A law firm that reviews or negotiates government contracts for clients often ends up in possession of controlled unclassified information (CUI) in its email and files. CUI is a category of client data with handling rules attached, and those rules can reach the firm through the agreements and contract terms that come with the information. For a law firm, compliance means handling that information under those terms, and CUI security comes down mostly to how the firm protects email and shared files.

What is controlled unclassified information?

Controlled unclassified information is government information that is not classified but still requires protection. The federal CUI rule, 32 CFR 2002.4, defines it as information the government creates or possesses, or that an entity creates or possesses for the government, “that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls.”

The categories of CUI are listed in the CUI Registry, maintained by the National Archives.

How does a law firm end up holding CUI?

Law firms often receive CUI from their clients: government contracts, bid protests, export control matters, technical data in IP disputes, and diligence on defense or federal contractors can all carry CUI. For the firm, CUI is one more type of client data it must protect.

That is why government contract work often brings CUI into ordinary email threads and shared folders. A redlined contract with controlled technical data attached, a protest record with source selection information, or a client’s system security plan shared for review all count.

Where does a law firm’s obligation to protect CUI come from?

A law firm’s obligation to protect CUI comes from the terms under which it receives the information. The federal CUI rule (32 CFR Part 2002) governs federal agencies and reaches outside organizations through agreements. Defense and federal clients often share CUI with outside counsel, and their contracts may require the firm to protect it. Engagement terms or confidentiality agreements often spell out those duties.

Flow diagram: a defense or federal client shares CUI with its law firm under an agreement with handling terms (32 CFR 2002.16(a)(6)); the firm becomes an authorized holder that must take reasonable precautions against unauthorized disclosure (32 CFR 2002.14(c)) and apply NIST SP 800-171 where the agreement requires it (32 CFR 2002.14(h)(2)).

Under 32 CFR 2002.16(a)(6), agreements with non-executive branch entities must include provisions that “Non-executive branch entities must handle CUI in accordance with the Order, this part, and the CUI Registry” and that the entity “must report any non-compliance with handling requirements to the disseminating agency.” Section 2002.14(c) sets the baseline: “Authorized holders must take reasonable precautions to guard against unauthorized disclosure of CUI.”

What security requirements apply to CUI on a law firm’s systems?

For CUI on systems outside the federal government, the federal CUI rule points to NIST SP 800-171, the NIST security standard for non-federal systems. The rule says NIST SP 800-171 “defines the requirements necessary to protect CUI Basic on non-Federal information systems” and that agencies must use it when setting requirements for those systems (32 CFR 2002.14(h)(2)). A firm’s specific obligations are those in its agreements with the client.

For a firm, the practical controls are the ones clients ask about: encryption of CUI in transit and at rest, access limited to authorized people, multi-factor authentication, activity logs, and incident reporting on the client’s timeline. The ABA’s baseline applies too. Formal Opinion 477R says a lawyer “may be required to take special security precautions… when required by an agreement with the client or by law, or when the nature of the information requires a higher degree of security.”

Which CUI requirements affect email and file sharing?

The CUI requirements that affect a firm’s email and file sharing are reasonable precautions against disclosure, handling under the terms of the firm’s agreement, NIST SP 800-171 where an agreement requires it, and incident reporting on the client’s timeline. Which ones apply depends on the terms under which the firm received the information.

RequirementCitationApplies to a firm whenHow PreVeil supports it
Reasonable precautions against unauthorized disclosure32 CFR 2002.14(c)The firm is an authorized holder under an agreementEnd-to-end encryption of message contents, attachments and files
Handle CUI per the Order, Part 2002 and the CUI Registry32 CFR 2002.16(a)(6)(i)Included in the firm’s agreementEncrypted email and files; access limited to key holders
NIST SP 800-171 for non-federal systems32 CFR 2002.14(h)(2)Required by agreementSupports encryption and logging controls for email and files
Report non-compliance and incidents32 CFR 2002.16(a)(6)(iii); client termsIncluded in the firm’s agreementActivity logs for the firm’s investigation (Business plan)
Special security precautionsABA Op. 477R; Rule 1.6(c)Client agreement, law or sensitivity requiresFIPS 140-3 validated cryptographic modules

How does PreVeil protect CUI in a law firm’s email and files?

PreVeil encrypts message contents, attachments and files end to end. PreVeil Mail works inside Outlook, Gmail and Apple Mail, and PreVeil Drive syncs files in Explorer and Finder. Defense contractors use PreVeil to protect CUI, and the same protection applies to a law firm’s client files. Clients and co-counsel read and reply for free from their browser, and their replies stay encrypted.

PreVeil cannot access or decrypt customer data, because the encryption keys stay on users’ devices. PreVeil uses FIPS 140-3 validated cryptographic modules, and the Business plan includes an admin console with activity logs. PreVeil supports specific controls; the firm’s agreements, policies, training and incident response remain the firm’s.

CUI is one of several obligations regulated clients pass to their firms. The guide to law firm security obligations for regulated clients covers HIPAA, NYDFS and outside counsel guidelines as well, and PreVeil for law firms covers the product.

CUI compliance questions law firms ask

Is CUI the same as classified information?

No. CUI is unclassified information that a law, regulation or government-wide policy requires or permits agencies to protect with safeguarding or dissemination controls (32 CFR 2002.4).

Do defense and federal clients pass CUI obligations to their law firms?

Yes. Defense and federal clients often share CUI with outside counsel, and their contracts may require the firm to protect it. The firm’s specific obligations are set by its agreements with the client.

What standard applies to CUI on a law firm’s systems?

The CUI rule points to NIST SP 800-171 for CUI Basic on non-federal systems (32 CFR 2002.14(h)(2)). The firm’s specific obligations are set by its agreements with the client.

How would a law firm know it holds CUI?

A law firm usually knows it holds CUI from CUI markings on documents or from the client’s handling instructions. Government contract, bid protest, export control and technical data matters are common sources.

Can PreVeil read CUI a firm stores or sends?

No. PreVeil cannot access or decrypt message contents, attachments or files, because the encryption keys stay on users’ devices.

Sources

Talk to PreVeil about CUI in your client files

If your firm handles government contracts or other CUI for clients, a demo shows how PreVeil protects it in email and files. Request a demo