CUI vs FCI: 2026 Guide
Table of Contents
- TL;DR
- CUI vs FCI at a Glance
- Federal Contract Information: What Government Contractors Handle Most
- Controlled Unclassified Information: The Narrower Subset
- FCI and CUI: How the Categories Overlap
- How to Tell Which One You're Holding
- Common Examples in Federal Contracts
- What Changes When Handling CUI Instead of FCI
- The Cost of Getting the Classification Wrong
- How MotherBear Keeps FCI and CUI Straight
- FAQs About CUI vs FCI
Most contractors can recite the difference between Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). Far fewer can look at a specific file on a laptop and say which one it is.
That gap is where the money goes. Treat everything as CUI, and you'll buy security you don't need. Treat CUI as ordinary FCI, and an assessor will find it sitting somewhere it shouldn't be.
The definitions themselves are only half the job. The useful skill is classification: looking at an email, a drawing, or a shared folder and knowing which rules attach to it.
Getting it right is what keeps sensitive data out of the wrong hands without over-engineering everything else.
This guide covers the distinction, then the part most articles skip. How the two categories overlap, how to tell them apart in practice, what changes when CUI enters, and what misclassification actually costs.
TL;DR
- FCI is the broad category: non-public information you receive from or create for the government while performing a contract. CUI is the narrower slice of that information which a law, regulation, or government-wide policy requires safeguarding for.
- The relationship runs one way. All CUI a contractor holds is also FCI, but most FCI never becomes CUI.
- The practical test isn't sensitivity. It's whether a law, regulation, or government-wide policy requires or permits an agency to apply safeguarding or dissemination controls, which is what converts otherwise-ordinary FCI into CUI.
- The consequences differ sharply. FCI means 15 basic safeguarding requirements at Cybersecurity Maturity Model Certification (CMMC) Level 1. CUI means 110 security controls and Level 2 for Department of Defense (DoD) contracts subject to Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012.
- MotherBear keeps requirement status, evidence, and documentation in one workspace, so the scope you defined is the scope you can prove.
CUI vs FCI at a Glance
Before we go into detail, here’s a brief overview of the two:
|
|
Federal Contract Information |
Controlled Unclassified Information |
|
What it is |
Non-public information provided by or generated for the government under a contract |
Government information that a law, regulation, or government-wide policy requires safeguarding or dissemination controls for |
|
Where the rule comes from |
Executive Order 13556 and 32 CFR Part 2002, reaching contractors through contract clauses |
|
|
Marking |
No standard FCI banner marking required |
Normally marked or otherwise identified as CUI, though a missing marking isn't definitive |
|
Security baseline |
15 basic safeguarding requirements |
Depends on the applicable contract and agency; for DoD contracts subject to DFARS 252.204-7012, the National Institute of Standards and Technology (NIST) standard 800-171 Revision 2 |
|
CMMC level |
Level 1 where CMMC applies |
Generally Level 2 or above where CMMC applies |
Two rows deserve emphasis. Marking is the fastest signal you have, and the security baseline is why misclassification is expensive in both directions.
Federal Contract Information: What Government Contractors Handle Most
FCI is the default category for information moving between you and the government during contract performance. If it isn't public and it relates to delivering the product or service you were hired for, it's probably FCI.
Two things sit outside the definition. Information intended for public release isn't FCI, so material already on public websites doesn't count. Neither does routine transactional data needed to process payments.
One boundary catches people out. Information your company creates independently, outside any government contract, isn't FCI at all, no matter how sensitive it feels. Your own intellectual property and financial data stay yours.
The test applies wherever you store, process, or transmit FCI, so the obligation follows the data rather than the department.
The Federal Acquisition Regulation Baseline
The government-wide baseline for FCI comes from one FAR clause. FAR 52.204-21 imposes 15 basic safeguarding requirements on covered contractor information systems that process, store, or transmit FCI, covering:
- Access control
- Identification
- Media and physical protection
- Boundary defense
- Malicious code protection
Those security controls exist to protect FCI at a baseline level. They're the minimum considered adequate to safeguard FCI, not a full security program.
That clause predates the CMMC program and applies wherever a contracting officer inserts it.
Controlled Unclassified Information: The Narrower Subset
Controlled Unclassified Information (CUI) is nonclassified information created or held by the federal government, as well as information created or maintained by another entity for the government, that is subject to safeguarding or dissemination requirements established by law, federal regulation, or government-wide policy.
The authority has to be one of those three. An agency's preference doesn't qualify, and neither does a contractor's judgment.
The rules bind executive branch agencies directly and reach non-federal systems through contracts. That's how the obligation lands on you.
The category exists because agencies used to invent their own markings. Executive Order 13556 replaced that sprawl with one system, administered by the National Archives and Records Administration.
