Skip to main content

CMMC Pause: What DoW & Primes Still Require

background

CUI vs. FCI: What’s the Difference Between Federal Contract Information and Controlled Unclassified Information?

  • cui
  • CUI vs. FCI: What’s the Difference Between Federal Contract Information and Controlled Unclassified Information?

If you're working on a defense contract, you're handling sensitive government information — but not all of it is treated the same way. 

Some of it is Federal Contract Information (FCI). Some of it may be Controlled Unclassified Information (CUI)

Knowing which is which determines your required CMMC level, your compliance scope, and ultimately the cost and effort involved for you to maintain your contract eligibility.

What is Federal Contract Information (FCI)?

FCI is information provided by or generated for the government under a contract that isn't intended for public release. It's sensitive in the sense that it's not meant to be shared publicly, but it doesn't meet the legal threshold that makes something CUI.

Common examples of FCI include:

  • Contract modification letters
  • Meeting schedules with a government program manager
  • Internal project timelines tied to a federal contract

FCI is the baseline. If you have any federal contract at all, you're almost certainly handling FCI, even if you never touch CUI.

What is Controlled Unclassified Information (CUI)?

CUI is government information that's sensitive enough to require safeguarding or dissemination controls under federal law, regulation, or government-wide policy, even though it isn't classified. It includes things like controlled technical data, export-controlled drawings, vulnerability scan results, and personnel records containing Social Security numbers.

Unlike FCI, CUI's protection requirement comes from a specific external authority, not just the fact that it was generated under a federal contract. That distinction is what separates the two categories.

CUI vs. FCI comparison

The simplest way to think about it: every contractor working with the federal government handles FCI. Only some handle CUI, and which one applies to you depends on whether a specific law, regulation, or policy requires safeguarding that particular information.

FCI CUI
What it is Non-public information generated under a federal contract Information requiring safeguarding under a specific federal law, regulation, or policy
Legal basis The contract itself 32 CFR Part 2002 and the CUI Registry
Examples Contract modification letters, meeting schedules, internal project timelines Controlled technical data, export-controlled drawings, personnel records with SSNs
Who handles it Nearly every federal contractor Contractors working with specific categories of sensitive information

How this affects your required CMMC level

Whether you handle FCI only, or FCI and CUI, is the biggest factor in which CMMC level applies to your organization.

  • If you only handle FCI, you're likely subject to CMMC Level 1, which requires 15 basic security practices and allows self-assessment.
  • If you handle CUI, you're likely subject to CMMC Level 2, which requires all 110 security controls in NIST SP 800-171 (currently Revision 2), a self-assessment in SPRS, and annual affirmations.

That's a significant jump in scope, cost, and effort. Misclassifying CUI as FCI risks building a compliance program that doesn't meet your actual contractual requirements. Misclassifying FCI as CUI means spending time and resources on controls you may not be required to have yet.

How does Security Protection Data (SPD) fit in?

As you scope your CMMC assessment, you'll likely also run into the term Security Protection Data (SPD). 

Per the CMMC Level 2 Scoping Guide and 32 CFR 170.19, SPD is data stored or processed by Security Protection Assets, the tools that protect your CUI environment, like firewalls, SIEM platforms, and identity and multi-factor authentication services. Examples include configuration data and log files generated by those tools. SPD isn't CUI and it isn't FCI. It doesn't come from your contract or from a CUI Registry category. It's generated by the security infrastructure you've built to protect CUI in the first place.

Assets that handle SPD are part of your CMMC Level 2 assessment scope, right alongside the assets that handle CUI directly. So while FCI and CUI determine which CMMC level applies to you, SPD affects exactly which assets get pulled into your assessment once you know you're at Level 2.

The FCI and CUI hierarchy

FCI and CUI aren't competing categories, they're a hierarchy. Every contractor handling CUI is also handling FCI, but not every contractor handling FCI is handling CUI. Getting this distinction right at the outset is what allows you to scope your CMMC compliance program accurately, rather than over-building for FCI-only work or under-building for a contract that actually involves CUI.

Proposed changes under the FAR Overhaul

The proposed FAR Overhaul (FAR Case 2026-001, June 2026) would rename Federal Contract Information to "Covered Federal Information". Future contracts may use the term "Covered Federal Information" rather than "FCI" in their clauses and forms. The public comment period for the proposed FAR Overhaul closed July 23, 2026.

Loading...