Exercise

Identify CUI Examples

Practice separating CUI from FCI and from ordinary business information.

Intended audience
Contractors and prospective contractors
Difficulty
Advanced
Estimated time
15 minutes
Access
Free
NIST SP 800-171
CMMC
DFARS
Government contracting

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Distinguish Controlled Unclassified Information (CUI) from Federal Contract Information (FCI) and from ordinary business information.
  • Recognize that 'need to ask' is a legitimate, common answer when marking or provenance is unclear.
  • Trace where CUI currently resides across systems, including email and personal devices.
  • Prioritize the first corrective action to reduce exposure of identified CUI.
  • Apply DFARS and CMMC contractual context to decide how information supplied by the government should be handled.

Items to evaluate

  • A technical drawing marked with distribution limits.
  • The list of tasks in your public statement of work summary.
  • Unpriced delivery schedules provided by the government.
  • Your own internal cost estimate for the bid.
  • An email from the contracting officer with performance details not for release.

Key takeaways

  • CUI and FCI are legally distinct categories, and confusing them can lead to under- or over-protecting information.
  • When an item's status is unclear, escalating to the contracting officer or facility security officer is the correct move rather than guessing.
  • CUI frequently ends up in unprotected locations like personal email inboxes or the personal devices of contractor staff.
  • The most effective first remediation step is typically moving CUI out of email into a controlled, access-restricted repository.
  • Properly identifying CUI is foundational to CMMC and NIST SP 800-171 compliance, since the entire control set exists to protect it.

Practice workspace

  1. Hint: 'Need to ask' is a correct answer more often than people expect.

  2. Hint: Include email and personal devices honestly.

  3. Hint: Usually: move it out of email into a controlled location.

Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

Earn a Certificate of Training Completion

Complete every section, acknowledge, and pass the knowledge check.

Sections opened0 of 1
Knowledge check

80% required to pass. Answers are graded on our servers.

1. Unpriced delivery schedules provided by the government are most likely which category?

2. When it is unclear whether an item is CUI, what is the correct response?

3. Why is an internal cost estimate for a bid typically not CUI?

4. Where does CUI most commonly end up unprotected, according to the exercise?

5. What is usually the most effective first step to protect identified CUI?

This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal) — government contracting
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.

Matched on shared frameworks, topics, and program packs.

Checklist

Government Contractor Startup Checklist

What to put in place before your first federal award creates security obligations you cannot meet.

Intermediate
40 min
Free
FAR
DFARS

Published · v1.0.0 · 2026-08-01

Checklist

CMMC Readiness Checklist

Work through the preparation steps most small contractors miss before a CMMC assessment: scope, system boundary, documentation, and evidence.

Intermediate
45 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Checklist

NIST SP 800-171 Preparation Checklist

A plain-language preparation pass across the requirement families, focused on what a small business must produce and prove.

Advanced
60 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Guide

What is NIST SP 800-171?

The requirement set that governs protecting Controlled Unclassified Information in non-federal systems, explained without the jargon.

Intermediate
14 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Exercise

Build a Sample SSP Section

Draft one System Security Plan section end to end, using the narrative pattern assessors expect.

Advanced
25 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.