GSA Ready Now
Contractor mapping FCI and CUI data types against contract clauses to set compliance scope
Back to Blog
Compliance Aug 10, 2026 8 min read

FCI vs CUI: The Distinction That Sets Your Scope

Focus keyword: FCI vs CUI

Federal Contract Information and Controlled Unclassified Information are not two names for the same thing, and they do not come from the same authority. FCI comes from the FAR and carries a requirement that is already in your contracts today. CUI comes from an executive order and a National Archives registry, and on the civilian side the government-wide contract clause for it is still a proposal, not a rule in force.

That difference is not academic. It decides which systems fall inside your boundary, what you owe your subcontractors, and how much you should be spending right now.

FCI and CUI safeguards overview: fifteen safeguards for Federal Contract Information, proposed safeguards for Controlled Unclassified Information, and the overlapping area of safeguards shared between FCI and CUI.
FCI and CUI safeguards overlap without either being a clean subset of the other. That overlap, and the gaps around it, is what sets your scope.

What Is FCI, and What Makes It Different from CUI?

Federal Contract Information is defined in FAR 4.1901 and FAR 52.204-21. It is information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service to the government. It excludes information the government has already made public and simple transactional information such as what is needed to process payments.

That definition is broad on purpose. A statement of work, a delivery schedule, internal correspondence about task order performance, a draft deliverable: all of that is likely FCI.

Controlled Unclassified Information is a different construct. It comes from Executive Order 13556 and the implementing regulation at 32 CFR Part 2002, and the authoritative list of what qualifies sits in the NARA CUI Registry. CUI exists because a law, regulation, or government-wide policy requires safeguarding of that specific information type. Export controlled data, certain privacy categories, critical infrastructure information, and law enforcement sensitive material are examples of registered categories.

The practical distinction: FCI is defined by how the information arose, meaning under a federal contract. CUI is defined by what the information is, meaning a category with a legal basis for protection. The two overlap heavily, but neither is a clean subset of the other.

Why Does the FCI to CUI Line Decide Scope Rather Than Company Size?

Because the obligations attached to each are different in kind, not just degree.

If you hold FCI on your information systems, FAR 52.204-21 applies and it has applied for years. It sets out fifteen basic safeguarding requirements: access control, authenticator management, media sanitization, boundary protection, malicious code protection, and so on. These are baseline hygiene controls. It flows down to subcontracts where FCI will reside in or transit through the subcontractor's systems, and it is generally excepted for acquisitions of commercially available off-the-shelf items.

If you hold CUI, the picture is agency by agency at the moment. There is no single government-wide FAR clause in force that says protect CUI to this standard. Instead, individual civilian agencies have their own supplement clauses and policies. GSA, DHS, NASA, and others have each written their own safeguarding and incident reporting language, and the requirements are not identical across them.

So scope is not a function of headcount or revenue. It is a function of two questions: what data types touch your systems, and which agency's clauses are in your contract file.

What Is Actually Required of Civilian Contractors Today?

Three things are worth separating.

First, FAR 52.204-21 is in force. If FCI touches your systems, the fifteen safeguards apply and they flow down. This is the floor and it is not new.

Second, agency-specific CUI clauses are in force where they appear in your contract. Read the clause. Some reference agency IT security policy documents, some impose incident reporting timelines, some address media handling and personnel screening. These are contractual obligations you already signed, and they vary.

Third, the government-wide FAR CUI rule is proposed. The FAR Council published a proposed rule under FAR Case 2017-016 in January 2025 that would create a standard CUI clause, a standardized identification form for contracting officers, and a safeguarding baseline drawn from NIST SP 800-171. It is a proposal. It has not been finalized, and until a final rule is published with an effective date and the resulting clause appears in your contract, it does not obligate you to anything.

Does the Recent Reporting on the FAR Council Change Any of That?

Not yet, and that word matters.

Legal commentary published this month, including analysis on JD Supra, describes the FAR Council moving forward on CUI rulemaking while the defense side slows its own timeline. That is worth watching. It is a signal about direction of travel, and it is a reasonable input into your planning horizon.

