Skip to main content

Research

CUI vs. FCI

FCI and CUI are not interchangeable. The difference affects contract clauses, safeguarding controls, CMMC level, subcontractor flowdowns, incident reporting, and how a contractor scopes its cybersecurity program.

Last reviewed: June 29, 2026

The short distinction

Federal Contract Information (FCI) is information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service to the government. It does not include information provided by the government to the public or simple transactional information necessary to process payments.

Controlled Unclassified Information (CUI) is unclassified information that the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, when a law, regulation, or government-wide policy requires or permits safeguarding or dissemination controls.

In practical terms, FCI is the baseline nonpublic contract information category. CUI is a more controlled category tied to legal or policy-based safeguarding or dissemination requirements.

Why the distinction matters

The FCI/CUI distinction affects:

  • which contract clauses apply;
  • which cybersecurity controls are required;
  • whether NIST SP 800-171 applies;
  • whether DFARS 252.204-7012 applies;
  • whether CMMC Level 1 or Level 2 is relevant;
  • how systems are scoped;
  • what subcontractors must receive as flowdowns;
  • what incident-reporting obligations may exist; and
  • what evidence the contractor must maintain.

A contractor that treats all information as ordinary business data may underprotect CUI. A contractor that treats every piece of nonpublic contract information as CUI may over-scope systems and create unnecessary cost. The goal is accurate classification and practical safeguarding.

FAR 52.204-21 and FCI

FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, applies when FCI resides in or transits through covered contractor information systems. It establishes basic safeguarding requirements such as limiting access, verifying controls on connections, controlling public posting, identifying users and devices, sanitizing media, limiting physical access, protecting against malicious code, updating malicious-code protections, and other baseline safeguards.

For many non-DoD contractors, this is the starting point for contract cybersecurity. It does not turn FCI into CUI. It means nonpublic federal contract information must receive basic safeguarding when it is on contractor systems.

DFARS 252.204-7012, covered defense information, and CUI

DFARS 252.204-7012 is central for DoD contractors handling covered defense information. It requires adequate security for covered contractor information systems and incorporates NIST SP 800-171 for protecting covered defense information in nonfederal systems. It also includes cyber incident reporting, malicious software submission, media preservation, and support for DoD damage assessment.

Covered defense information is tied to controlled technical information and other CUI categories when such information is provided to the contractor by or on behalf of DoD, or collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of contract performance.

NIST SP 800-171

NIST SP 800-171 provides security requirements for protecting the confidentiality of CUI in nonfederal systems and organizations. It is not a general-purpose checklist for every contractor system. It matters when CUI is in scope and when the contract or applicable requirement points to it.

Contractors should identify which systems process, store, or transmit CUI; which users and administrators can access those systems; which external services support those systems; and which requirements apply to the scoped environment.

CMMC Level 1 vs. Level 2

CMMC is designed to assess contractor implementation of required cybersecurity protections for FCI and CUI in DoD contracts.

  • CMMC Level 1 is associated with safeguarding FCI using the Level 1 requirements.
  • CMMC Level 2 is associated with protection of CUI and is based on NIST SP 800-171 requirements under the CMMC program.

The required CMMC level depends on the solicitation or contract. Contractors should not claim that CMMC applies to every contract in the same way. They should check whether the DoD solicitation or contract identifies a CMMC level and whether FCI or CUI will be processed, stored, or transmitted on contractor information systems.

Markings matter, but they are not the whole analysis

CUI should be marked under the CUI Program when it is designated and shared. Markings help authorized holders identify handling requirements. But contractors should not rely blindly on the absence of markings. Some contracts, attachments, technical documents, data exchanges, or agency communications may contain information that requires protection even when markings are missing, incomplete, inconsistent, or delayed.

If a contractor receives information that appears sensitive, export-controlled, privacy-protected, procurement-sensitive, proprietary, or otherwise restricted, it should escalate rather than assume it is safe to treat as ordinary information.

Common contractor mistakes

Common mistakes include:

  • treating FCI and CUI as synonyms;
  • assuming “unclassified” means “uncontrolled”;
  • waiting for perfect markings before protecting obviously sensitive information;
  • putting CUI into general corporate systems without scoping review;
  • using cloud or AI tools that are not approved for the data;
  • failing to flow down requirements to subcontractors;
  • submitting unsupported self-assessment scores;
  • assuming CMMC replaces DFARS 7012 incident reporting;
  • ignoring CUI created by the contractor during performance; and
  • relying only on IT to classify contract data.

Examples

A purchase order, statement of work, or technical email that is nonpublic and generated for contract performance may be FCI even if it is not CUI.

A controlled technical drawing, export-controlled technical data, sensitive law-enforcement information, protected health information provided for an agency mission, or certain vulnerability information may be CUI if the relevant law, regulation, or government-wide policy requires or permits safeguarding or dissemination controls.

A subcontractor that receives FCI may need FAR 52.204-21 flowdown. A subcontractor that receives covered defense information under a DoD contract may need DFARS 252.204-7012 flowdown and NIST SP 800-171 implementation.

Educational content only. This page provides general legal information for educational purposes. It does not constitute legal advice and does not create an attorney-client relationship. Contractors should consult qualified legal counsel for contract-specific CUI and FCI obligations.