top of page

FCI vs CUI: What's the Difference and Why Should Contractors Care?

11 minutes ago
11 min read

FCI vs CUI

 

Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) are two terms that appear frequently in federal contracting and cybersecurity conversations. FCI and CUI are also two terms that are often mistaken as interchangeable.

 

Want to clear up the FCI vs CUI confusion?

 


Gold Comet FCI vs. CUI padlock and key


As a contractor you know that you work with government information, but you may not know whether that information is FCI, CUI, or both. It may also be unclear which security requirements apply, how FAR 52.204-21 fits into the picture, or how CMMC-related requirements impact the systems used to process, store, or transmit that information.

 

To simplify things, understand that:

 

FCI and CUI are related, but they are not the same thing.

 

FCI is specifically defined in the Federal Acquisition Regulation (FAR) 52.204-21. CUI is a broader federal information category governed by laws, regulations, and government-wide policies that require or permit safeguarding or dissemination controls.

 

For contractors and vendors in the DIB supply chain, understanding the distinction affects how information should be handled, what contractual requirements apply, what systems are in scope, and what cybersecurity practices need to be in place.

 

This post will break down the differences in practical, understandable, and applicable terms.

 

 

What Is FCI?

 

Federal Contract Information (FCI) is information that is:

  • not intended for public release;

  • provided by the Government under a contract; or

  • generated for the Government under a contract to develop or deliver a product or service.

 

FAR 52.204-21 specifically excludes information that the Government has made publicly available, such as information it has placed on public websites.

 

FCI can include information a contractor receives or creates while performing a federal contract service that is not intended for public view.

 

For example, depending on the circumstances and the contract, FCI could include:

  • contract-related documents

  • project plans and ideation information

  • schedules and work products

  • technical or administrative information

  • internal communications related to contract performance

  • other information provided by or generated for the Government under the contract

 

These are items that are mission critical and not intended for the public to view. The key point is that FCI is defined by its relationship to a federal contract and its intended public-release status.

 

FAR Subpart 4.19 applies when a contractor's information system may contain FCI, and FAR 52.204-21 is inserted into solicitations and contracts when the contractor or a subcontractor at any tier may have FCI residing in or being transmitted through its information system.

 

Do not confuse FCI (or CUI) with "CLASSIFIED” information. Classified information is information that if released to the public could cause or contribute to varying degrees of damage to national security. This is information at an elevated tier governed by high levels of access and visibility control and never processed through standard unclassified systems.

 

FCI is unclassified information. Also, FCI is not automatically considered CUI simply because it comes from the federal government. That distinction is also important.

 

So now let’s talk about CUI.

 

 

 

 What Is CUI?

 

Controlled Unclassified Information (CUI) is information that requires safeguarding and dissemination controls pursuant to applicable law, regulation, or government-wide policy, but is not classified under Executive Order 13526 or the Atomic Energy Act.

 

The CUI program was established to standardize the government's approach to protecting sensitive unclassified information. Consider CUI as a step above FCI as regards information sensitivity.

 

The National Archives and Records Administration (NARA), through its Information Security Oversight Office, serves as the Executive Agent for the federal CUI program. The CUI Registry provides government-wide information about CUI categories, markings, and applicable safeguarding or dissemination authorities. (Here’s a NARA link on the history of the CUI program.)

 

CUI can encompass many different types of information. The CUI Registry includes categories involving areas such as:

 

  • controlled technical information

  • source-selection (contract award) information

  • critical infrastructure information

  • privacy-related information

  • international agreement information

  • other information subject to specific safeguarding authorities.

 

The exact controls applicable to CUI depend on the authority governing the CUI category. For contractors handling CUI in nonfederal systems, NIST SP 800-171 (Revision 3) provides the security requirements for protecting the confidentiality of CUI when the publication's conditions apply.

 

CUI is a category governed by the applicable underlying authority, and the associated requirements can depend on the type of CUI and the contractual environment. This is one of the reasons CUI conversations can become more complicated than FCI conversations. Sometimes there seems to be a fine line between the two.

