Federal Contract Information (FCI) is information provided by or generated for the U.S. government under a contract to develop or deliver a product or service to the government, that is not intended for public release. The definition comes from the FAR basic safeguarding clause, FAR 52.204-21, which was renumbered FAR 52.240-93 on February 1, 2026; older contracts may still carry the original number. FCI does not include information the government makes publicly available, such as on a public website, or simple transactional information like that needed to process payments.
FCI and Controlled Unclassified Information (CUI) are related but distinct. Nearly all CUI is also FCI, but not all FCI is CUI. The distinction matters because it drives which safeguarding requirements, and which CMMC level, apply to you.
| Aspect | FCI | CUI |
|---|---|---|
| What it is | Non-public information provided by or generated for the government under a contract | Government-created or -possessed information that law, regulation or policy requires to be safeguarded |
| Sensitivity | Basic; not intended for public release | Higher; specifically designated and controlled |
| Safeguarding standard | The 15 basic safeguarding requirements in FAR 52.204-21 (now FAR 52.240-93) | The 110 requirements in NIST SP 800-171 |
| CMMC level triggered | Level 1 (if you handle FCI but not CUI) | Level 2 (handling CUI) |
| Relationship | Broader category; most contract information | A protected subset that also counts as FCI |
If your organization handles FCI but not CUI, you fall under CMMC Level 1. Level 1 maps to the 15 basic safeguarding requirements in FAR 52.204-21 (now FAR 52.240-93), and is the entry point of the CMMC model.
Level 1 is met through an annual self-assessment, with the results and an annual affirmation entered in SPRS under 32 CFR 170.15. If a contract later involves CUI, the applicable bar rises to Level 2 and the 110 NIST 800-171 requirements. Knowing whether you hold FCI, CUI, or both is therefore the first scoping question in any CMMC effort.
Read the framework guides, or see how Compli.ai handles CMMC and NIST 800-171 with a practitioner on the call.