Skip to main content
Compliance & ATO

FCI and CUI: telling them apart in your own systems

One of these categories costs you fifteen security requirements and an annual self-attestation. The other costs one hundred and ten and an assessment. Nothing about your company decides which applies — the data does. And the data does not always arrive labeled.

Engineering perspective, not legal advice Written by engineers who build and instrument the systems this data lands in. The authoritative sources are FAR 52.204-21, Executive Order 13556 and its implementing rule at 32 CFR part 2002, the CUI Registry maintained by the National Archives, DoD Instruction 5200.48, and the DFARS clauses in your own contract. Where a determination is genuinely ambiguous, the person who resolves it is your contracting officer, in writing. Not a blog.

The two definitions, in the words that matter

Federal contract information is defined in FAR 52.204-21 as information not intended for public release, provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. The definition explicitly leaves out information the Government has already made public, and simple transactional information such as what is needed to process payments. Read plainly, that means almost every contract other than a catalog purchase produces FCI. Statements of work, delivery dates, internal correspondence about performance, draft deliverables, the milestone dates — all of it counts.

Controlled unclassified information is a narrower and more formal thing. It is government-created or government-possessed information that a law, regulation, or government-wide policy requires be safeguarded or subjected to dissemination controls. The program was established by Executive Order 13556 in 2010 and implemented for the executive branch at 32 CFR part 2002, with the National Archives maintaining a public CUI Registry that lists every approved category. The Department of Defense implements it through DoD Instruction 5200.48. CUI is supposed to arrive marked, with a banner marking, a category, and sometimes a limited dissemination control.

The relationship is not a hierarchy of sensitivity so much as two different tests. A contract that puts CUI on your systems will almost certainly also produce FCI. A contract that produces FCI may produce no CUI at all, and for a large share of software and services work it genuinely does not. That asymmetry is why the first question is always the CUI question: if the answer is a confident no, Level 1 is the ceiling, and the whole program is fifteen requirements you probably mostly satisfy already.

One distinction inside CUI is worth knowing before you read a marking. CUI Basic is handled under the default rules in the government-wide program. CUI Specified categories carry additional handling requirements set by the underlying statute or regulation, and those requirements can be stricter than the default. Export-controlled information is the example most firms meet first, and it brings obligations that exist entirely independently of CMMC — the export control rules apply whether or not a defense contract is in play.

You are probably here because

  • A prime told you that you handle CUI and you are not sure they are right
  • Your contract has DFARS 252.204-7012 in it and you want to know what that actually reaches
  • Somebody sent an unmarked spreadsheet and nobody knows what to do with it
  • You are trying to decide whether to build an enclave or secure the whole company

Start at the contract-first discovery section. The five hiding places section is the one that surprises data and AI teams. If the answer turns out to be no CUI, the last two sections tell you how to keep it that way.

Start from the contract, never from the file share

The instinct is to go looking through the shared drive. That is the wrong end. Data-first discovery finds files and cannot tell you what they legally are, because the same spreadsheet is or is not CUI depending on what authority covers it and what the government said when they handed it over. Contract-first discovery answers the legal question once and then tells you exactly what to search for.

Four documents carry the answer, and all four are in your possession already.

The clause list. Read the clauses actually incorporated in your award. DFARS 252.204-7012 is the safeguarding clause and it predates CMMC by years; it defines covered defense information and imposes obligations that stand on their own, including reporting a cyber incident to the Department within 72 hours of discovery, preserving affected system images for at least 90 days, and using cloud services that meet security requirements equivalent to the FedRAMP Moderate baseline. The presence of that clause is a strong signal that the government expects covered defense information to reach you. Its absence is a weaker signal in the other direction, because flowdown terms from a prime can carry the same expectations.

The data requirements list. Contract deliverables are enumerated on data item descriptions, and each one carries a distribution statement. A distribution statement that is anything other than the one approving public release is telling you something material about how that deliverable must be handled. This is the most under-read document in most contract files and it is often the clearest evidence available.

