HLD Group
CUI handling policy
Handling Controlled Unclassified Information per CMMC and NIST 800-171.
Last updated: 24 July 2026
Version 1.1 · Review cycle: 180 days · View all frameworks
1. Purpose
This policy defines how HLD Group protects Controlled Unclassified Information and export-controlled technical data entrusted to us in the course of defence and government-related work. It exists to satisfy the security requirements imposed by our government customers and by law, and to protect information whose compromise could harm national security or third parties.
2. Scope
This policy applies to all CUI and export-controlled information received, created, stored, processed, or transmitted by HLD Group, to the systems that handle it, and to all personnel and subcontractors with access to it.
3. Definitions
- Controlled Unclassified Information (CUI) — information the government requires to be safeguarded or disseminated under controls, but that is not classified
- Covered defense information — a category of CUI defined under DFARS 252.204-7012
- Export-controlled information — technical data subject to the ITAR or the EAR
- Controlled environment — an approved system or physical space authorised to handle CUI
- Deemed export — release of controlled technology to a foreign person, including within a single country
4. Legal and regulatory framework
- NIST SP 800-171 (Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations), the applicable revision required by contract
- DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting)
- Cybersecurity Maturity Model Certification (CMMC) at the level required by contract
- 32 CFR Part 2002 (Controlled Unclassified Information) and the National Archives CUI Registry
- International Traffic in Arms Regulations (ITAR), 22 CFR Parts 120–130, for defence articles and technical data
- Export Administration Regulations (EAR), 15 CFR Parts 730–774, for dual-use items
- Australian Defence export controls and the Defence Trade Controls Act 2012 (Cth), where applicable to Australian operations
5. Marking and identification
CUI is identified and marked in accordance with the CUI programme and contract requirements, so that everyone handling it knows its status and the controls that apply. Unmarked information reasonably believed to be CUI is treated as CUI until confirmed.
6. Safeguarding requirements
- CUI is stored and processed only in approved, access-controlled environments
- Access is restricted to authorised personnel with a lawful need to know, and, for export-controlled data, to authorised persons under the relevant regulation
- CUI is encrypted at rest and in transit using FIPS-validated cryptography where required by contract
- CUI is not sent to personal accounts or devices, and not stored in unapproved cloud services
- Media and equipment holding CUI are sanitised or destroyed under approved methods before disposal or reuse
- Physical CUI is protected in controlled areas with appropriate access control
7. Export control and foreign person access
Access to export-controlled technical data by foreign persons, including deemed exports within a single location, is restricted and permitted only under an applicable licence or exemption. Personnel screening and technology control plans are applied where required, and access is segregated so that controlled data is not exposed to unauthorised persons.
8. Subcontractor flow-down
The safeguarding and reporting requirements applicable to CUI are flowed down to subcontractors who will handle CUI, and their compliance is assessed under the Vendor Management Policy before access is granted.
9. Incident reporting
Cyber incidents affecting CUI are reported within the timeframes required by contract and regulation — including the 72-hour reporting requirement under DFARS 252.204-7012 to the Department of Defense — in coordination with the Incident Response and Breach Notification Policies.
10. Roles, exceptions, and review
The CISO and a designated compliance lead own CUI protection. Exceptions require documented approval and, where relevant, government authorisation; controls required by law or contract cannot be waived internally. This policy is reviewed at least annually and on any change to contractual security requirements.
Related frameworks
For contractual attestations or audit packs, contact [email protected].