FCI vs CUI: Sorting Your Contract Data Before CMMC Applies

Federal Contract Information and Controlled Unclassified Information trigger different CMMC levels. Learn to tell them apart and find where each lives.

3 min readBy Ironfield Cyber Team

Two acronyms drive most of the confusion in defense contracting cybersecurity: FCI and CUI. They sound similar, they are both sensitive, and they trigger very different obligations under CMMC. Companies that cannot tell them apart tend to either overspend on controls they do not need or underprotect data that requires more.

Sorting your data into the right category is one of the most valuable early steps in compliance work, and it does not require technical expertise.

What FCI is

Federal Contract Information is information provided by or generated for the government under a contract that is not intended for public release. Think of ordinary contract administration: statements of work, schedules, pricing exchanged with the prime, and correspondence about performance. FCI does not include information the government has made public, such as content on a public website, or simple transactional information such as that needed to process payments.

Companies handling FCI are generally expected to meet basic safeguarding practices, which map to CMMC Level 1.

What CUI is

Controlled Unclassified Information is information the government creates or possesses, or that an entity creates or receives on its behalf, that requires safeguarding or dissemination controls under law, regulation or government-wide policy. CUI comes in categories, and a contract that involves it should say so, usually with marking requirements and specific handling instructions.

For a contractor, CUI might show up as certain drawings, technical specifications, facility details or infrastructure information. The key point is that CUI must be identified by the government or the prime, not guessed by the subcontractor. Companies handling CUI are generally expected to implement NIST SP 800-171 requirements, which map to CMMC Level 2.

Why the difference matters

  • Scope and cost: Level 2 involves many more requirements than Level 1, including documentation, access control, logging and incident response capabilities.
  • Assessment: Level 1 involves self-assessment. Level 2 may involve self-assessment or a third-party assessment, depending on the contract.
  • Systems: where CUI lives determines which systems fall into your assessment boundary.
  • Subcontractors: sharing CUI with subs extends obligations down the chain.

Overclassifying everything as CUI can burden your operations. Underclassifying risks noncompliance. Accuracy saves both money and risk.

How to sort your data

Step 1: Review contracts and flow-downs

Read each active contract and subcontract for clauses about FCI, CUI, DFARS safeguarding and CMMC. Note which ones state a level and which are silent.

Step 2: Ask in writing

If a contract is unclear, ask the prime or contracting officer whether CUI will be provided or created, and which categories apply. Keep the response with your compliance records.

Step 3: Look for markings

CUI should carry markings, such as a banner or designation indicator. Unmarked data is not automatically exempt, so when in doubt, ask. But a lack of markings from the source is useful evidence.

Step 4: Trace where it goes

For every category of FCI or CUI you identify, follow the data:

  1. How does it arrive, by email, portal, shared drive or physical media?
  2. Where is it stored, on servers, laptops, cloud tools or removable drives?
  3. Who can access it?
  4. Where does it go next, to subcontractors, vendors or printers?
  5. How is it destroyed when no longer needed?

Common mistakes

  • Treating all project data as CUI, which inflates scope
  • Treating nothing as CUI because no one told you, even when drawings arrive marked
  • Letting CUI spread into personal email, phones and consumer file sharing
  • Forgetting printed copies and removable drives
  • Not telling subcontractors what they are receiving

A hypothetical example

Consider a hypothetical electrical subcontractor working on a federal facility. Most of its contract data is routine FCI. A subset of drawings arrives marked as CUI. If the whole company's network is treated as in scope, the cost climbs. If the contractor isolates the CUI to a small, controlled environment, with its own access controls and storage, the assessment boundary shrinks and so does the burden. Careful data sorting makes that approach possible.

Build a simple data map

A one-page data map helps. List each type of FCI and CUI, where it lives, who touches it and what protects it. Update it when contracts change. The map becomes the backbone of your system security plan and your scoping discussions.

Where to start

Ironfield Cyber helps defense subcontractors sort contract data, identify where FCI and CUI actually live and decide how to scope the environment. If you are unsure which category your data falls into, we can walk through your contracts with you and build a data map you can use.