FCI is Federal Contract Information. CUI is Controlled Unclassified Information. Both can require protection, but they describe different obligations. For defense contractors, understanding the information your business receives or creates is an early step in defining CMMC readiness.
BCS helps Austin and Houston businesses connect their workflows to a practical readiness plan. Our CMMC consulting services begin with questions about your contracts, information, users, devices, and providers.
What is FCI?
Under FAR 52.204-21, FCI is information that is not intended for public release and is provided by or generated for the government under a contract to develop or deliver a product or service. The definition excludes publicly available government information and simple transactional information needed to process payments.
Illustrative example: An Austin subcontractor receives a nonpublic delivery schedule for government contract work. That schedule may be FCI. Before treating it as FCI only, confirm whether additional handling requirements apply.
A publicly available solicitation is different from nonpublic information exchanged while performing a contract. The context and the actual information matter.
What is CUI?
CUI is unclassified information subject to safeguarding or dissemination controls under applicable law, regulations, or government-wide policy. It is not classified national security information, and it is not simply anything a business considers confidential.
The NARA CUI Registry identifies authorized categories and their authorities. Examples include controlled technical information and certain information covered by privacy or other legal protections. A category label alone does not establish that every document of that general type is CUI.
Illustrative example: A Houston manufacturer receives a military-related technical drawing identified by its customer as controlled technical information, with handling instructions. Those instructions should inform the systems and workflow used for the project. Not every engineering drawing is CUI.
FCI versus CUI: a practical comparison
| Question | FCI | CUI |
|---|---|---|
| Meaning | Nonpublic information provided by or generated for government contract performance, subject to the FAR definition. | Unclassified information requiring safeguarding or dissemination controls under a governing authority. |
| Key reference | FAR 52.204-21 | CUI Registry, applicable authority, and contract instructions |
| CMMC relationship | Level 1 focuses on basic safeguarding of FCI. | Level 2 addresses protection of CUI; some contracts may require a higher level. |
| What to check first | Whether the information is nonpublic contract information and which safeguards apply. | Category, authority, markings, handling instructions, and applicable contract requirements. |
These concepts can overlap in government contract work. Avoid treating FCI and CUI as two labels that always place information into mutually exclusive buckets.
Does a “confidential” label make a file CUI?
No. Internal confidentiality labels do not automatically establish a federal CUI designation. A company’s private pricing or personnel records may need protection under other obligations without necessarily being CUI.
Likewise, do not use a missing CUI banner as the only basis for a handling decision. If the information or customer instructions suggest controls may apply, pause and obtain clarification before forwarding it or moving it to a different service.
Ask your customer clear questions
When the status of information is uncertain, ask the contracting officer or prime contractor:
- Which information in this project is identified as FCI or CUI?
- For CUI, what category, authority, and handling instructions apply?
- What CMMC level and assessment type does the contract specify?
- Which subcontractor obligations apply to our portion of the work?
- Who should resolve questions about markings or permitted sharing?
Keep the answers with your project records and provide the relevant instructions to the people designing and operating the IT environment.
Follow the information through your business
A readiness review should follow the entire workflow. Ask where files arrive, who opens them, where copies are saved, and which services transmit them. Include email, desktops, laptops, shared drives, cloud storage, printing, backups, remote access, and outside support providers.
Practical example: A project file may start in an approved folder but later be emailed to a personal account so an employee can work from home. Mapping the real workflow can reveal a gap that a folder inventory alone would miss.
How this affects your CMMC readiness plan
The information involved helps define the safeguards and assessment scope, but your contract establishes the required CMMC level and assessment path. Company size and a software vendor’s marketing claims do not settle the question.
Read Do I Need CMMC Level 1 or Level 2? for the assessment comparison. Before buying new tools, establish the requirements, document your workflow, and agree on responsibilities for implementation and verification.
FCI and CUI readiness support in Austin and Houston
Business Communication Solutions provides CMMC consulting for Austin and Houston contractors, with an initial focus on Level 1 readiness. We help organize scope reviews, gap findings, remediation, documentation, and self-assessment preparation.
We can coordinate with your existing IT staff on agreed tasks and connect the readiness plan to hands-on cybersecurity and network support. When CUI is involved, establish the appropriate handling and assessment requirements before assuming a Level 1 engagement is sufficient.
Start with your information and contract requirements
Bring your customer instructions and an overview of your systems. BCS can help organize the next steps for your readiness review.
Austin: 512-257-1433
Houston: 281-815-8784
Official reference resources
- FAR 52.204-21: FCI definition and basic safeguarding
- NARA: About CUI
- NARA: Controlled Technical Information
- NARA CUI FAQs
- Official contractor cybersecurity guidance
Examples are illustrative and do not designate your records as FCI or CUI. Confirm unclear information-handling and contract requirements with the appropriate contracting authority. BCS provides consulting and readiness support, not CMMC certification.