The statement of work. Read it for what the government will give you, not for what you will deliver. Drawings, specifications, test data, government-furnished information, access to a government system — each of those is a channel through which CUI arrives, and each one should have a named owner on your side.

What the prime's subcontract says. If you are a subcontractor, the flowdown is the operative document, and it can be broader than the underlying prime contract requires. Primes set their own sourcing standards. Read what you actually signed rather than what the program manager described.

Data-first discovery finds files. Contract-first discovery finds obligations. Only one of those tells you which of the two requirement sets you owe, and it is not the one that starts with a search box.

Marking is the government's job, and it is imperfect

Under the CUI program, the agency that designates information as CUI is responsible for marking it. In practice, marking is inconsistent. Files arrive with no banner. Technical drawings arrive with a distribution statement and no CUI marking. An engineer emails you a specification because it was faster than the portal. A prime forwards a package they received marked and strips the markings when they repackage it.

Two failure modes follow, and they cost differently.

Under-identification means CUI sits on systems that were never built to hold it, and the annual affirmation in SPRS attests to a boundary that does not describe reality. That is the expensive one. A named official signs that attestation, and the risk of a signed statement that has quietly stopped being true is not a technical risk.

Over-identification is the one nobody warns you about. Declaring everything CUI feels conservative and is not free: it drags the entire corporate network into the assessment boundary, converts machines that could have been documented as risk-managed into assets assessed against all one hundred and ten requirements, and turns a contained project into a company-wide program. We have watched firms spend a year and a large budget securing an estate that a two-week scoping exercise would have reduced to a dozen machines.

The way out of both is the same and it is unglamorous: when the marking is missing or ambiguous, ask the contracting officer in writing and keep the answer. Not the program engineer, not the prime's technical lead, and not by inference from a phone conversation. A written determination from the person with authority to make it is both the correct answer and the artifact you will want later.

What you are holdingUsually indicatesWhat to do first
A banner marking naming a CUI categoryCUI, and the category tells you whether additional handling rules attachLook the category up in the CUI Registry; check for a limited dissemination control
A technical drawing or specification with a restrictive distribution statementControlled technical information, which is a CUI categoryTreat as CUI and confirm in writing; check whether export control also applies
Government-furnished data with no markings at allUnresolved — absence of a marking is not a determinationQuarantine it, ask the contracting officer in writing, do not distribute internally meanwhile
Your own draft deliverable for a government contractFCI at minimum; CUI if it incorporates or is derived from CUITrace what went into it; derived material generally inherits the obligation
A milestone chart, invoice backup, or performance emailFCI, and usually nothing moreKeep it out of the CUI enclave so it does not enlarge the boundary
Anything the Government has published openlyNeither — public information is excluded by definitionConfirm it is genuinely the published version and not a pre-release draft

Five places CUI hides in a modern data stack

If your company runs on file shares and email, discovery is tedious but conceptually simple. If it runs on a data platform, the boundary leaks in ways that a traditional readiness checklist does not look for. These are the five we find most often.

Derived data. An extract, a join, a summary table, a chart in a dashboard. Material derived from CUI generally carries the obligation with it, and derived artifacts propagate faster than anyone tracks. A warehouse that ingests one controlled file and fans it into forty downstream tables has just enlarged your boundary by forty tables.

Model inputs and outputs. Prompts, completions, retrieval indexes, embeddings, fine-tuning sets, evaluation sets. A vector store built over controlled documents holds a transformed representation of them, and the sensible engineering assumption is that the obligation follows. If a hosted model provider is in the path, their terms and their data residency become part of your compliance position, not just your procurement position.

Logs and telemetry. Application logs that capture request payloads. Error traces with document snippets. Analytics events carrying filenames. Support tooling that mirrors user sessions. This is the leak that survives every boundary redesign, because logging is configured by developers solving a different problem.

