Is my contract information FCI or CUI?

Marked, or named as CUI in the contract: Level 2, 110 requirements. Other nonpublic contract info is FCI: Level 1, 15. How to tell, and the email to send the prime.

Classification record. Public release. Contract information. Controlled technical data. Working guide.
In this guide

Updated September 29, 2026

You have a folder of files from a prime, the larger company whose contract you're working under, and no idea which ones trigger what. If the government, a marking on the document, or your contract says it's CUI, treat it as CUI. Anything else nonpublic that you received or created under a federal contract is FCI. Public material and simple payment details are neither.

Those two labels decide how much security work, and money, the Defense Department expects from you. FCI (federal contract information) is the everyday paperwork of a government job: schedules, prices, emails about the order. CUI (controlled unclassified information) is the sensitive layer: the drawings, specs, and technical data the government wants kept away from the wrong people. Neither is classified. Both come with rules.

Those rules are enforced through CMMC, the Cybersecurity Maturity Model Certification, which is how the Defense Department checks that its suppliers protect contract information. FCI alone puts you at CMMC Level 1: 15 basic safeguards, listed in FAR 52.204-21,. Holding CUI puts you at Level 2: the 110 requirements of NIST SP 800-171, the government's security standard for CUI. That means multi-factor login for everyone, encrypted laptops, logs, written plans, and more. DoD's own estimate for a small company's Level 2 certification is $101,752 in the first year, and that's assessment costs alone (final rule, 89 FR 83092). Call CUI "just FCI" and you're underprotected and can't back up what you tell the government. Call every file CUI and you pay Level 2 prices for Level 1 work. Which level applies

How you actually tell

The legal definition says CUI is information that a law, regulation, or government-wide policy requires or permits to be protected or limited in who gets it (32 CFR 2002.4). In a defense shop that almost always shows up in one of three ways.

The document says "CUI" at the top and bottom of each page, with a small block naming the agency or office that controls it. Or it's a technical drawing or data package carrying a distribution statement, the line of fine print that says who may receive it, lettered B through F. That makes it Controlled Technical Information, one of the most common kinds of CUI (CUI Registry: CTI). Or the contract itself says so: the statement of work, or a CDRL (the contract's list of required deliverables), marks a deliverable as CUI.

FCI is broader and duller: delivery schedules, pricing, internal correspondence about the contract. The FAR definition leaves out information the government has made public and "simple transactional information, such as necessary to process payments."

Two traps catch most shops. Your own "Confidential" stamp doesn't make anything CUI; only a government basis does. And a missing banner doesn't make a drawing safe. Unmarked drawings from a prime are the most common gap we see, and the fix is a one-line email, below.

One more misread: if your contract includes the clause DFARS 252.204-7012, you must protect CUI when you receive it. It doesn't mean every file you hold is CUI.

Item from the prime What it is What you do with it
Product brochure, cleared for release Neither Keep the release approval on file
Delivery schedule FCI Only people working the job can open it; Level 1 safeguards
Drawing with "Distribution D" and a CUI banner CUI, possibly also export-controlled Save it only in the folders and machines you've set aside for CUI; check export status before anyone else sees it

A second question, if you make defense articles

Some drawings are also controlled under ITAR, the State Department's export rules for military items. A drawing can be CUI and ITAR-controlled at once, and the ITAR half has sharper edges. Showing ITAR technical data to a foreign person, meaning anyone who isn't a U.S. citizen, green-card holder, or protected individual such as a refugee, counts as an export even if it happens in your own building (22 CFR 120.50(a)(2)). That includes a foreign national at your IT provider or on a software vendor's help desk. If you manufacture defense articles you must register with the State Department even if you never ship anything abroad, and registering gives you no right to export (22 CFR 122.1). No cloud product is "ITAR certified," whatever the sales page says. What matters is who can reach the file.

The email that settles it

For anything unclear, keep the file where your CUI lives until you hear back, and send this to the prime's contracts contact. File the reply with the document. It's the record that explains your decision if anyone asks later.

We received [item] under [contract / PO number] on [date]. It carries [marking, or "no marking"]. Please confirm in writing whether it is CUI, which category applies, and any handling or export-control instructions. Until we hear back, we are handling it as CUI.

Once every kind of information you receive has an answer, map how each one moves through your shop.

Mock assessment

Know what you're protecting before you buy anything.

Garde1 records each information type once and carries it into your scope, your SSP, and your media protection policy.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE