FCI is nonpublic information created for or collected by the federal government under a contract, while CUI is unclassified information subject to specific safeguarding or dissemination controls. The distinction affects CMMC requirements, cybersecurity practices, and how defense contractors handle information across employees, systems, and subcontractors.
Identifying each type starts with three steps: determine what information is involved, trace where it is stored or transmitted, and confirm the safeguards tied to the contract. The harder questions often arise when that information reaches drawings, emails, purchase orders, and production records.

What Is Federal Contract Information (FCI)?
Federal Contract Information (FCI) is nonpublic information created for or collected by the federal government under a contract. Under FAR 52.204-21, publicly released information and simple transactional details used to process payments are excluded.
FCI can appear in routine business records, including contract correspondence, schedules, purchase information, and project documentation. Its ordinary appearance can cause confusion because information does not need to be classified or highly technical to qualify as FCI.
For defense contractors, identifying FCI also means tracking where it resides and travels. Contract details may move into an ERP platform, email system, purchasing record, or shared workspace during normal operations. When FCI resides in or passes through a contractor information system, FAR 52.204-21 establishes baseline safeguarding requirements. Recognizing those touchpoints helps define which systems, employees, and processes need appropriate protections.
What Is Controlled Unclassified Information (CUI)?
Controlled Unclassified Information (CUI) is unclassified government information that is subject to safeguarding or dissemination controls under federal law, regulation, or government-wide policy. Although CUI is not classified information, contractors may face specific requirements for storing, accessing, transmitting, and sharing it.
For defense manufacturers, CUI can appear in technical records used throughout engineering and production. Depending on the contract and applicable CUI category, examples may include:
- Engineering drawings and specifications
- Process sheets and technical reports
- Technical data with military or space applications
- Certain software and related documentation
A familiar file type does not automatically determine its status. Contractors should review contract clauses, CUI markings, the information’s source, and applicable handling instructions. When the classification remains unclear, the appropriate contracting authority should clarify how the information is designated and handled.
CUI vs. FCI: What Are the Key Differences?
The main difference is the level of safeguarding tied to the information. FCI covers nonpublic federal contract information, while CUI carries specific safeguarding or dissemination controls established by government authority.
| Factor | FCI | CUI |
|---|---|---|
| Information Type | Nonpublic federal contract information | Controlled, unclassified government information |
| Typical Examples | Contract correspondence, schedules, project records | Technical drawings, specifications, process sheets |
| CMMC connection | Level 1 | Level 2 in applicable DoD contracts |
| Safeguards | FAR 52.204-21 practices | NIST SP 800-171 requirements for applicable DoD CUI |
The distinction also affects compliance scope. Systems that store, process, or transmit protected information may fall within applicable safeguarding requirements. Contractors therefore need to know where information originates, where it travels, and which employees or outside partners can access it before determining the appropriate controls.
How to Identify FCI and CUI in Your Contracts
Identifying protected information starts with the contract, but the review should follow that information into everyday workflows.
1. Check contract clauses and markings. Review applicable FAR and DFARS clauses, CUI markings, distribution statements, and handling instructions associated with the work.
2. Trace the information. Identify where contract data appears across drawings, specifications, emails, purchase orders, ERP records, production files, and shared systems.
3. Confirm uncertain classifications. A file name, document type, or technical subject alone does not establish its status. Questions about a designation should be addressed with the appropriate contracting authority.
This process also helps contractors identify employees, systems, and outside partners that interact with protected information. Documenting those touchpoints creates a clearer foundation for determining CMMC scope and applying the safeguards associated with the contract.
How FCI and CUI Affect CMMC Requirements
The type of federal information a defense contractor handles directly influences its CMMC obligations. CMMC Level 1 applies to contractors handling FCI and incorporates the 15 safeguarding requirements found in FAR 52.204-21. CMMC Level 2 applies to contractors handling applicable CUI and incorporates the 110 security requirements in NIST SP 800-171 Revision 2.
Determining the applicable level starts with knowing what information enters company systems and where it travels. Misidentifying data can expand compliance scope or leave protected information exposed. Contractors researching
CMMC certification for manufacturers should examine which employees, devices, cloud platforms, and facilities interact with federal information. Accurate scoping keeps cybersecurity planning aligned with actual contract obligations rather than assumptions about a project’s sensitivity.
How to Protect FCI and CUI
Protecting federal information means controlling access throughout its lifecycle, from initial receipt through storage, production, sharing, and approved disposal. Access should remain limited to authorized employees, systems, and manufacturing partners, with appropriate safeguards applied when information moves through email, cloud platforms, removable media, or shared workspaces.
Production workflows deserve the same scrutiny. Drawings, specifications, and related records can move through
electronics manufacturing services and
PCB assembly, creating additional information touchpoints. Contractors should map those movements and identify who can access the files at each stage. Clear handling procedures across engineering, purchasing, IT, and manufacturing reduce unintended exposure while keeping information controls aligned with contract requirements.
FCI and CUI Rules for Subcontractors
Federal information does not lose its protections when work moves downstream. Prime contractors should identify what information a subcontractor will receive and apply the appropriate contractual flowdown provisions. The subcontractor’s obligations depend on the information and contract requirements involved, rather than automatically matching the prime contractor’s CMMC level.
That distinction matters when sharing drawings, specifications, or production files with partners sourcing
military electronic components,
aerospace electronic components, or completing
cable and wire harness assembly. Each handoff should account for authorized access, secure transmission, storage, and applicable safeguarding practices.
EI Sales works with defense and aerospace OEMs across component sourcing and manufacturing. For help connecting project requirements with qualified manufacturing resources,
contact EI Sales to discuss the application and next steps.





