 

 

 FCI vs. CUI: What Are the Key Differences?

 

The following table provides a way to understand the distinctions between FCI vs. CUI with a comparison of  how each category is defined and controlled.

 

Factor

FCI — Federal Contract Information

CUI — Controlled Unclassified Information

What is it?

Information not intended for public release provided by or generated for the Government under a contract to develop or deliver a product or service.

Information that requires safeguarding or dissemination controls pursuant to applicable law, regulation, or government-wide policy but is not classified.

Primary definition

FAR 52.204-21

Executive Order 13556 / 32 CFR Part 2002 and applicable authorities

Does it have to be associated with a contract?

Yes. The definition is tied to information provided by or generated for the Government under a contract.

Not necessarily in the same way. CUI is defined by the applicable safeguarding or dissemination authority.

Is it classified?

No.

No.

Can it be publicly available?

Information provided by the Government to the public, such as public websites, is excluded from FCI under FAR 52.204-21.

CUI is not public information while it remains controlled; authorized public release can result in decontrol.

Primary concern

Basic safeguarding of covered contractor information systems that process, store, or transmit FCI.

Protection and controlled dissemination of information requiring safeguarding under applicable authority.

Key federal framework

FAR 4.19 / FAR 52.204-21

CUI Program, applicable laws/regulations/policies, and contractual requirements

Contractor security requirements

FAR 52.204-21 establishes 15 basic safeguarding requirements when applicable.

Requirements depend on the applicable authority and contract. NIST SP 800-171 provides requirements for protecting CUI in covered nonfederal systems.

Relationship to CMMC

FCI can be within the scope of systems subject to CMMC requirements when the applicable DoD solicitation/contract requires it.

CUI can also be within the scope of systems subject to CMMC requirements.

Can an organization handle both?

Yes

Yes

Are they interchangeable terms?

No

No

 

 

The distinctions are important because not every piece of FCI is necessarily CUI, and not every piece of CUI should simply be treated as FCI.

 

NARA's CUI Program has specifically addressed the difference between the two categories, noting that FCI is defined under FAR 52.204-21 while CUI has its own definition under the CUI program. This NARA CUI Program Blog provides some further definitions and clarifications that you may find helpful.

 

 

What Does FAR 52.204-21 Have to Do With FCI?

 

FAR 52.204-21 is titled "Basic Safeguarding of Covered Contractor Information Systems." The clause defines a covered contractor information system as an information system owned or operated by a contractor that processes, stores, or transmits FCI.

 

When applicable, FAR 52.204-21 establishes 15 basic safeguarding requirements and procedures addressing:

  • authorized system access

  • authorized transactions and functions

  • external information-system connections

  • publicly accessible systems

  • identification and authentication

  • media sanitization and destruction

  • physical access

  • visitor controls

  • communications protection

  • network segmentation

  • information-system flaws

  • malicious-code protection

  • security scanning

 

 

The clause also contains an important provision that contractors should not overlook.

FAR 52.204-21 states that its requirements do not relieve contractors of other specific safeguarding requirements, including requirements relating to CUI. This means that FAR 52.204-21 is not a substitute for understanding other applicable cybersecurity requirements.

 

Also, applicability of this FAR is not limited to prime contractors. FAR 4.1903 directs contracting officers to insert the clause when a contractor or subcontractor at any tier may have FCI residing in or being transmitted through its information system.

 

 

How Does FCI Relate to CMMC?

 

Understand that CMMC is not another definition of FCI or CUI.

 

Instead, CMMC is a cybersecurity assessment and the overarching certification framework for applicable DoD contractors and subcontractors to qualify for performing services or providing deliverable products to the DoD.

 

Under current DoD CMMC contract language, the required CMMC level is specified in the applicable solicitation (request for proposal (RFP)) or contract, and the requirement applies to contractor information systems used in performance of the contract that process, store, or transmit FCI or CUI. The required level is determined by the applicable solicitation or contract.

 

So FCI and CUI describe the level of information. CMMC describes a cybersecurity assessment framework and contractual requirements applicable to certain DoD contracts. They are connected but are not interchangeable perspectives.

