CUI vs FCI: What Defense Contractors Must Know

September 23, 2026


Share This Article

FCI is nonpublic information created for or collected by the federal government under a contract, while CUI is unclassified information subject to specific safeguarding or dissemination controls. The distinction affects CMMC requirements, cybersecurity practices, and how defense contractors handle information across employees, systems, and subcontractors.


Identifying each type starts with three steps: determine what information is involved, trace where it is stored or transmitted, and confirm the safeguards tied to the contract. The harder questions often arise when that information reaches drawings, emails, purchase orders, and production records.

Circuit board assembly machine with robotic heads working over a green PCB on a conveyor belt

What Is Federal Contract Information (FCI)?

Federal Contract Information (FCI) is nonpublic information created for or collected by the federal government under a contract. Under FAR 52.204-21, publicly released information and simple transactional details used to process payments are excluded.


FCI can appear in routine business records, including contract correspondence, schedules, purchase information, and project documentation. Its ordinary appearance can cause confusion because information does not need to be classified or highly technical to qualify as FCI.


For defense contractors, identifying FCI also means tracking where it resides and travels. Contract details may move into an ERP platform, email system, purchasing record, or shared workspace during normal operations. When FCI resides in or passes through a contractor information system, FAR 52.204-21 establishes baseline safeguarding requirements. Recognizing those touchpoints helps define which systems, employees, and processes need appropriate protections.

What Is Controlled Unclassified Information (CUI)?

Controlled Unclassified Information (CUI) is unclassified government information that is subject to safeguarding or dissemination controls under federal law, regulation, or government-wide policy. Although CUI is not classified information, contractors may face specific requirements for storing, accessing, transmitting, and sharing it.


For defense manufacturers, CUI can appear in technical records used throughout engineering and production. Depending on the contract and applicable CUI category, examples may include:

  • Engineering drawings and specifications
  • Process sheets and technical reports
  • Technical data with military or space applications
  • Certain software and related documentation

A familiar file type does not automatically determine its status. Contractors should review contract clauses, CUI markings, the information’s source, and applicable handling instructions. When the classification remains unclear, the appropriate contracting authority should clarify how the information is designated and handled.

CUI vs. FCI: What Are the Key Differences?

The main difference is the level of safeguarding tied to the information. FCI covers nonpublic federal contract information, while CUI carries specific safeguarding or dissemination controls established by government authority.

Factor FCI CUI
Information Type Nonpublic federal contract information Controlled, unclassified government information
Typical Examples Contract correspondence, schedules, project records Technical drawings, specifications, process sheets
CMMC connection Level 1 Level 2 in applicable DoD contracts
Safeguards FAR 52.204-21 practices NIST SP 800-171 requirements for applicable DoD CUI

The distinction also affects compliance scope. Systems that store, process, or transmit protected information may fall within applicable safeguarding requirements. Contractors therefore need to know where information originates, where it travels, and which employees or outside partners can access it before determining the appropriate controls.

How to Identify FCI and CUI in Your Contracts

Identifying protected information starts with the contract, but the review should follow that information into everyday workflows.

1. Check contract clauses and markings. Review applicable FAR and DFARS clauses, CUI markings, distribution statements, and handling instructions associated with the work.

2. Trace the information.  Identify where contract data appears across drawings, specifications, emails, purchase orders, ERP records, production files, and shared systems.

3. Confirm uncertain classifications.  A file name, document type, or technical subject alone does not establish its status. Questions about a designation should be addressed with the appropriate contracting authority.

This process also helps contractors identify employees, systems, and outside partners that interact with protected information. Documenting those touchpoints creates a clearer foundation for determining CMMC scope and applying the safeguards associated with the contract.

How FCI and CUI Affect CMMC Requirements

The type of federal information a defense contractor handles directly influences its CMMC obligations. CMMC Level 1 applies to contractors handling FCI and incorporates the 15 safeguarding requirements found in FAR 52.204-21. CMMC Level 2 applies to contractors handling applicable CUI and incorporates the 110 security requirements in NIST SP 800-171 Revision 2.


Determining the applicable level starts with knowing what information enters company systems and where it travels. Misidentifying data can expand compliance scope or leave protected information exposed. Contractors researching
CMMC certification for manufacturers should examine which employees, devices, cloud platforms, and facilities interact with federal information. Accurate scoping keeps cybersecurity planning aligned with actual contract obligations rather than assumptions about a project’s sensitivity.

How to Protect FCI and CUI

Protecting federal information means controlling access throughout its lifecycle, from initial receipt through storage, production, sharing, and approved disposal. Access should remain limited to authorized employees, systems, and manufacturing partners, with appropriate safeguards applied when information moves through email, cloud platforms, removable media, or shared workspaces.


Production workflows deserve the same scrutiny. Drawings, specifications, and related records can move through electronics manufacturing services and PCB assembly, creating additional information touchpoints. Contractors should map those movements and identify who can access the files at each stage. Clear handling procedures across engineering, purchasing, IT, and manufacturing reduce unintended exposure while keeping information controls aligned with contract requirements.

FCI and CUI Rules for Subcontractors

Federal information does not lose its protections when work moves downstream. Prime contractors should identify what information a subcontractor will receive and apply the appropriate contractual flowdown provisions. The subcontractor’s obligations depend on the information and contract requirements involved, rather than automatically matching the prime contractor’s CMMC level.


That distinction matters when sharing drawings, specifications, or production files with partners sourcing
military electronic components, aerospace electronic components, or completing cable and wire harness assembly. Each handoff should account for authorized access, secure transmission, storage, and applicable safeguarding practices.


EI Sales
works with defense and aerospace OEMs across component sourcing and manufacturing. For help connecting project requirements with qualified manufacturing resources, contact EI Sales to discuss the application and next steps.

Connect With Us

Automated machine inspecting a green circuit board on a factory conveyor belt
September 15, 2026
EI Sales explains how vapor phase reflow reduces head in pillow defect risk by improving thermal uniformity across dense PCBs.
Technician wiring an electrical control panel with tools in an industrial cabinet
September 1, 2026
Explore power generation panel assembly design, components, integration, testing, and production considerations with electronics manufacturing expertise from EI Sales.
Green circuit board on an automated assembly line with metal rails and components
August 26, 2026
Explore CCA vs PCBA terminology, applications, assembly processes, and quality considerations with EI Sales for reliable electronics manufacturing solutions.

LATEST NEWS