, many are surprised to learn that not all CUI is subject to the same handling requirements. The distinction between CUI Basic and CUI Specified can have significant implications for selecting cloud service providers and designing compliant environments.

Understanding these differences is essential to ensuring that an organization not only meets CMMC requirements today but is also prepared to support future contracts that may impose additional safeguarding obligations. This article examines the differences between CUI Basic and CUI Specified, explains how those distinctions affect cloud hosting requirements, and discusses what contractors should consider when building a compliant CMMC environment.

What Is the Requirement?

Per 32 CFR Part 170 of the CMMC Program:

“Defense contracts involving the development or transfer of CUI to a non-Government organization require applicable requirements of DFARS clause 252.204-7012. This clause requires defense contractors to provide adequate security on all covered contractor information systems by implementing the 110 security requirements specified in NIST SP 800-171. This clause includes additional requirements; for example, defense contractors must confirm that any Cloud Service Providers (CSPs) used by the contractor to handle controlled unclassified information (CUI) meet Federal Risk and Authorization Management Program (FedRAMP) Moderate Baseline or the equivalent requirements.”

How to Verify a CSP Meets FedRAMP Requirements

The FedRAMP is a United States federal government-wide compliance program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. The FedRAMP Marketplace provides a searchable, sortable database of Cloud Service Offerings (CSOs) that have achieved a FedRAMP designation. Verify on FedRAMP Marketplace – Products.

Which CSP Should Be Selected?

It depends on the categories of CUI an organization processes and their business requirements. If one knows that they will only receive CUI Basic, Microsoft’s GCC may suit their organization’s needs.

If one is unsure what category CUI they might receive or want to adopt a “blanket” approach to safeguarding CUI, using a CSP such as GCC High or AWS GovCloud may be the right choice.

How to Know if Data Is CUI Basic Versus CUI Specified

CFR 32 Part 2002, CONTROLLED UNCLASSIFIED INFORMATION (CUI) clarifies:

“Law, regulation, or government-wide policy may require or permit safeguarding or dissemination controls in three ways: Requiring or permitting agencies to control or protect the information but providing no specific controls, which makes the information CUI Basic; requiring or permitting agencies to control or protect the information and providing specific controls for doing so, which makes the information CUI Specified; or requiring or permitting agencies to control the information and specifying only some of those controls, which makes the information CUI Specified, but with CUI Basic controls where the authority does not specify.

  • CUI Basic: Sensitive and must be protected, but there are no special handling rules beyond the normal CUI requirements.
  • CUI Specified: A law, regulation, or government-wide policy specifically says exactly how this type of information must be protected, shared, marked, or destroyed.”

Basically, basic requires safeguarding under NIST 800-171 to protect the confidentiality of and access to the data. It does not automatically require U.S. only hosting, storage, personnel, and sovereign cloud infrastructure. As soon as the CUI is protected by a law, regulation, agency rule, export restriction, or contract clause that adds these restrictions, then one must be mindful of any non U.S. personnel access to or storage of the CUI.

For a list of CUI Basic and Specified banner markings, reference the National Archives and Records Administration’s (NARA) CUI Markings page. CUI training is also available here. To understand what categories of CUI an organization will receive and the safeguarding requirements, one should thoroughly review their contract with their government contracting officer or contracting officer representative (COR).

What Does This Mean When Selecting a CSP?

According to Microsoft: “GCC isn’t suitable to hold CUI Specified (for example, ITAR, Nuclear, and so on). This type of data requires US sovereignty, which only GCC High offers.”

Although Microsoft’s Government Community Cloud (GCC) meets the CMMC FedRAMP Moderate requirement, it does NOT meet all CUI Specified laws, regulations, or government-wide policies with specific handling controls.

Alternatively, Microsoft GCC High or AWS GovCloud offers isolated U.S. sovereign regions operated by U.S. citizens which has a FedRAMP High certification.

Bottom Line

Many contractors and sub-contractors in the DIB only have CUI Basic. The typical contractor technical data, procurement information, and internal operational information could be marked as CUI Basic or CUI Specified. The CUI markings are determined by the contract. The risk is that there are no guarantees contracts that an organization wants to bid on may include additional requirements which results in at least a portion of the CUI being CUI Specified. A CMMC environment using GCC that only meets CUI Basic requirements will not meet the contractual requirements for CUI Specified, which requires GCC High.

For more information on our CMMC services, contact Dave Hammarberg, Partner, LCCA or Elaine Nissley, Director, LCCA.

About the Author

Logan Daniels

Logan Daniels joined McKonly & Asbury in 2026 and is currently a Supervisor with the firm’s CMMC team.

Prior to joining the firm, he served in multiple cybersecurity and information assurance roles for the U.S. Navy, including Information Systems Security Engineer (ISSE), Information Systems Security Manager (ISSM), and Information Systems Security Officer (ISSO).

Related Services

Contact

Subscribe to Our Newsletter