FCI vs CUI: Which One Does Your Contract Involve?
FCI and CUI are the two kinds of non-public information you handle on a federal contract, and the difference decides how much security you owe. FCI is the broad category and triggers 15 controls at CMMC Level 1. CUI is the sensitive subset and triggers all 110 at Level 2. Here is how to tell which is which, and who gets to decide.
The difference in one sentence
Everything non-public you touch on a federal contract is at least FCI. A smaller, more sensitive slice of it is CUI. FCI gets you the baseline; CUI gets you the full standard. Get the line between them right and your whole CMMC scope follows from it. Get it wrong and you either underprotect regulated data or overspend guarding data that never needed it.
FCI, defined
Federal Contract Information is the wider of the two. The FAR, at 48 CFR 52.204-21, defines it as information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service, excluding information the Government has already made public and simple transactional data like the details needed to process a payment.
In plain terms: if it came to you because of the contract, it is not public, and it is not just a routine invoice, it is FCI. A non-public statement of work, delivery schedules, internal contract correspondence, and org charts built for the engagement all qualify.
Two things to know. FCI is never marked. There is no "FCI" stamp; it is defined by what it is, not by a label. And handling it obligates you to the 15 basic safeguarding requirements of FAR 52.204-21, which is CMMC Level 1. Almost every federal contractor clears this bar, because almost every contract generates FCI.
CUI, defined
Controlled Unclassified Information is the narrower, more sensitive category, and it predates CMMC by years. Executive Order 13556 created the CUI Program in 2010, the National Archives (NARA) runs it, and its rule at 32 CFR Part 2002 defines CUI as information the Government creates or possesses, or that an entity creates or possesses for the Government, that a law, regulation, or Government-wide policy requires to be safeguarded.
The operative word is requires. CUI is not "sensitive information" in a loose sense. It is information that a specific authority, listed in the NARA CUI Registry, obligates you to protect. Controlled technical information such as engineering drawings and specifications, export-controlled data, and covered defense information are common examples.
Two things to know here too. CUI is marked, by the Government, with banner and portion markings that an assessor will look for. And handling it obligates you to all 110 controls of NIST SP 800-171, which is CMMC Level 2.
How the two relate
Here is the cleanest way to hold it: CUI is a subset of FCI. In NARA's own words, non-federal systems that handle FCI that does not also qualify as CUI must follow, at a minimum, the FAR 52.204-21 baseline. That phrase, "does not also qualify," is the entire relationship. CUI is FCI that additionally meets a safeguarding requirement written into law or policy.
What decides which you have is the nature of the information, not the size or type of the contract. A small task order can carry CUI. A large one might carry nothing but FCI. The trigger is the data, and only the data.
How to tell which one is on your systems
Work it in order:
Is the information public, or simple transactional data? If yes, it is neither. If no, it is at least FCI.
Does it fall into a category in the NARA CUI Registry, or did it arrive marked as CUI? If yes, it is CUI, and you are at Level 2.
Unsure, or the data looks sensitive but arrived unmarked? Ask the contracting officer. Do not self-designate CUI, and do not assume that unmarked means unregulated.
The parts experienced teams still get wrong
Three edge cases separate a clean compliance program from a costly one.
Unmarked CUI is your problem too. Agencies mismark and undermark. If you receive information that looks like it belongs in a CUI category but carries no marking, the safe move is to protect it and flag it to the contracting officer for a determination. The proposed FAR CUI rule would formalize this with an eight-hour notification window; even before it lands, treating suspected CUI as CUI until told otherwise is the defensible posture.
Not all CUI is handled the same. 32 CFR Part 2002 splits CUI into CUI Basic and CUI Specified. Basic follows the uniform safeguarding baseline. Specified carries extra handling rules written into the underlying authority, with export-controlled data the classic case. Two documents can both be CUI and still demand different controls.
The enclave is your cost lever. You do not have to bring your whole company to Level 2. Containing all CUI inside a defined enclave keeps the 110-control obligation, and the assessment, scoped to that environment rather than every laptop in the building. It works only when the boundary is real in daily practice.