It is not a compliance trigger. Rulemaking timelines slip regularly, proposed language changes between the proposed and final stages, and the volume of comments on this particular case was substantial. Anyone telling you that you must be compliant with a proposed rule is describing something that does not exist.

The honest position is this: the direction is fairly clear, the timing is not settled, and the final text may differ from the proposal.

Does CMMC Apply to My Civilian Agency Work?

No. CMMC is a Department of War program that applies to that department's contracts and subcontracts through its own acquisition supplement. If your work is with GSA, DHS, HHS, NASA, or another civilian agency, CMMC is not the mechanism that governs you.

There is no equivalent certification on the civilian side. No assessor, no certificate, no third party stamp that makes you eligible for civilian awards. If a vendor offers to certify you for civilian CUI work, they are selling something that does not exist.

What the civilian side has is contract clauses, and if the proposed FAR rule is finalized, it would most likely operate on a self assessment and representation basis rather than a certification regime. That is what the proposal describes. It could change.

How Should I Scope This Now Without Overbuilding?

Start with data, not tools.

Inventory where FCI lives. For most small and mid sized contractors, that means email, file storage, a CRM or project system, endpoints, and possibly a subcontractor or two. Confirm the fifteen FAR 52.204-21 safeguards are actually implemented against that footprint, and confirm the flowdown is in your subcontract templates. This is a present obligation, not a future one.

Then identify whether any registered CUI category is genuinely in play, and whether your contracts contain agency-specific CUI clauses. Read them rather than assuming.

Only then consider whether to voluntarily align to NIST SP 800-171. For many firms with a mixed civilian and defense pipeline, or with an eye on where the FAR is heading, doing the gap assessment now is a reasonable business decision. Doing it because you believe a proposed rule already binds you is not. Those are different reasons, and they justify different budgets.

The middle path most contractors land on: get the FCI baseline genuinely solid, document your system boundary, and keep the 800-171 work scoped to the environment that would actually handle CUI rather than the whole company.

Frequently Asked Questions

Is CUI just a higher level of FCI?

No. They come from different legal authorities. FCI is defined in the FAR based on how information originated, meaning it was provided by or generated for the government under a contract. CUI is defined by Executive Order 13556 and 32 CFR Part 2002 based on what the information is, using categories listed in the NARA CUI Registry. They overlap, but one is not simply a tier of the other.

Does FAR 52.204-21 apply to me right now?

If your information systems process, store, or transmit Federal Contract Information under a federal contract, yes, subject to the exceptions in the clause such as acquisitions of commercially available off-the-shelf items. It has been in effect for years and it includes a flowdown requirement to subcontractors whose systems will handle FCI.

Is the FAR CUI rule in effect?

No. The FAR Council issued a proposed rule under FAR Case 2017-016 in January 2025. It has not been finalized. Until a final rule is published with an effective date and the clause is incorporated into your contract, it creates no obligation.

Do civilian agency contractors need CMMC certification?

No. CMMC is a Department of War program implemented through that department's acquisition supplement. There is no comparable certification requirement or certification body for civilian agency CUI work.

What standard applies to CUI on civilian contracts today?

It depends on the agency and the clause. Several civilian agencies have their own supplement clauses addressing safeguarding and incident reporting, and they are not uniform. Read the clauses in your specific contract rather than assuming a single government-wide standard applies, because at present there is not one.

Should I implement NIST SP 800-171 before the rule is final?

That is a business decision, not a compliance requirement. If you have or want defense work, or if you want to shorten your response time when a final civilian rule lands, an early gap assessment is defensible. Scope it to the environment that would actually handle CUI rather than your entire company.

Not sure whether what you hold is FCI, CUI, or both? Map your data against your actual contract clauses and let us put a second set of eyes on your system boundary before you spend on controls you may not need.

Run the Gap Assessment

Find Out If You're Ready for a GSA Contract

Take the free 19-question GSA readiness assessment and get a personalized score with a clear action plan — in minutes.

Start Free Assessment