/

April 27, 2026

CUI vs FCI: Which of Your Systems Actually Need to Be CMMC-Certified?

Comparison of CUI and FCI regulations

CUI vs FCI CMMC Classification Is the First Decision That Determines Everything Else — Get It Right or Pay for It Twice

There’s a single question that determines whether your CMMC compliance program costs $35,000 or $300,000. It’s not your company size. It’s not your contract value.

It’s this: what data are you actually handling?

If you’re handling only Federal Contract Information, you need 15 basic safeguards and a self-assessment. If you’re handling Controlled Unclassified Information, you need all 110 NIST SP 800-171 controls and a third-party C3PAO assessment that costs at a minimum of $35,000 to $75,000 — before you’ve spent a dollar on remediation.

The math is brutal, but it’s not the worst part. Most contractors get this classification wrong in one of two directions: they assume everything is CUI and overspend by six figures protecting data that doesn’t need it, or they assume none of it is CUI and fail their assessment the moment a C3PAO opens a shared folder and finds a technical drawing they shouldn’t have.

This article walks through the actual difference between CUI vs FCI, how to figure out which of your systems handle which, and why getting this right early saves a year of compliance work.

What FCI Actually Is

Federal Contract Information is defined in FAR 52.204-21 as “information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government.”

In practice, FCI is the everyday operational data flowing through any defense contract:

  • Statements of Work and the back-and-forth emails that produce them
  • Project plans, schedules, and milestone documents
  • Communications with your contracting officer
  • Deliverable drafts before submission
  • Status reports and project performance data

If it’s information you got from the government or generated for the government as part of contract performance — and it’s not on a public website or simple transactional payment data — it’s FCI.

The bar for protecting FCI is set by FAR 52.204-21: 15 basic safeguards covering things like limiting access to authorized users, sanitizing media before disposal, controlling physical access, applying basic malware protection, and authenticating users. Common-sense cyber hygiene. If your organization is running a competently configured Microsoft 365 environment with MFA on and reasonable access controls, you’re probably already doing most of it.

FCI maps to CMMC Level 1 — annual self-assessment, annual senior-official affirmation, no third-party assessment.

What CUI Actually Is

Controlled Unclassified Information is a categorically different animal. CUI is information that, while not classified, requires safeguarding under specific laws, regulations, or government policies. The category is defined and managed by the National Archives’ CUI Registry.

For DoD contractors, CUI typically shows up as:

  • Technical drawings, specifications, and design documents
  • Engineering data covered by ITAR or export control rules
  • Vulnerability assessments and security architecture documents
  • Source code and software design documents for defense systems
  • Operational plans and system configuration data
  • Mission-critical performance and capability data

When the government provides any of this — or you generate it under contract — it’s CUI. The moment CUI enters your environment, the protection bar shifts dramatically: from 15 basic safeguards to all 110 controls of NIST SP 800-171, plus the three-year C3PAO assessment cycle that comes with CMMC Level 2.

CUI splits into two flavors. CUI Basic is the standard category — protected under NIST 800-171 and the general handling rules. CUI Specified carries additional dissemination, marking, or handling rules dictated by specific laws like ITAR, the Privacy Act, or export control regulations. The control baseline is the same, but the markings and transmission rules tighten.

The Single Most Important Rule: All CUI Is FCI, But Not All FCI Is CUI

Every piece of CUI in a contractor’s possession is also, by definition, FCI — because it was provided by or generated for the government under contract. But not all FCI rises to the CUI threshold. A weekly status report referencing milestone progress is FCI. The technical specification attached to that report describing the system being delivered may very well be CUI.

The practical implication: if you’re handling any CUI at all, the systems that touch it need Level 2 controls. The systems that touch only FCI without any CUI can stay at Level 1. This is what makes the FCI-vs-CUI distinction the most important scoping decision in your entire compliance program.

The CUI vs FCI CMMC Question That Saves You Six Figures

“Which specific deliverables under this contract are CUI, which are FCI-only, and where in our environment does each one live?”
If you can’t answer that, you’re not ready to define your assessment boundary, control baseline, or budget.

FREE Compliance Check – You Are In Scope

Where CUI Sneaks Into FCI Environments

The trap that catches most contractors: CUI doesn’t always arrive announced. Government program offices are supposed to mark CUI explicitly, and increasingly they do — but the workflow downstream is where it gets messy. CUI infiltrates FCI environments constantly, usually without anyone making a deliberate decision.

A few common scenarios:

Email attachments. A government engineer emails a technical drawing to your project manager. The email is FCI. The attachment is CUI. The moment that the email lands in your inbox, your email system is in CUI scope.

Derived documents. Your engineering team takes a CUI specification, paraphrases it into a proposal section, and saves it to your shared drive. That proposal inherits the CUI classification because it contains substantive CUI content — even though it was generated in-house. The same goes for slide decks pulling text from CUI requirements documents.

