Skip to content
    August 16, 2026| Top Floor Team| 9 min read

    FCI vs CUI: How to Tell What Your Company Actually Handles

    Federal Contract Information (FCI) is information not intended for public release, provided by or generated for the government under a contract to develop or deliver a product or service, excluding information the government provides to the public. If you hold a federal contract, you almost certainly hold FCI. Controlled Unclassified Information (CUI) is the narrower category that triggers CMMC Level 2: information that a law, regulation, or government-wide policy requires to be safeguarded or disseminated under controls, catalogued by category in the National Archives CUI Registry. The reliable way to tell which you hold is not to look for markings, because markings are frequently missing. It is to ask your contracting officer or prime in writing whether the contract involves CUI, and then to audit what actually arrives.

    The distinction decides your CMMC level, your assessment scope, and most of your cost. The rest of this is the two definitions in practical terms, the identification test, and the scoping trap that one misrouted email can spring.

    Key takeaways

    • If you hold a federal contract, you almost certainly hold FCI: information not intended for public release, provided by or generated for the government under a contract to develop or deliver a product or service.
    • CUI is the narrower category that triggers Level 2. It is not a judgment call about sensitivity; it is a pointer to a law, regulation, or government-wide policy, catalogued in the National Archives CUI Registry.
    • Do not rely on markings. They are frequently missing, and an absent marking does not make the information something other than CUI.
    • Ask your contracting officer or prime in writing whether the contract involves CUI and which categories, and keep the answer. The determination belongs to the government.
    • Scope follows where the data actually goes. One CUI drawing routed through normal mail and a shared drive can pull the mail system, file server, endpoint and backup into the assessment boundary.

    FCI, in the terms that matter to a small contractor

    FCI is defined broadly on purpose. The test is three parts: it is not intended for public release, it was provided by or generated for the government, and it exists under a contract to develop or deliver a product or service. Press releases and published solicitations are excluded because the government put them out itself.

    What that catches in practice is mundane: unpublished statements of work, delivery schedules, contract correspondence, pricing you submitted, and internal deliverable drafts. This is why we tell contractors that the FCI question is usually settled before it is asked. If you have a federal contract and any of it is not on a public website, you have FCI.

    FCI obliges the 15 basic safeguarding requirements in FAR 52.204-21, which is CMMC Level 1. That is a real obligation and a small one.

    CUI, and why the definition is harder to apply than to state

    CUI is information the government creates or possesses, or that an entity creates or possesses for the government, that a law, regulation, or government-wide policy requires to be safeguarded or disseminated under controls. The operative words are "law, regulation, or government-wide policy": CUI is not a judgment call about sensitivity, it is a pointer to an authority that already exists.

    The National Archives maintains the CUI Registry, which organizes those authorities into categories. The ones defense subcontractors meet most often are Controlled Technical Information, export-controlled data under ITAR or EAR, and the various procurement and acquisition categories. Controlled Technical Information is the big one for manufacturing: technical data with military or space application, which in a machine shop means drawings, models, specifications, process instructions, and test results.

    Two clarifications that save arguments. CUI is not classified information; it sits below classification entirely. And CUI is not a DoD invention. It is a government-wide program under 32 CFR Part 2002, which is why the FAR Council is now proposing a government-wide CUI safeguarding rule that would reach civilian-agency contractors too. The site's radar entry on that proposed rule has the citation.

    The identification test that works in the real world

    The textbook answer is to look for CUI markings: a banner, a designation indicator naming the office that made the determination, and a category marking. Use that when it is there.

    When it is not there, and often it is not, work the problem in this order.

    Ask, in writing, and keep the answer. Send your contracting officer or your prime's contracts lead one question: does this contract involve CUI, and if so which categories? A written answer is both an operational input and a piece of evidence. The determination belongs to the government, not to you, and asking for it is normal.

    Read the contract for the clause set. DFARS 252.204-7012 in a contract is a strong signal that the department expects covered defense information to be involved. DFARS 252.204-7021 names a required CMMC level directly.

    Inventory what actually arrives. Ask what a month of inbound files looks like: drawings, specifications, test data, source-controlled documents. If you receive engineering data for a defense end item, treat the CUI question as live no matter how the file is labeled.

    Treat unmarked-but-obvious data as CUI until told otherwise, and say so. If you receive an unmarked drawing for a weapons-system component, the sane operational posture is to protect it and raise the marking gap with the sender. What you should not do is decide unilaterally that missing markings mean the data is not CUI. That reasoning has never protected anyone.

    The one email that expands your scope

    Here is the failure mode we see most often, and it has nothing to do with definitions.

