CUI Identification Worksheet
Filled in by the person who owns your government contracts, with help from engineering, program management and IT, this worksheet produces a single list of the information types your organization receives, creates, processes or transmits that may constitute Controlled Unclassified Information (CUI). For each type it records where it came from, who touches it, where it sits and how it moves. That list is the input to every later step: the flow map, the scope boundary, the technology inventory and the evidence you will eventually be asked to produce.
- 01
Gather your active contracts, subcontracts and purchase orders. Note every one that carries DFARS 252.204-7012, references NIST SP 800-171 or states a CMMC level, and every prime that has sent you a flow-down letter.
- 02
Work through Part 1 with the contracts owner and record, in Part 2, one row per information type. Name the type the way your people name it ("drawing package", "test report"), not the way the regulation does.
- 03
For each row, ask the person who actually handles that information where it comes from, who opens it, where it is stored and how it leaves the building. Write down what happens today, not what policy says should happen.
- 04
Fill in the last column honestly. "Not marked" is a finding, not a failure; unmarked information from a prime is one of the most common gaps we see.
- 05
Record what you learned in the findings block and hand the completed sheet to whoever runs the next document, the CUI Flow Mapping Template (CMMCg-R002).
1 working table, 1 checklist, 2 sets of fields, a findings section and recommended next steps. Every page carries the resource number, the version and the licence.
- Part 1 — Where the obligation comes from
- Contract sources
- Part 2 — Examples of information that may constitute CUI
- Part 3 — Information you receive, create, process or transmit
- Quick inventory by activity
- CUI identification register
- Part 4 — Review questions
- Before you call this list complete
- Resolve every "unknown" designation with the prime or contracting officer in writing and keep the reply with this worksheet.
- Where information is unmarked but contractually identified, agree with the prime how it should be marked on receipt and on anything you send back.
- Take each row of the register into the CUI Flow Mapping Template (CMMCg-R002) and trace it from receipt to disposition.
This resource is general guidance for organizations preparing for Cybersecurity Maturity Model Certification (CMMC). It is not legal advice, it does not constitute an assessment or a certification, and completing it does not by itself establish compliance with NIST SP 800-171 Rev 2, 32 CFR Part 170 or any contract clause. Determinations about what information constitutes Controlled Unclassified Information (CUI) rest with the designating agency and the terms of your contract. Confirm requirements against the current regulation and your contracting officer.
Filled it in and found gaps?
That is what it is for. The readiness call turns a completed worksheet into a scoped plan, and an engineer runs it.
- Your CUI boundary sketched on the call
- The requirements costing you the most points, named
- A written summary afterward, yours to keep
NDA signed before anything technical. No cost, no obligation.