APTSecurity Management

FCI vs CUI: Which Type of Data Are You Handling?

Cody D. Martin//Updated August 9, 2026

Federal Contract Information (FCI) points to CMMC Level 1 and its 15 safeguarding requirements. Controlled Unclassified Information (CUI) points to Level 2 and its 110 NIST SP 800-171 practices. Your contract clauses decide which you handle. Not your company size or how long you have held a contract.

Your Cybersecurity Maturity Model Certification (CMMC) level is not based on how big your company is or how long you have held a Department of Defense contract. It comes down to one question: what kind of government data do you handle?

There are two types that matter. Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). If you only handle FCI, you are looking at Level 1. If you handle CUI, you are looking at Level 2, which is a substantially larger undertaking.

This post explains the difference in plain language, shows you how to tell which type you handle, and walks through what each one triggers.

What counts as FCI

Federal Contract Information is defined in FAR 52.204-21. In plain terms, it is information the government provides to you, or that you generate for the government, as part of doing the work, and that is not intended for public release.

It does not cover two things: information the government already makes public, such as content on a public agency website, and simple transactional information, like the data needed to process a payment.

Almost everything else tied to your contract counts. Emails with a contracting officer about delivery schedules, internal performance reports, contract correspondence, and basic project documents are all FCI. If you do any work for a federal agency, you almost certainly handle it.

What counts as CUI

Controlled Unclassified Information is broader and more sensitive. It is unclassified information that a law, regulation, or government-wide policy requires you to safeguard. The National Archives and Records Administration maintains the registry of categories.

In the defense world the most common category is Controlled Technical Information (CTI). Technical data and engineering information with a military or space application. Research data, engineering drawings, specifications, and process sheets.

One detail trips people up. CUI is often marked, but not always. A document with no marking can still be CUI if it falls into a registered category. Do not treat the absence of a stamp as proof that something is safe to handle as FCI.

How to tell which one you handle

The fastest way is to read your contract. The clauses tell you what is in scope.

Clause What it signals
FAR 52.204-21 FCI. Basic safeguarding.
DFARS 252.204-7012 CUI. Triggers NIST SP 800-171 and incident reporting.
DFARS 252.204-7019 / 7020 SPRS score posting and assessment access.
DFARS 252.204-7021 The CMMC clause itself.

Two things matter here. Check the full contract, including attachments and statements of work, not just the cover page. And if you are a subcontractor, check what your prime has flowed down to you. A prime that handles CUI may or may not pass CUI down, and the flow-down is what governs your obligations, not what the prime does internally.

Two examples

Janitorial subcontractor. A company provides cleaning services at a defense contractor’s facility. The only government information it receives is the service contract, a schedule, and invoices. None of it is technical and none of it is CUI. This is FCI, and the path is Level 1.

Small machine shop. A shop machines parts for a defense prime. To make those parts it receives engineering drawings and specifications. That technical data is almost always Controlled Technical Information. A CUI category. The path is Level 2.

What each one requires

FCI only points to Level 1. Fifteen basic safeguarding requirements drawn from FAR 52.204-21, handled through annual self-attestation, where a senior company official affirms compliance in the Supplier Performance Risk System (SPRS).

CUI points to Level 2. One hundred and ten practices aligned to NIST SP 800-171, plus a System Security Plan, a POA&M for anything not yet met, an SPRS score, and annual affirmation.

What the July 2026 suspension changed. And what it did not

On 13 July 2026 the Department of War suspended CMMC Phase 2, which had been due to begin that November, and froze Phases 3 and 4 pending a reform review.

This is the part worth being precise about, because “CMMC is suspended” has been repeated in a way that is leaving contractors with the wrong impression.

Suspended is not repealed. 32 CFR Part 170, DFARS 252.204-7012, and DFARS 252.204-7021 all remain in force exactly as written. What stopped is the Department exercising its discretion to require the higher assessment types.

Paused Unchanged
Level 2 (C3PAO) third-party assessment NIST SP 800-171 Rev. 2 self-assessment
Level 3 (DIBCAC) assessment System Security Plan
CMMC waivers POA&M and remediation
SPRS score posting
Annual affirmation

During the suspension, requiring activities may designate only Level 1 (Self) or Level 2 (Self). Solicitations and contracts carrying a C3PAO or DIBCAC requirement are being amended to remove it.

So the question this post answers has not changed at all. You still need to know whether you handle FCI or CUI, because that still determines which set of requirements applies to you. What changed is who checks. Not what you owe.

If anything, the scoping work matters more now. A contractor who used the suspension as a reason to stop is still contractually obligated under 7012 and 7021, and still has to affirm compliance annually in SPRS.

If you are still not sure

Plenty of contractors read this far and remain uncertain. That is normal, and there are clear next steps.

Ask your prime. If you are a subcontractor, your prime is responsible for telling you what data flows down and which clauses apply. Put the question in writing.

Ask the contracting officer. They can clarify what data a contract involves and how it should be handled. Asking early is far better than guessing.

Or get the scoping done properly. A gap assessment starts with exactly this work: sorting FCI from CUI, confirming your level, and mapping what compliance actually involves before you commit time and budget to it.

  • CMMC
  • CUI
  • FCI
  • NIST 800-171
  • DFARS

More on compliance