How to Protect Controlled Unclassified Information (CUI)

Protecting Controlled Unclassified Information is the single most important security requirement for DoD manufacturers in 2026. CUI mishandling causes failed CMMC audits, lost contracts, and DFARS penalties. The right approach combines a dedicated CUI enclave, NIST 800-171 controls, continuous monitoring, and documented evidence. Most manufacturers can fully protect CUI in 90 to 180 days with the right plan.

Here's exactly how to do it.

What Is CUI? (Simple Breakdown)

Think of CUI as classified information's quieter cousin. It's not "Top Secret," but it's still sensitive enough that the DoD requires strict handling.

CUI includes things like:

  • Engineering drawings for defense parts
  • Technical specifications
  • Test results and performance data
  • Export-controlled information
  • Procurement and contract details

If you handle any of this, CUI protection rules apply. Your subcontractors handling the same data must comply as well.

Core Steps to Protect CUI

1. Identify and Classify Your CUI

You can't protect what you can't find. Start by mapping data flows from primes, subcontractors, and engineering teams, labeling CUI clearly in file systems and emails, inventorying storage locations including local drives, cloud apps, and email, and documenting access to identify who touches CUI today. Most manufacturers discover CUI in unexpected places: shared OneDrive folders, personal laptops, even text messages.

2. Build a Dedicated CUI Enclave

CUI cannot live in general-purpose Microsoft 365 Commercial. You need a compliant enclave such as Microsoft 365 GCC High for full DoD compliance, a CMMC-certified enclave solution for smaller environments, or isolated network segments for on-premises CUI. The enclave separates CUI from general business data and ensures only U.S. persons can access it, critical for ITAR-controlled data.

3. Apply NIST 800-171 Access Controls

NIST 800-171 requires strict access control over CUI: multi-factor authentication on every account touching CUI, role-based access control limiting CUI access to specific users, privileged access management for admin accounts, session timeouts and re-authentication for sensitive systems, and account reviews at least quarterly. Without these controls, you fail multiple CMMC assessment objectives immediately.

4. Encrypt CUI at Rest and in Transit

CUI encryption is non-negotiable. You need FIPS 140-2 validated encryption for all CUI storage, TLS 1.2 or higher for data in transit, encrypted email for any CUI sent externally, full-disk encryption on every laptop and endpoint, and encrypted backups stored in compliant environments. Standard Microsoft Commercial encryption does not meet FIPS 140-2 validated requirements for DoD CUI.

5. Monitor and Log All CUI Access

Continuous monitoring is required by NIST 800-171 and CMMC Level 2. You need SIEM to collect logs from CUI systems, MDR to detect unauthorized access in real time, log retention for at least 12 months, audit trails showing who accessed what and when, and automated alerts for suspicious CUI activity. This monitoring is also your evidence trail during CMMC audits.

Why Manufacturers Get CUI Protection Wrong

Mistake 1: Storing CUI in Microsoft 365 Commercial. It's not compliant, and auditors catch this immediately.

Mistake 2: Emailing CUI without encryption. Unencrypted email is the most common DFARS violation.

Mistake 3: Letting foreign nationals access CUI. This triggers ITAR violations and contract termination.

Mistake 4: No documented CUI handling procedures. If it's not written down, auditors assume it doesn't exist.

These mistakes are avoidable, but they're extremely common because most MSPs don't specialize in CUI.

Illustrative Scenario. Consider a 60-employee aerospace machining manufacturer in Washington with several million dollars in annual DoD subcontracts, whose prime requested CMMC Level 2 documentation for renewal. The gaps discovered included engineering drawings stored in standard SharePoint, CUI emailed without encryption to subcontractors, personnel with full file access who required additional screening under ITAR, no CUI labeling or classification, and log retention limited to 30 days.

Over a 6-month remediation, the organization completed CUI inventory, classification, and labeling, followed by GCC High migration and enclave deployment, then access controls, MFA, and encryption rollout, and finally SIEM, MDR, documentation, and training. Total remediation cost ran roughly $125,000, with ongoing managed IT services at $210 per user per month. The organization secured its contract renewal. This is a representative example, not a specific client engagement.

What This Means for Your Business

CUI protection directly affects your bottom line. The risks include contract loss if primes find CUI mishandling, DFARS penalties for unreported incidents, ITAR fines per violation, failed CMMC audits blocking new bids, and breach costs if CUI is exfiltrated. Proper CUI protection makes you a preferred supplier, as primes increasingly choose vendors with documented, audit-ready controls over those without.

How to Protect CUI: A 5-Step Framework

  1. Assess. Inventory all CUI, map data flows, and identify gaps.
  2. Scope. Isolate CUI in a dedicated compliant enclave.
  3. Implement. Deploy access controls, encryption, and MFA.
  4. Document. Create an SSP, CUI handling procedures, and incident response plans.
  5. Monitor. Run continuous SIEM and MDR monitoring with audit-ready logs.

Most manufacturers complete this cycle in 90 to 180 days with a CMMC-focused MSP.

Bottom Line

CUI protection is the foundation of CMMC compliance. Get it right and your DoD contracts are protected. Get it wrong and you risk lost revenue, penalties, and reputational damage in the defense supply chain.

The good news is that CUI protection follows a clear, repeatable framework. You just need the right partner to execute it.

Ready to protect your CUI? Start with a CUI and CMMC gap assessment to see exactly where your sensitive data lives and what's required to protect it.

Get a Gap Assessment Book a 30-Minute Call

Related Resources

Frequently Asked Questions

Can CUI be stored in standard Microsoft 365 Commercial?

No. CUI requires a compliant enclave such as Microsoft 365 GCC High, a CMMC-certified enclave solution, or isolated on-premises network segments. Standard commercial tenants do not meet FIPS 140-2 validated encryption or access control requirements for DoD CUI.

What's the biggest mistake manufacturers make with CUI?

Storing CUI in standard Microsoft 365 Commercial and emailing it without encryption are the two most common violations, and both are typically caught immediately during a CMMC audit.

How long does it take to fully protect CUI?

Most manufacturers complete CUI inventory, enclave deployment, access controls, encryption, and monitoring within 90 to 180 days with a CMMC-focused MSP.

Do subcontractors need to protect CUI too?

Yes. Any subcontractor handling CUI on your behalf must meet the same protection requirements. Their gap becomes your gap during an audit or prime review.