4.1 FCI vs CUI: Statutory Foundations, E.O. 13556 & 32 CFR Part 2002

Key Takeaways

  • FCI is nonpublic information provided by or generated for the Government under a contract to develop or deliver a product or service, excluding public Government information and simple transactional payment information.
  • CUI is unclassified information that a law, regulation, or Government-wide policy requires or permits an agency to safeguard or control in dissemination; the CUI Registry identifies categories and authorities.
  • CUI Basic follows the uniform CUI controls when no specific authority adds different controls, while CUI Specified has authority-prescribed handling that must be applied with the general CUI rules.
  • NIST SP 800-171 applies to covered nonfederal CUI systems through the governing contract or rule; not every FCI item is CUI, and a private company cannot create CUI merely by applying a label.
  • Marking, dissemination, decontrol, and destruction follow the designating agency’s authority and contract; do not invent universal portion marks, shred sizes, or self-designation powers.
Last updated: August 2026

FCI, CUI & Their Governing Authorities

CMMC begins with information. A system is not Level 1 or Level 2 merely because it belongs to a defense contractor; the contract, information, and required status drive the obligation. A candidate must distinguish Federal Contract Information (FCI) from Controlled Unclassified Information (CUI) and then find the source that controls handling.

Federal Contract Information

FAR 4.1901 defines FCI as information not intended for public release that is provided by or generated for the Government under a contract to develop or deliver a product or service. The definition excludes information the Government has made public and simple transactional information, such as information needed to process payment.

Examples can include nonpublic contract schedules, performance information, or deliverables that meet the definition. A document is not FCI simply because a federal contractor created it. Internal payroll, commercial marketing, and a public solicitation do not become FCI without the required contractual relationship and nonpublic character.

FAR 52.204-21 supplies 15 basic safeguarding requirements for a covered contractor information system. CMMC Level 1 uses those same 15 requirements. Section 170.15 maps them to NIST SP 800-171A procedures; because one PE safeguarding requirement has three separately mapped phrases, the regulatory mapping table contains 17 rows without changing the count of Level 1 requirements.

Controlled Unclassified Information

32 CFR 2002.4 defines CUI as information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. CUI is unclassified; classified information uses a different regime.

Executive Order 13556 established the government-wide CUI Program. NARA is the Executive Agent, and the CUI Registry lists categories, subcategories, authorities, banners, and dissemination controls. The registry is an authority map—not a menu that lets a contractor declare ordinary proprietary information to be CUI.

CUI and FCI can overlap, but they are not synonyms. CUI handled in contract performance will generally also be nonpublic contract information, yet many FCI items do not fall within a CUI category. Conversely, an entity may create CUI for the Government during performance even if the original input did not arrive as a marked document.

CUI Basic and CUI Specified

CUI Basic is CUI for which the governing authority does not prescribe controls that differ from the uniform CUI Program controls. CUI Specified is CUI whose underlying law, regulation, or Government-wide policy requires or permits specific handling that differs from those uniform controls.

“Specified” does not mean classified or automatically export controlled. The category’s authority decides the extra control. A candidate should identify the category and authority in the registry, then apply the agency guidance and contract. For a nonfederal system subject to DFARS 252.204-7012, NIST SP 800-171 Revision 2 supplies the required baseline unless the contract authorizes a variance; another authority may add obligations for a specified category.

Marking and designation

Government agencies establish processes to designate CUI and communicate it to authorized holders. NARA guidance uses the CUI banner and a CUI designation indicator for documents containing CUI; portion marking is generally optional unless agency policy, a category authority, or the contract requires it. Category and limited-dissemination markings must be authorized rather than invented.

A contractor follows the applicable agency marking instructions and contract. If information appears to meet a CUI category but arrives unmarked or inconsistently marked, the safe response is to protect it, preserve provenance, and seek guidance through the contracting or designated program channel. The contractor should not unilaterally downgrade, decontrol, or publicly release it.

Marking is evidence about status, not the sole source of status. A correct banner does not cure unauthorized creation, and a missing banner does not necessarily eliminate an underlying contractual safeguarding duty. Assessors compare markings with the contract, DD Form 254 or security classification guidance when relevant, CUI guidance, data flows, and actual handling.

Dissemination, decontrol, and destruction

CUI may be shared only when the recipient is authorized and has a lawful government purpose, subject to applicable dissemination controls and the contract. “CUI Basic” does not mean freely shareable. Export, privacy, procurement-sensitive, and other rules may independently restrict disclosure.

Decontrol occurs through the authorized agency or governing process when the information no longer requires CUI controls. Decontrol does not authorize public release if another restriction remains. A contractor does not decontrol CUI merely by deleting a banner or ending a contract.

When destruction is authorized, 32 CFR part 2002 requires a method that makes the information unreadable, indecipherable, and irrecoverable. The appropriate method depends on paper, digital media, equipment, agency policy, contract, and media-sanitization guidance. There is no universal CMMC shred-particle dimension for every record.

Exam method

For an information scenario, ask:

  1. Who created or possesses the information, and for whom?
  2. Is it intended for public release or simple transaction processing?
  3. Which CUI category and authority, if any, applies?
  4. Which FAR, DFARS, agency, export, privacy, or contract terms apply?
  5. What marking, dissemination, system, decontrol, and destruction duties follow?

This sequence avoids the two dangerous shortcuts: treating every contractor record as FCI, and treating every nonpublic defense record as CUI without an authority.

Test Your Knowledge

Which fact is necessary for information to be CUI?

A
B
C
D
Test Your Knowledge

What distinguishes CUI Specified from CUI Basic?

A
B
C
D
Test Your Knowledge

A contractor receives apparently controlled information with inconsistent markings. What is the best response?

A
B
C
D