 

For organizations handling CUI in covered nonfederal systems, NIST SP 800-171 is also an important reference point. NIST states that SP 800-171 provides security requirements for protecting CUI in nonfederal systems and organizations under the conditions described by the publication.

 

 

Why FCI and CUI Matter to CMMC

 

You shouldn't assume that: "We process FCI, so we're CMMC Level 1."

Or:

"We store CUI, so we're automatically CMMC Level 2."

 

The applicable requirement depends on the specific contract, solicitation, information involved, system boundaries, and governing requirements. FCI forms the baseline for government contract information and requires a formal self-assessment and approved self-attestation process to be considered CMMC Level 1 compliant. Level 1 compliance must be achieved before a contractor can qualify for CMMC Level 2, which requires meeting the qualification requirements for handling CUI.

 

The right approach is to determine exactly what information your organization handles, which systems handle it, and what contractual and regulatory requirements apply so that you can prepare accordingly.

 

 

When Organizations Encounter Both FCI and CUI

 

A contractor may work on a federal program where some information qualifies as FCI while other information qualifies as CUI. For example, an organization might have contract-related administrative information that falls within the definition of FCI, while also handling controlled technical information that is designated as CUI under an applicable authority.

 

The same organization, along with potentially related workflows, can therefore involve both categories. This requires an understanding of the information you handle, the rules that govern each category, and knowing which systems (will) process, store, or transmit the information.

 

This is particularly important when information moves between employees, subcontractors, suppliers, customers, and other external collaborators in hybrid environments. Maintaining access control and public exposure of sensitive information can become challenging when information moves beyond your controlled environment.

 

You will need secure data storage, controlled sharing, access management, and auditability, to ensure secure collaboration across multiple organizations and networks.

 

That’s where a broader Zero Trust collaboration approach can and should become relevant.  Never assume that information is safe because it is inside your organizational network. Apply controls to govern and monitor identity, access, devices, data, and collaboration.

 

 

6 Common FCI and CUI Misconceptions

 

Misconception #1: "FCI and CUI are the same thing."

 

You can see now that they aren't. FCI has a specific definition under FAR 52.204-21. CUI has a separate federal definition and program framework. Your organization, however, can encounter both.

 

Misconception #2: "Anything received from the Government is automatically CUI."

Not necessarily. The information received must meet the applicable definition and requirements for CUI status which is connected to a law, regulation, or government-wide policy that requires or permits safeguarding or dissemination controls.


Misconception #3: "If information isn't classified, it doesn't require protection."

This is one of the most important misconceptions to eliminate. Both FCI and CUI are examples of information that can require protection even though they are not classified. CUI, by definition, is unclassified information subject to safeguarding or dissemination controls. FCI is information covered by the FAR definition and the applicable safeguarding requirements of FAR 52.204-21.

 

Misconception #4: "FAR 52.204-21 covers everything."

No, it doesn’t. The clause establishes basic safeguarding requirements for covered contractor information systems handling FCI. It expressly states that it does not eliminate other applicable safeguarding requirements, including those associated with CUI.

 

Misconception #5: "Having CUI automatically tells me what CMMC level I need."

Not by itself. The CMMC requirement is established through the applicable DoD solicitation or contract, and your organization must be prequalified to meet the stated requirement. Current DoD CMMC language identifies different possible levels and requires the applicable level for systems processing, storing, or transmitting FCI or CUI.

 

Misconception #6: "CMMC is the same thing as FCI or CUI."

You understand now that the two are different. A useful way to remember the relationship is that FCI and CUI are information categories while CMMC is the cybersecurity assessment and certification framework encompassing the two. These concepts interact, but they serve different purposes.

 

 

Gold Comet's FCI/CUI Recommendations

 

If your organization is still unclear about whether it handles FCI, CUI, or both, don't begin by buying another cybersecurity tool. Start by understanding your information environment.

 

1. Identify the information you handle.

Create an inventory of information received from or generated for the Government.

Ask:

  • What information do we receive?

