What is the difference between FCI and CUI?
Federal Contract Information (FCI) is any non-public information provided by or generated for the government under a contract; it needs the 15 basic safeguarding requirements and CMMC Level 1. Controlled Unclassified Information (CUI) is a narrower category that a law, regulation or government-wide policy requires to be safeguarded; it needs the 110 requirements of NIST SP 800-171 Rev 2 and CMMC Level 2.
The two definitions
FCI is information, not intended for public release, that is provided by or generated for the government under a contract to develop or deliver a product or service. It excludes information the government makes public and simple transactional information, such as what is needed to process payments. Almost every federal contractor that receives anything non-public has FCI.
CUI is information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation or government-wide policy requires or permits an agency to handle with safeguarding or dissemination controls. The definition comes from 32 CFR 2002.4(h), and the CUI Registry lists the approved categories.
How they relate
Think of CUI as a subset of the information you might hold under a contract. All CUI you receive or create under a federal contract is also FCI, but most FCI is not CUI. A purchase order, a delivery schedule or a non-public statement of work may be FCI. Controlled technical information, export-controlled drawings or marked engineering data are typically CUI.
What each one requires
- FCI: the 15 basic safeguarding requirements in FAR 52.204-21, now carried in FAR Part 40 under the FAR Overhaul deviation.
- FCI: CMMC Level 1 (Self), an annual self-assessment where every requirement must be met, no POA&M allowed, with results and an affirmation in SPRS.
- CUI: DFARS 252.204-7012, including the 110 requirements of NIST SP 800-171 Rev 2, cloud requirements and 72-hour incident reporting.
- CUI: CMMC Level 2, scored out of 110 points, with a System Security Plan, limited POA&M use and an annual affirmation by a senior official.
Where CMMC stands in October 2026
The Department of War suspended the CMMC Phase 2 transition on July 13, 2026, and DFARS Class Deviation 2026-O0025 carries that into contracting. During the suspension, requiring activities may only call for CMMC Level 1 (Self) or Level 2 (Self), and DFARS 252.204-7012 remains in effect. The FCI and CUI distinction is unchanged: it still decides which level, and which controls, your contracts require.
How to tell which you have
Read the contract first. A clause requiring CMMC Level 2 or DFARS 252.204-7012, CUI banner markings, or contract language identifying controlled technical data all point to CUI. If the contract has only FAR basic safeguarding and nothing is marked, you are likely dealing with FCI only. When in doubt, ask the contracting officer or your prime contractor in writing, and treat ambiguous data as CUI until you have an answer.
Subcontractors need the same clarity. Under the CMMC contract clause, primes must flow the correct CMMC level down to subcontracts and make sure each subcontractor has a current affirmation in SPRS before award. If a prime sends you only FCI, Level 1 applies; if it shares CUI, expect a Level 2 requirement in your subcontract.
Common follow-up questions
If I only have FCI, do I need NIST SP 800-171?
No. FCI requires the 15 basic safeguarding requirements and CMMC Level 1. NIST SP 800-171 and CMMC Level 2 apply when your contract involves CUI. Many companies still use the Level 1 controls as a starting point toward Level 2 if they expect CUI work.
Can I keep FCI and CUI in separate systems?
Yes. Many contractors build a smaller, tightly controlled enclave for CUI and keep FCI and general business data in their main environment. That shrinks the scope of the Level 2 assessment, but the boundary has to be documented and enforced.
Does the Phase 2 suspension mean I can ignore CUI rules?
No. The suspension removed third-party C3PAO assessment requirements from new solicitations during the review. DFARS 252.204-7012 and NIST SP 800-171 Rev 2 still apply whenever your contract involves CUI, and Level 2 self-assessments are still required.
LAN Service Group's ISSO-led CMMC practice helps defense suppliers sort FCI from CUI in their contracts, set the right assessment boundary and implement Level 1 or Level 2 controls.
Talk to LAN Service Group (888) 281-7243Sources
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems
- 32 CFR Part 2002, Controlled Unclassified Information (eCFR)
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS Class Deviation 2026-O0025, Revision 3 (DFARS Part 240, incl. 252.240-7997 and 252.204-7021)