# Federal Contract Information (FCI) | Secureframe

> What counts as FCI, how FCI differs from CUI, the 15 FAR 52.204-21 safeguarding requirements, and how to identify FCI in your environment.

canonical: https://secureframe.com/glossary/federal-contract-information

Federal Contract Information is non-public information the government provides to a contractor, or that a contractor generates for the government under a contract. It is not CUI. It does not carry a CUI category marking. But it triggers FAR 52.204-21 safeguarding requirements, which CMMC Level 1 adopts as its 15 practices. If your contract involves only FCI (and no CUI), you need CMMC Level 1, not Level 2.

### What Counts as FCI

Government-provided technical specifications. Draft deliverables a contractor creates for the government. Pricing data submitted to the contracting officer. Internal contractor emails discussing a government project. None of this is made public, and none of it is simple transactional data like payment processing.

### What Is Not FCI

Information the government has already put on a public website. Invoice and payment records needed to process the contract financially. Press releases. Public source selection documents after award. These fall outside FCI and get no special safeguarding requirement.

### FCI vs CUI

FCI is the broad bucket of non-public contract information. CUI is a subset that a law, regulation, or government-wide policy specifically flagged for safeguarding. CTI (military/space technical data) is a CUI category. Export-controlled data is a CUI category. FCI that is not categorized as CUI still gets protection, but it's the lighter FAR 52.204-21 level.

### CMMC Level 1 Requirements for FCI

FAR 52.204-21 lists 15 basic safeguarding requirements. CMMC Level 1 uses exactly those 15. You self-assess annually, submit affirmation in SPRS, and a senior company official signs off. Common practices include limited access to authorized users, MFA for remote access, sanitizing media before disposal, and updating malicious code protection on endpoints.

### Identifying FCI in Your Environment

- **Review each DoD or civilian federal contract and identify w**hich deliverables or shared data are non-public.
- **Map the email, file share**, and collaboration paths where that information flows.
- **If contract language is unclear on whether specific data is FCI **or CUI, ask the contracting officer. Do not guess upward (CUI) or downward (not FCI).
- **Document the FCI** boundary in your SSP so it's clear what scope is Level 1 vs Level 2.