    An engineer receives a CUI-marked drawing on their normal work email, saves it to the shared drive so a colleague can quote it, and attaches it to a message to a supplier. Nobody did anything malicious. But the assessment boundary now arguably includes the mail system, the file server, the endpoint, the backup, and the supplier relationship, because CUI is scoped by where it goes rather than by where you meant it to go.

    This is why enclave design and, more importantly, a simple written rule about where CUI is allowed to land, is worth more than most tooling. The technical controls are the easy part. The routing habit is the part that determines how much of your company sits inside the boundary.

    It is also why the first genuinely useful CMMC deliverable is usually a data-flow diagram: where CUI enters, who touches it, where it rests, and where it leaves. Most organizations discover at least one path they did not know about.

    What changes the day the answer turns out to be CUI

    It is worth being concrete about the size of the step, because the two categories sound adjacent and the obligations are not.

    The requirement count goes from 15 to 110. FCI means the basic safeguarding requirements of FAR 52.204-21. CUI means the full NIST SP 800-171 Rev 2 set: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. That is a program rather than a checklist, and the detail is in what CMMC level you need.

    A boundary decision arrives. Once CUI is in play you have to decide where it is allowed to live. Confining it to a segmented environment keeps the rest of the company out of scope; letting it flow through general-purpose mail and file shares puts everything in. That decision drives more of the eventual cost than any tooling choice, and it is much cheaper to make early.

    Incident reporting attaches. DFARS 252.204-7012 requires a cyber incident report to the Department within 72 hours of discovery, with media preservation and malicious software submission alongside it. That is an operational commitment with a clock, and most organizations discover on the day of an incident whether they have a workable process or a paragraph in a policy.

    Documentation stops being optional. The System Security Plan becomes the artifact everything else references, and under 32 CFR 170.21 it is one of the requirements that can never be deferred to a plan of action. The POA&M rules cover which items can be.

    When this does not apply to you

    If you are a commercial supplier selling catalog items to a defense prime with no technical data exchange, you may well hold FCI and no CUI, and the right project is Level 1. Fifteen requirements is not a program.

    If your only federal exposure is a civilian-agency contract with no CUI clause today, CMMC does not reach you at all, though the proposed FAR CUI rule is worth tracking because it would extend a NIST SP 800-171 baseline government-wide if finalized.

    And if a consultancy tells you that you handle CUI before reading your contracts and looking at your inbound data, that is a sales conclusion rather than a finding. The determination is your customer's to make and yours to confirm.

    Where Top Floor fits

    The first phase of our CMMC engagements is data identification and boundary definition, because every downstream cost is a function of it. That means reading the contract clauses, sampling inbound data, drawing the flows, and writing the boundary down in a form an assessor can follow.

    If the answer turns out to be Level 1, we will tell you, and that is a much smaller engagement than the one you were probably quoted.

    How to decide this week

    Send the written question to your contracting officer or prime: does this contract involve CUI, and which categories?

    Search your mail and file shares for CUI banner markings and for the file types that usually carry them.

    Then draw the flow for one representative document, from arrival to disposal, and mark every system it touches. That single diagram usually answers the level question and the scope question at the same time, and it tells you which of the two problems you actually have.

    Frequently asked questions

    What is the difference between FCI and CUI?

    FCI is any information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service. CUI is the narrower category that a law, regulation, or government-wide policy requires to be safeguarded, catalogued by category in the National Archives CUI Registry. Nearly every federal contractor holds FCI, which means CMMC Level 1 and the 15 requirements of FAR 52.204-21. Holding CUI raises the obligation to CMMC Level 2 and the 110 requirements of NIST SP 800-171 Rev 2.

    Is a technical drawing CUI?

    Often yes, under the Controlled Technical Information category, when it is technical data with military or space application that is subject to controls on access, use, or dissemination. It is not automatic: a drawing for a commercial part with no export control or dissemination restriction may not be CUI at all. Because the determination belongs to the government rather than to the contractor, the reliable route is to ask the contracting officer or prime in writing which categories the contract involves.

    What if CUI arrives without markings?

    Missing and incorrect markings are common, and an absent marking does not make the information something other than CUI. The workable posture is to protect data that is obviously in a CUI category while raising the marking gap in writing with whoever sent it, and to ask the contracting officer for the determination. Deciding unilaterally that unmarked data is uncontrolled leaves you carrying the risk of someone else's administrative error.

    Does CUI only apply to the Department of Defense?

    No. CUI is a government-wide program established under 32 CFR Part 2002 and administered through the National Archives CUI Registry, and it applies across federal agencies. CMMC is the Department of Defense program that assesses contractor implementation of the safeguards for it. The FAR Council has separately proposed a government-wide CUI rule that would apply a NIST SP 800-171 baseline to civilian-agency contractors as well, though as of August 2026 that rule is not final.

    Share Share on LinkedIn

    Related Services

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.