Glossary

What is FCI (Federal Contract Information)?

Federal Contract Information (FCI) is information provided by or generated for the U.S. government under a contract to develop or deliver a product or service to the government, that is not intended for public release. The definition comes from the FAR basic safeguarding clause, FAR 52.204-21, which was renumbered FAR 52.240-93 on February 1, 2026; older contracts may still carry the original number. FCI does not include information the government makes publicly available, such as on a public website, or simple transactional information like that needed to process payments.

FCI vs CUI: what is the difference?

FCI and Controlled Unclassified Information (CUI) are related but distinct. Nearly all CUI is also FCI, but not all FCI is CUI. The distinction matters because it drives which safeguarding requirements, and which CMMC level, apply to you.

AspectFCICUI
What it isNon-public information provided by or generated for the government under a contractGovernment-created or -possessed information that law, regulation or policy requires to be safeguarded
SensitivityBasic; not intended for public releaseHigher; specifically designated and controlled
Safeguarding standardThe 15 basic safeguarding requirements in FAR 52.204-21 (now FAR 52.240-93)The 110 requirements in NIST SP 800-171
CMMC level triggeredLevel 1 (if you handle FCI but not CUI)Level 2 (handling CUI)
RelationshipBroader category; most contract informationA protected subset that also counts as FCI

Which CMMC level does FCI trigger?

If your organization handles FCI but not CUI, you fall under CMMC Level 1. Level 1 maps to the 15 basic safeguarding requirements in FAR 52.204-21 (now FAR 52.240-93), and is the entry point of the CMMC model.

Level 1 is met through an annual self-assessment, with the results and an annual affirmation entered in SPRS under 32 CFR 170.15. If a contract later involves CUI, the applicable bar rises to Level 2 and the 110 NIST 800-171 requirements. Knowing whether you hold FCI, CUI, or both is therefore the first scoping question in any CMMC effort.

FCI only
FCI alone calls for CMMC Level 1 and its 15 basic safeguarding requirements.
CUI involved
CUI calls for CMMC Level 2 and the 110 NIST SP 800-171 requirements.
First step
Scope your data: identify where FCI and CUI live in your systems.

FCI FAQ

Is all FCI also CUI?
No. FCI is the broader category. CUI is a protected subset that also meets the definition of FCI, but plenty of FCI is not CUI. If you handle FCI without any CUI, Level 1 requirements apply; once CUI is in scope, the higher NIST 800-171 bar applies.
Does FCI include information on a public website?
No. Information the government intends for public release, such as content on a public website, is excluded from FCI. FCI is specifically non-public contract information.
What are the 15 requirements for FCI?
FAR 52.204-21, now numbered FAR 52.240-93, sets out 15 basic safeguarding requirements for covered contractor information systems that process, store or transmit FCI. These map to CMMC Level 1 and cover fundamentals such as access control, identification and authentication, and physical protection.
How do I know if I handle FCI?
If you have a federal contract and receive or generate non-public information to deliver the product or service, you almost certainly handle FCI. The practical next step is to scope your data and systems to see where FCI, and any CUI, actually resides.

Scope FCI and CUI, then meet the right level

Read the framework guides, or see how Compli.ai handles CMMC and NIST 800-171 with a practitioner on the call.