Why this is the highest-leverage decision you'll make
The gap between the two standards is 15 controls versus 110. That is the difference between a self-assessment you can run in-house and a full NIST 800-171 program under DFARS 252.204-7012, with an SPRS score and, eventually, third-party certification.
Which is why getting the line wrong is expensive in both directions. Treat CUI as FCI and you have underprotected regulated information, which is a compliance violation and, because your SPRS score is a statement to the Government, potential False Claims Act exposure. Treat FCI as CUI and you have spent months and real money certifying an environment that never needed it. The classification is not paperwork. It sets everything downstream.
One shift worth watching: the FAR Overhaul's proposed CUI rule would retire the term "Federal Contract Information" itself, folding it into a broader "covered Federal information." The concepts here hold. The vocabulary may not.
Key Takeaways
FCI is the broad category: non-public information provided or generated under a federal contract. It triggers 15 controls (FAR 52.204-21) at CMMC Level 1, and almost every contractor has it.
CUI is the sensitive subset: information a law, regulation, or policy requires you to safeguard, listed in the NARA CUI Registry. It triggers all 110 NIST 800-171 controls at Level 2.
CUI is FCI that also meets a safeguarding requirement. The nature of the data decides, not the contract.
FCI is never marked; CUI is marked by the Government. If sensitive data arrives unmarked, protect it and ask the contracting officer.
The FCI/CUI line sets your entire compliance scope. Getting it wrong means either a violation or wasted spend, and a CUI enclave keeps the higher bar contained.
FAQ
What is the difference between FCI and CUI? FCI is the broad category of non-public information provided or generated under a federal contract; it triggers the 15 basic safeguarding requirements of FAR 52.204-21, which is CMMC Level 1. CUI is a sensitive subset that a law, regulation, or Government-wide policy requires you to safeguard; it triggers all 110 controls of NIST SP 800-171, which is CMMC Level 2.
Is all FCI also CUI? No. In the contract context all CUI is also FCI, but most FCI is not CUI. CUI is the smaller, regulated subset, defined by a specific safeguarding authority listed in the NARA CUI Registry. The majority of the non-public information on an ordinary contract is FCI and nothing more.
Who decides whether information is CUI? The Government does. The agency or data owner identifies CUI and marks it with banner and portion markings. Contractors do not self-designate information as CUI. If information looks regulated but arrived unmarked, the right move is to protect it and ask the contracting officer for a determination.
How do I know if I have CUI? Check two things: whether the information arrived marked as CUI, and whether it falls into a category in the NARA CUI Registry. If either is true, you are handling CUI and owe the full NIST 800-171 standard. If it is non-public contract information but not in a CUI category, it is FCI.
Does FCI require NIST 800-171? No. FCI requires only the 15 basic safeguarding requirements in FAR 52.204-21, which map to CMMC Level 1. The full 110 controls of NIST SP 800-171, and CMMC Level 2, apply only when you handle CUI.
Getting the FCI/CUI line right is the first decision in a compliance program, and it rarely stays still. The categories, the markings, and the rules that reference them all shift with each new regulation. Federal Cyber Brief tracks what is being bought, who can bid, and what is changing across federal IT and cyber contracting, and sends the parts that matter to your inbox each week. Primary sources only. No noise.
SOURCES
FAR 4.1901 and FAR 52.204-21 (acquisition.gov / 48 CFR). The definition of Federal Contract Information and the 15 basic safeguarding requirements that apply to systems handling it.
Executive Order 13556, Controlled Unclassified Information (November 2010). Established the Government-wide CUI Program and designated the National Archives and Records Administration as Executive Agent.
32 CFR Part 2002 (eCFR). The CUI definition at 2002.4(h); the division of CUI into CUI Basic and CUI Specified; NIST SP 800-171 as the safeguarding standard for CUI in nonfederal systems.
NARA CUI Registry (archives.gov/cui). The authoritative list of CUI categories and the safeguarding and dissemination authorities behind each.
NARA Information Security Oversight Office (ISOO), CUI Program guidance. Confirms that non-federal systems handling FCI that does not also qualify as CUI must meet, at a minimum, the FAR 52.204-21 baseline.
DoD Instruction 5200.48 and the DoD CUI Marking Guide. CUI identification, marking, and handling requirements for defense contractors.