Vendor and subcontractor coordination. A subcontractor needs to see a portion of a technical spec to deliver a component. If that spec is CUI, the moment it’s shared, the sub’s environment is also in CUI scope — and your prime is responsible for verifying their controls.

Backup systems. Your CUI lives on a hardened file server. But your backup writes to a general-purpose backup target on the corporate network. Now your backup environment is in the CUI scope, even if no one intended it.

The pattern: CUI follows wherever it travels. There is no “we only stored a copy temporarily” exception. If CUI was on a system, that system was in scope while it was there.

Three Common CUI vs FCI CMMC Misclassification Mistakes

Each pattern has a direct cost.

  1. Treating all data as CUI to be safe. The most expensive mistake. Smaller contractors hear “CMMC” and assume the highest bar applies to everything. If your contracts only require Level 1, applying 110 controls to all your data drives compliance costs into a territory the contract value doesn’t justify. You’re solving a $0 problem with a $100,000 solution.
  2. Treating CUI as FCI because nobody marked it. The flip side is arguably more dangerous. Government program offices don’t always mark CUI consistently, and contractors default to “if it’s not marked CUI, it must not be CUI.” Wrong. Classification depends on the content and the applicable category in the CUI Registry, not on whether someone remembered to stamp the document. Storing functional CUI on FCI-categorized systems means your assessment fails the moment it’s discovered.
  3. Not refreshing the classification when contracts change. New awards, contract modifications, new task orders under existing IDIQs, and changes in scope all introduce new data flows. We routinely see contractors whose classification was correct two years ago and is meaningfully wrong today.

How to Figure Out Which Systems Need Certification

The work is mechanical, but it’s not optional. Treat it as an inventory exercise, not an opinion exercise.

Start with the contract. DFARS clauses, SOW language, and data delivery requirements tell you what types of information will flow. Look specifically for DFARS 252.204-7012 (which signals CUI), CDRL line items, and references to ITAR or specific CUI categories.

Map every data flow. For each contract handling government data, map where data enters your environment, where it’s stored, who accesses it, what systems process it, and where it leaves.

Classify every artifact. For each piece of data in the flow, classify it as FCI-only, CUI Basic, or CUI Specified. Document the rationale. The CUI Registry is your authoritative reference.

Decide on your environment architecture. A single CMMC Level 2 environment that handles both FCI and CUI is simpler from a classification standpoint but more expensive — everything gets the 110-control treatment. Two separate environments (Level 1 for FCI-only, Level 2 enclave for CUI) require more architecture work upfront, but dramatically lower ongoing cost.

Document everything in your SSP. Whichever architecture you choose, your System Security Plan needs to clearly identify which systems are in which scope, what data they handle, and how the boundaries are enforced.

Frequently Asked Questions

Can a single contract require both Level 1 and Level 2 work?

Yes — and it happens frequently. A contract may have FCI-only deliverables (administrative work, reporting) and CUI deliverables (technical work) running in parallel. You can certify a single environment at Level 2 to cover both, or split your environments and run Level 1 self-assessment on one and Level 2 C3PAO certification on the other.

What if my contract doesn’t say anything about CUI, but I think we’re handling it?

Document your classification rationale and protect accordingly. The legal obligation to protect CUI exists regardless of whether the clause is correctly written. Contractors who assume “no clause = no CUI” routinely find themselves on the wrong end of False Claims Act exposure.

Does FCI require any third-party assessment under CMMC?

No. Level 1 (FCI-only) is an annual self-assessment plus an annual affirmation from a senior official. No C3PAO involvement. But the affirmation is a legal representation, and inaccurate Level 1 affirmations carry FCA exposure just like Level 2 ones do.

Helpful Articles & Information

How Greypike Helps GovCons Get the CUI vs FCI CMMC Line Right

Greypike works with small and mid-sized Defense Industrial Base contractors on CUI vs FCI CMMC readiness every day, and we’ve watched enough miscategorization mistakes turn into six-figure problems to know where the leverage is. Getting the FCI-vs-CUI line right early is the cheapest, highest-impact decision in any CMMC program.

We help contractors map every contract-driven data flow, classify each artifact against the CUI Registry, and design environment architectures that keep CUI tightly contained while letting FCI-only work run in a lighter compliance posture. Greypike’s Enclave deploys a hardened, CUI-compliant VDI environment on Google or Microsoft government clouds, giving you a defensible boundary on day one.

If you’ve been treating all your government data as CUI to be safe — or none of it as CUI because nothing is marked — there’s a free tool worth running before you spend another dollar.

Use the “Am I in Scope?” Decision Tool → https://greypike.com/are-you-in-scope-tool

The tool walks you through your data flows, asks the right questions about contract clauses and CUI vs FCI CMMC categories, and produces a defensible classification for every artifact in your environment — plus a clear answer on whether you need Level 1, Level 2, or both.

Visit greypike.com or call (703) 214-9246 to talk through your scope strategy.

Greypike Inc. — Veteran-Owned. Mission-Focused. Compliance-Ready.