Backups, snapshots and replicas. A backup of a machine inside the boundary is inside the boundary. So is the read replica in another region, the snapshot in the old account, and the export somebody made for a migration in 2024 and never deleted.

Software-as-a-service in the workflow. Ticketing systems with attachments. Design tools. Transcription. Note-takers. Code hosting with issue attachments. Each of these is an external service provider in the scoping sense, and each needs a written answer about what it stores and where.

Where we find unexpected controlled data — our read

Email attachments and forwarded threads
90
Personal folders on general-purpose file shares
82
Ticketing and project tool attachments
68
Application logs and error traces
60
Derived tables and dashboards
54
Retrieval indexes and evaluation sets
44

Our judgment from doing this work, not a survey. The bottom two rows are newer, less looked-for, and growing fastest.

The decision that follows the answer

Once you know which category applies, one design decision determines the size of everything downstream: whether CUI is allowed to exist anywhere in the company, or only inside a deliberately small enclave reached through controlled interfaces.

The scoping rules make this concrete. Systems that process, store or transmit CUI are assessed against the full requirement set. Systems that provide security functions to that environment are assessed for what they do. Systems kept clear of CUI by policy and procedure are documented and risk-managed rather than fully assessed. Systems that cannot hold CUI and provide no security function are out of scope entirely. An enclave is simply the deliberate use of those categories: one small assessed environment, everything else documented as kept clear.

The enclave costs something real. There is a transfer point, and the transfer point is friction that engineers will route around unless it is genuinely usable. Building an enclave people hate is how CUI ends up in a personal folder. The design goal is not maximum restriction; it is a path of least resistance that happens to be the compliant one.

The alternative — treat the whole company as in scope — is defensible for a firm whose entire business is one program with controlled data everywhere. For anyone else it is a much larger bill for the same contract.

When the honest answer is that you do not have CUI

This is more common than the market implies, and it is worth stating plainly because nobody selling readiness services will say it.

A firm delivering commercial software under a catalog-style award, a services firm whose deliverables are all approved for public release, a subcontractor doing work whose outputs carry no restrictive distribution statement — these firms have FCI and no CUI. Their obligation is fifteen requirements, self-assessed annually, with results and an affirmation posted in SPRS. There is no assessment to buy and no enclave to build. Do the fifteen properly, document them, keep the affirmation honest, and spend the rest of the budget on the business.

Two cautions on that. The acquisition rule excludes awards solely for commercially available off-the-shelf items and does not reach acquisitions at or below the micro-purchase threshold, but it does apply to commercial products and services acquired under FAR part 12 — commercial-item status is not by itself an exemption, which surprises people. And a no-CUI position is a live position, not a permanent one. It changes the first time a government engineer emails you a drawing.

So make the determination reviewable. Write down what you concluded, what you relied on, and who confirmed it. Re-run it at every new award, every modification that adds a data deliverable, and every time a prime sends a new flowdown. A determination that was correct eighteen months ago and has never been revisited is the same category of risk as an assessment that has drifted.

What is still moving

Two things are worth watching if you are planning past this fiscal year.

The government-wide CUI rule for the Federal Acquisition Regulation was published as a proposed rule in January 2025 and, as of this writing, had not been issued in final form. The proposal contemplates standardized identification of CUI requirements on contracts across the civilian side of government, which would change the picture for firms whose federal work has never touched the Department of Defense. Check the docket rather than assuming either outcome; it is a live matter, not settled law.

And the CMMC phase-in itself is under review. The Department suspended the Phase 2 requirements in July 2026, pending a reform review, while leaving Phase 1 award conditions, the DFARS safeguarding clause, and the annual affirmation entirely in place. None of that changes the FCI-versus-CUI determination. The obligation to protect controlled unclassified information on a nonfederal system lives in the safeguarding clause and the underlying standard, not in the phase-in calendar.