Critically, CUI is not classified information. It sits outside the national security classification system, so there's no general CUI clearance or cleared-facility requirement, and it lives on ordinary contractor systems under stronger-than-ordinary controls.
That said, the law behind a particular category can impose its own controls or penalties, so the absence of a clearance regime isn't the absence of consequences.
Why Government Agencies Designate CUI
Designation authority sits with the government. When an agency shares CUI with a contractor, it's responsible for marking or otherwise identifying it, and contractors can carry marking duties for CUI they create when their contracts instruct it.
The CUI Registry maintained by the National Archives lists every valid category. They range widely, such as:
- Export-controlled data
- Unclassified controlled technical information (UCTI)
- Personally identifiable information (PII)
- Critical infrastructure details
Some categories carry national security implications, which is why what's considered CUI is decided by authority rather than by how confidential something looks.
Contractors have a narrower role. You may be asked to mark CUI you create during performance when your contract instructs it, but you don't invent categories on your own.
FCI and CUI: How the Categories Overlap
Here's the relationship that resolves most confusion, and it comes from the National Archives directly: all CUI in a contractor's possession is also FCI, but not all FCI is CUI.
Picture FCI as the outer circle. Everything non-public that passes between you and the government under a contract sits inside it. CUI is a smaller circle drawn within that one.
This is why the two aren't alternatives. A contractor holding CUI also holds FCI.
The levels aren't two checklists run against the same asset, though. Once an asset processes, stores, or transmits CUI, it falls into the Level 2 assessment scope where CMMC applies and gets assessed against the Level 2 requirements.
The underlying FAR obligation to safeguard FCI still exists contractually.
The one-way nature matters when you're scoping. Finding CUI in a system you'd classified as FCI-only expands your requirements. Finding ordinary FCI in a CUI enclave doesn't shrink them.
How to Tell Which One You're Holding
Classification is a three-step check, and it goes fastest in this order.
Step #1: Start With the Marking
CUI is supposed to arrive identified. A banner reading CUI or CONTROLLED is a strong signal, though category and dissemination markings vary.
Unmarked doesn't automatically mean FCI, though. Marking failures happen, and the obligation to protect CUI doesn't wait for a label to appear. Treat an unmarked file that looks regulated as a question for your contracting officer rather than a settled answer.
Step #2: Ask Who the Law Binds
This test separates the categories cleanly, and almost nobody explains it.
Determine whether any law, regulation, or government-wide policy requires or authorizes an agency to impose safeguards or restrictions on how the information is shared.
Where it does, and the information falls within an authorized category, you're dealing with CUI rather than ordinary FCI.
If the information otherwise meets the FCI definition and no such CUI authority exists, it remains FCI regardless of how sensitive it seems.
Sensitivity is not the standard. A purely internal pricing model your company created independently, and never provided to or created for the government, can be commercially sensitive without being either FCI or CUI.
Step #3: Check What the Contract Says
Contract requirements settle the question in practice, though not as bluntly as people assume. FAR 52.204-21 establishes the FCI baseline.
DFARS 252.204-7012 is inserted broadly in DoD contracts, so its presence alone doesn't prove you hold CUI. The heavier compliance requirements attach where performance actually involves covered defense information on your systems, which is what brings NIST 800-171 into play.
When the picture is still unclear, ask. Contracting officers can confirm what a contract conveys, and getting that answer in writing is cheaper than discovering it during a CMMC assessment.
Common Examples in Federal Contracts
Concrete cases make the boundary easier to see than definitions do.
Typical FCI includes non-public delivery schedules, unclassified process documentation you produce for the government, correspondence coordinating site access, and progress reports on contract work.
Common CUI examples can include:
- Controlled government technical drawings
- UCTI
- Export-controlled data received or created for the government
- Certain PII covered by a CUI authority
The information type alone doesn't settle it. Each instance still needs a valid CUI authority and category basis, which is why the category matters more than the file format.
The ambiguous middle is worth naming. Engineering documentation you created for a defense contract could be either, depending on whether an authority requires protecting it. That's exactly the case where the marking and the contract decide, not your instinct.
What Changes When Handling CUI Instead of FCI
What your organization handles decides its obligations. For a DoD contractor subject to DFARS 252.204-7012 and applicable CMMC requirements, moving from FCI-only work to CUI changes the program substantially.
Once you store, process, or transmit CUI, the following shift at once:
- Requirement count: 15 basic safeguards become 110 security requirements, spanning areas FCI never touches, including incident response, audit logging, and multi-factor authentication.
- Documentation burden: Level 2 requires a System Security Plan (SSP) describing how each requirement is implemented, alongside evidence you can produce on demand.
- Assessment rigor: Level 1 is a self-assessment against a short list. Level 2 involves scoring, regular assessments, and considerably deeper scrutiny.
