Branded graphic reading FCI vs. CUI: How to tell what your company actually handles

Ask a small defense supplier which CMMC level they need, and the honest answer is often “it depends on what we handle.” That’s exactly right. The single biggest factor in your CMMC scope, cost, and timeline is whether your company handles Federal Contract Information (FCI) only, or Controlled Unclassified Information (CUI) as well.

Get it wrong in one direction and you spend heavily protecting data that doesn’t need it. Get it wrong in the other and you’re exposed on a contract you’ve already signed. This guide explains the difference in plain English and gives you a practical way to find out what you actually have.

The two definitions, in plain English

FCI comes from FAR 52.204-21. It is information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service. It does not include information the Government has released to the public or simple transactional information, such as what’s needed to process payments.

CUI is defined in 32 CFR 2002.4(h). It is information the Government creates or possesses, or that a contractor creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls.

The practical difference: nearly everything tied to a DoD contract that isn’t public is at least FCI. CUI is the narrower subset that a specific law, regulation, or policy says needs extra protection, such as export-controlled technical data or controlled technical information on a drawing.

FCI CUI
Where it’s defined FAR 52.204-21 32 CFR 2002.4(h)
Typical examples Delivery schedules, contract correspondence, non-public pricing Controlled technical drawings, export-controlled data, specifications marked CUI
Contract clause to look for FAR 52.204-21 DFARS 252.204-7012
Security baseline 15 basic safeguarding requirements 110 NIST SP 800-171 requirements
Usual CMMC level Level 1 Level 2 (Level 3 for some critical programs)

Why the answer decides your CMMC level

If your company handles FCI but no CUI, you’re typically looking at CMMC Level 1: the 15 FAR 52.204-21 requirements, an annual self-assessment, and an affirmation in SPRS. We walk through that process in our Level 1 self-assessment guide.

If you handle CUI, you’re in Level 2 territory: all 110 NIST SP 800-171 requirements, a System Security Plan, and either a self-assessment or a third-party assessment, depending on your contract. Our Level 2 requirements guide covers that path.

The level isn’t about the size of your company. It’s about the information in your systems.

Your contract ultimately specifies the CMMC level required, but knowing what you handle lets you check that the requirement makes sense, and plan before the solicitation arrives.

How to tell what you actually handle

1. Read the clauses in your contracts and subcontracts

Look for FAR 52.204-21 (FCI) and DFARS 252.204-7012 (covered defense information, which includes CUI). Primes are expected to flow these clauses down to subcontractors whose work involves that information, so check your purchase orders and subcontracts, not just prime contracts.

2. Look at the markings

Under 32 CFR 2002, CUI is identified with a banner marking that contains “CUI” or “CONTROLLED,” and may include category markings and dissemination controls. Check drawings, specifications, statements of work, and email attachments from your customers.

Be careful with older documents. The regulation says legacy markings such as “For Official Use Only” are void and no longer by themselves indicate that information is CUI. Treat them as a reason to ask, not as a final answer.

3. Follow the data, not just the documents

Map where contract information enters your company and where it goes: email, file shares, CAD workstations, ERP systems, shop-floor PCs, and cloud storage. CUI often travels further than people expect, which is why it drives scope.

4. Ask when something isn’t clear

If you receive information you believe should be CUI but isn’t marked, or markings look inconsistent, ask your contracting officer or your prime in writing and keep the answer. Unmarked or inconsistently marked information is one of the most common sources of confusion for small suppliers.

5. Write it down

Record what you handle, where it lives, and how you decided. That record becomes the foundation of your assessment scope, whether you end up at Level 1 or Level 2.

What’s changing: the FAR CUI rule

On June 23, 2026, the FAR Council published an updated proposed rule that would bring CUI requirements into a new FAR Part 40 for all federal contracts, not just DoD. It replaces the January 2025 proposal. Key points include:

  • A standard form, the SF XXX, that agencies would use to tell contractors whether a contract involves CUI and which requirements apply
  • 72-hour reporting of CUI incidents from discovery
  • An obligation to notify the contracting officer when CUI isn’t properly marked

The comment period closed on July 23, 2026. It is still a proposed rule, so the requirements aren’t final. If it’s adopted, it should make the FCI-versus-CUI question clearer at the start of a contract. Until then, the steps above are how you get your answer.

Quick checklist

  • ☐ We’ve listed every active DoD contract, subcontract, and purchase order
  • ☐ We’ve checked each one for FAR 52.204-21 and DFARS 252.204-7012
  • ☐ We’ve reviewed incoming documents for CUI banner markings
  • ☐ We’ve asked in writing about unmarked or legacy-marked information
  • ☐ We’ve mapped where FCI and CUI live in our systems
  • ☐ We know which CMMC level our contracts call for

Not sure which side of the line you’re on?

Quad-B CMMC Readiness helps small and mid-size defense suppliers work out what they handle and scope their environment so they protect the right systems. See our services or request a free CMMC consultation. You can also reach us at info@quadbsystems.com or 949.693.0664.

This article is for general information and isn’t legal advice. Review your specific contract clauses with qualified counsel.

Sources