The mistakes we see most

  • Searching the file share first instead of reading the contract that creates the obligation
  • Treating an unmarked file as unregulated — absence of a marking is not a determination
  • Declaring everything CUI to be safe, which quietly buys a company-wide assessment
  • Reading distribution statements as a formatting detail rather than as a handling instruction
  • Forgetting derived data, so the boundary excludes the tables that contain the actual content
  • Overlooking logs and retrieval indexes, which hold controlled content in a shape nobody searches for
  • Resolving ambiguity in a hallway conversation instead of in writing with the contracting officer
  • Making the determination once and never revisiting it at the next modification

A determination you can defend

  • Every active award has been read for its safeguarding clauses and flowdowns
  • Data deliverables and their distribution statements are listed in one place
  • Each channel through which government data arrives has a named owner
  • Ambiguous items were resolved in writing by the contracting officer
  • Derived data, indexes, logs and backups were included in the search
  • Every external service in the workflow has a written answer about what it stores
  • The boundary decision — enclave or whole estate — was made deliberately
  • The determination is written down with its basis and its date
  • A re-review is triggered by each new award and each modification
  • The person signing the annual affirmation has read the determination

Bottom line

FCI and CUI are not degrees of the same thing. They are two definitions, in two different documents, that select between fifteen requirements and one hundred and ten. Almost every government contract produces FCI. A much smaller share produces CUI, and the ones that do usually say so somewhere in the contract file even when the files themselves arrive unmarked. Read the contract first, quarantine what you cannot classify, get the ambiguous cases answered in writing, and then decide deliberately whether controlled data is allowed to live anywhere outside a small, well-instrumented enclave. That sequence takes a couple of weeks and it sets the size of every bill that follows.

Frequently asked questions

If a file has no CUI marking, is it safe to treat as ordinary business data?

No. Marking is the designating agency's responsibility and it is frequently incomplete, so an unmarked file is unresolved rather than cleared. The practical handling is to quarantine it, avoid distributing it internally, and ask the contracting officer in writing whether it is CUI. Keep the answer — it is both the determination and the evidence that you made one.

Does data we generated ourselves count?

It can. The safeguarding clause reaches information collected, developed, received, transmitted, used or stored by the contractor in support of contract performance, not only what the government hands over. A report you wrote that incorporates controlled technical information generally carries the obligation forward. Trace what went into a deliverable rather than assuming authorship settles it.

Is controlled technical information the same as CUI?

Controlled technical information is one category within the CUI program — technical information with military or space application whose access, use or distribution is controlled. In practice it is the category most defense suppliers meet first, and it usually announces itself through a restrictive distribution statement on a drawing or specification rather than through a CUI banner. Look the category up in the CUI Registry to see what handling rules attach.

Can a prime decide that we handle CUI when the contract does not say so?

A prime can impose whatever terms you agree to in a subcontract, and many impose more than the underlying contract requires. That is a commercial decision, not a regulatory one, and it is negotiable before signature and much less negotiable after. If the flowdown asserts CUI handling and you believe the work does not involve CUI, raise it during negotiation and ask what data they intend to send you.

Does any of this apply outside the Department of Defense?

The CUI program itself is government-wide, established by executive order and implemented at 32 CFR part 2002, so civilian agencies designate CUI too. CMMC is a Department of Defense program implemented through DFARS clauses and does not attach to civilian contracts. A proposed government-wide CUI rule for the Federal Acquisition Regulation was published in January 2025 and had not been finalized as of this writing, so check its current status before planning around either outcome.

1 business day response

Not sure whether what you are holding is CUI?

Send the clause list and the data deliverables from one award, and we will tell you plainly what appears to be in play and what to put to your contracting officer in writing. Email bo@precisionfederal.com.

Email an engineerCapabilitiesMore insights →
FCICUI RegistryDFARS 252.204-7012Enclave Scoping