- Scope discipline: CUI environments typically get segmented deliberately, because letting CUI spread through general systems pulls everything into scope.
If You Only Handle FCI
Plenty of contractors genuinely never touch CUI, and they shouldn't build for it speculatively. Confirm the classification, implement the 15 requirements properly, and revisit the question whenever a new contract arrives.
The revisit matters. Scope changes arrive through contracts, not announcements, and a supplier that handled only FCI last year can be holding CUI this year without anyone flagging it.
The Cost of Getting the Classification Wrong
Misclassification is expensive in both directions, which is why guessing is the worst strategy.
Over-classify, and you pay for controls you don't need. Applying CUI-grade protection to every system multiplies your compliance costs and your assessment scope without buying eligibility for anything.
Under-classify, and the failure is sharper. CUI discovered on a system scoped only for FCI is a compliance failure an assessor can't overlook, and it can undo an otherwise sound program.
There's a contractual dimension too. When a required status isn't in place, contract eligibility suffers, and an inaccurate representation of your protections carries consequences well beyond the assessment itself.
CMMC Requirements for DoD Contractors
For defense work, the information your systems will handle informs the CMMC level specified in the solicitation or contract. Level 1 and Level 2 are distinct assessment statuses tied to different information-protection requirements.
CMMC Compliance at Level 1 and Level 2
Level 1 covers FCI. It requires the 15 basic safeguarding requirements, an annual self-assessment, and an annual affirmation, with no remediation plans permitted.
Level 2 covers CUI. It brings the 110 requirements from NIST 800-171, Revision 2 under the current program, along with far heavier documentation.
One piece of current context. The Department suspended CMMC Phase 2 on July 13, 2026, pending a program review, so third-party assessment is paused.
Phase 1 self-assessment obligations continue, and the required affirmation, often called CMMC self-attestation, still carries legal weight.
The classification question doesn't change during the pause. Whichever verification model returns, it will verify the scope your data types define.
How MotherBear Keeps FCI and CUI Straight
Classification decisions get made once and then quietly drift. A new contract arrives, a folder gets shared, and the boundary you documented last year no longer matches the environment you're running.
That drift is what turns a clean scope into an assessment problem. The requirement status lives in one place, the evidence in another, and nothing connects either to the data classification that justified them.

MotherBear gives defense contractors and their consultants one workspace holding requirement status, an evidence repository tied to what each artifact proves, documentation, and remediation work, whether the program sits at Level 1 or Level 2.
That matters most when a classification shifts. A new contract brings CUI to a client who only ever handled FCI, and managed service providers and consultants need to see which programs just changed shape rather than finding out at the next assessment.
Book a demo and see how MotherBear keeps your scope defensible as contracts change.
FAQs About CUI vs FCI
What is the difference between FCI and CUI?
FCI is non-public information exchanged or created during contract performance, protected by 15 basic safeguarding requirements under FAR 52.204-21. CUI is a more limited category of information that is subject to protection or sharing restrictions authorized or required by law, regulation, or government-wide policy.
For DoD contracts subject to DFARS 252.204-7012, CUI brings the 110 NIST 800-171 Revision 2 requirements into scope and generally corresponds to CMMC Level 2. The trigger isn't how sensitive the information feels; it's whether an applicable authority requires or permits those controls.
Is FCI part of CUI?
It's the other way around. All CUI held by a contractor is also FCI, but most FCI never rises to CUI, so CUI is best understood as a subset of the broader FCI category.
That one-way relationship has a practical consequence: a contractor with CUI holds both types.
Where a contract requires Level 2, systems in that assessment scope are assessed against the Level 2 requirements. The underlying FAR obligation to safeguard FCI remains contractually applicable.
What is FCI under CMMC?
Under CMMC, FCI is the information type associated with Level 1. Contractors subject to FAR 52.204-21 must implement its 15 safeguards on systems handling FCI, and where a DoD contract requires CMMC Level 1, those safeguards are verified through an annual self-assessment and annual affirmation.
FCI is widespread in federal contracting, so Level 1 is often the starting point for defense suppliers subject to CMMC, and the question becomes whether CUI pushes them higher.
What are the two types of CUI?
The CUI Program splits the category into CUI Basic and CUI Specified. CUI Basic follows the uniform handling rules in 32 CFR Part 2002, with no special instructions beyond the baseline.
CUI Specified applies where the underlying law or regulation prescribes particular handling controls. Where the authority specifies controls, those govern, and the CUI Basic rules fill whatever the authority leaves unaddressed. Check the CUI Registry entry for your category to find out which applies.
Need CMMC Compliance?
Book a demo of MotherBear to see how we streamline CMMC Level 1 and Level 2
