FCI vs CUI Explained (Avoid Costly CMMC Mistakes)

Quick answer: FCI (Federal Contract Information) is non-public information generated under a government contract and requires basic safeguards under FAR 52.204-21. CUI (Controlled Unclassified Information) carries stricter handling requirements under DFARS 252.204-7012 and NIST SP 800-171. Mixing them up can put you on the wrong CMMC compliance path entirely.

If you work with the Department of War, you’ve probably heard FCI and CUI used almost interchangeably. They’re not the same thing. Confusing the two can send you down the wrong compliance path, either leaving sensitive data under-protected or spending thousands of dollars building security controls you don’t actually need. Our team at HRCT put together a short video breaking this down:

This post walks through what each term means, what rules apply, and how to figure out which one your environment actually involves.

What Is Federal Contract Information (FCI)?

FCI is non-public information the government provides or generates under a contract for a product or service. Think of it as the behind-the-scenes paperwork of a government project.

Common examples include:

  • Contract documents and statements of work
  • Technical details not posted publicly
  • Project schedules and deliverables
  • Internal communication about the work

FCI does not include information already available to the public, and it does not cover basic payment processing details. A simple way to picture it: FCI is the work happening inside your office that isn’t meant for public eyes. You wouldn’t leave it on a table at a coffee shop, but it doesn’t require a heavily controlled environment either.

What Is Controlled Unclassified Information (CUI)?

CUI is a step up. It’s still not classified information, but the government has determined it must be handled with specific safeguards or sharing rules because of laws, regulations, or government-wide policy.

Categories of CUI include:

  • Controlled Technical Information (CTI)
  • Export controlled data
  • Critical infrastructure information
  • Other categories listed in the official CUI Registry

A useful analogy: CUI is like a folder stamped “Confidential for Handling.” The contents are still part of your normal business workflow, but there are defined rules for how the information must be protected and who it can be shared with. The bar is higher, and it’s set by policy, not just common sense.

What Rules Apply to Each Type of Data?

Getting this distinction right matters because FCI and CUI point to different regulatory requirements.

For FCI: The baseline is FAR 52.204-21, which outlines the minimum safeguarding controls contractors must apply to systems that process or store FCI. These are foundational protections, not an extensive security overhaul.

For CUI: The requirements jump significantly. For DoD contractors, DFARS 252.204-7012 ties the protection of covered defense information to the CUI program. It requires contractors to implement NIST SP 800-171 across any systems that store, process, or transmit CUI. That’s 110 security controls across 14 families.

This is why correctly identifying CUI matters so much. It directly drives scope, effort, and cost.

How Does This Connect to CMMC Levels?

The Cybersecurity Maturity Model Certification (CMMC) framework maps directly onto this distinction.

  • CMMC Level 1 aligns to safeguarding FCI through the 17 basic controls outlined in FAR 52.204-21. Organizations can self-assess at this level.
  • CMMC Level 2 focuses on protecting CUI and aligns to the full NIST SP 800-171 control set. This level requires a third-party audit and is where most DoD contractors will need to be to bid and win contracts.

Knowing which CMMC level applies to your business starts with knowing what type of data you actually handle.

How Do You Figure Out Which One You Have?

Start with your contract language. CUI is often marked directly in documentation, and it can also be identified by category through the CUI Registry. If your contract or prime contractor is telling you that CUI is involved, treat that as a clear signal your environment needs to meet the higher standard.

If you’re unsure, that’s not uncommon. Many contractors don’t have a clear picture of what data flows through their systems until someone walks them through it.

Get the Right Answer Before You Build the Wrong Plan

Misidentifying your data type leads to one of two problems: under-protecting information you’re responsible for, or overbuilding a compliance program for requirements that don’t apply to you. Neither outcome is good.

The HRCT team helps DoD contractors and subcontractors figure out exactly what data they handle, what compliance requirements actually apply, and what a right-sized plan looks like for their contracts.

Contact us here to start the conversation with no pressure and no guesswork!

Frequently Asked Questions About CUI vs FCI

What is the main difference between CUI and FCI?

FCI is non-public information generated under a government contract and requires basic safeguards under FAR 52.204-21. CUI is a broader category of sensitive information that is not classified but must be handled according to specific rules defined by law or government policy. CUI requires more rigorous controls, typically under NIST SP 800-171.

Does all FCI qualify as CUI?

No. FCI and CUI are separate categories. All CUI is sensitive, but not all FCI meets the threshold for CUI. FCI requires basic protections; CUI requires a higher, policy-driven standard of security.

What compliance level does CUI trigger under CMMC?

CUI triggers CMMC Level 2 compliance, which requires contractors to implement all 110 controls outlined in NIST SP 800-171 and undergo a third-party audit. CMMC Level 1 applies to contractors handling FCI only.

How do I know if my contract involves CUI?

Check the contract language directly. CUI is often labeled within documentation, and categories are listed in the government’s official CUI Registry. If your prime contractor indicates CUI is present, that’s a strong signal your environment must meet Level 2 requirements.

What happens if I don’t correctly identify CUI?

Misidentifying CUI can put you on the wrong compliance path. Under-protecting CUI can result in contract violations, loss of eligibility to bid, or security incidents. Overbuilding controls for FCI that is actually CUI wastes time and money on requirements that don’t apply to your contract.