  • What information do we create?

  • What information is intended for public release?

  • What information is not intended for public release?

  • What information is subject to specific safeguarding or dissemination requirements?

 

2. Map information to systems.

Determine where relevant information is created, stored, transmitted, shared, downloaded, backed up, and disposed of

 

This is where secure data storage becomes more than a storage question. The system holding sensitive information is part of your broader security environment.

 

3. Review your contract.

Don't rely solely on generic cybersecurity terminology.

Review the actual:

  • solicitation;

  • contract;

  • applicable clauses;

  • agency requirements;

  • CUI requirements;

  • subcontract requirements; and

  • flow-down provisions.

 

The applicable contract determines which requirements apply.

 

4. Determine your CMMC obligations.

 

If the contract is subject to CMMC requirements, determine:

  • which information systems are in scope;

  • whether they process, store, or transmit FCI or CUI;

  • which CMMC level the contract requires;

  • what assessment status is required; and

  • which requirements flow down to subcontractors.

 

Current DoD CMMC contract language specifically ties the required CMMC status to contractor information systems used to process, store, or transmit FCI or CUI.

 

5. Evaluate collaboration activities, not just storage.

 

You may have secure data storage and still create risk when sensitive information is shared through:

  • email attachments

  • unmanaged file-transfer services

  • personal cloud accounts

  • open sharing links

  • uncontrolled downloads

  • external collaboration platforms

  • third-party systems

 

Security needs to follow and protect your data as it moves. This is why Zero Trust collaboration should be an important part of a broader data-protection strategy: access should be based on verified identities, appropriate authorization, and the sensitivity and context of the information. Simply being an authorized member within your organization no longer provides enough protection.

 

6. Establish a controlled data environment.

 

For organizations dealing with FCI, CUI, or both, consider whether your environment provides appropriate capabilities for:

  • access control

  • authentication

  • secure data storage

  • controlled external sharing

  • secure messaging

  • auditability

  • data lifecycle management

  • protection against malicious activity

  • appropriate separation of sensitive information

 

For organizations seeking secure collaboration for regulated industries, your objective should be to establish an environment in which sensitive information can be stored, accessed, shared, monitored, and managed according to the data security requirements that apply.

 

 

Where Gold Comet Fits

 

Gold Comet approaches FCI protection as a data-management and collaboration problem, not simply a file storage problem.

 

The Gold Comet FCI Data Management / Enterprise Solution is designed to offer secure management of FCI and related collaboration requirements, with capabilities addressing secure data storage, controlled collaboration, access management, and Zero Trust principles, managed throughout the full data management lifecycle:

 

Store → Access → Collaborate → Share → Monitor → Manage

 

Rather than treating security as something that happens only when a file enters a storage system, your enterprise should be evaluating your contracts, information types, system boundaries, and applicable requirements to determine what controls and technologies are the best fit for your specific circumstances. The Gold Comet solution can be tailored to fit your needs. Give us the opportunity to help establish peace of mind regarding the security of your data.

 

 

Conclusion: FCI and CUI Are Different, Don’t Get it Twisted

 

The best thing to remember from the foregoing discussion is this: FCI and CUI are not interchangeable terms. Understanding the category of information you handle, and which requirements govern it, is the starting point for establishing the right security environment to begin the CMMC accreditation process. Start by:

 

·         Knowing how your information is classified.

·         Assessing your operational environment.

·         Understanding what your contract will require.

·         Learning how to comply with applicable policies and procedures.

Then begin to establish and maintain your security environment around those realities.

 

Gold Comet can help. Visit our Contact page and complete the form to request a free consultation. We'll show you how a secure data environment can help protect your FCI.


Gold Comet Secure Data Storage, Data Sharing, and Messaging banner

 

Note: This post provides information intended for general understanding and is not legal, contractual, or compliance advice. Every sicario is different. Contractors should review your specific solicitations, contracts, applicable agency requirements, and current regulatory guidance to determine which requirements apply to your systems and information. Reach out if we can help you begin to map your path.









Comments


bottom of page