Skip to main content
Truvisory
Federal

What Is FCI (Federal Contract Information)?

Tony Adams9 min read

Every conversation about CMMC eventually arrives at the same question: do we even handle FCI? It’s the right question, because FCI is the trigger. If your systems hold it, the fifteen basic safeguards of FAR 52.204-21 apply and CMMC Level 1 is your floor. If they genuinely don’t, most of the CMMC conversation isn’t about you.

And yet FCI is chronically misexplained — usually by dropping the two exclusions built into its definition, which conveniently makes everything on a government contract sound like FCI and every contractor sound like they need help. So let’s start with the actual words.

The FAR 4.1901 definition, taken apart

Here is the definition, verbatim — it appears at FAR 4.1901 and again word-for-word in FAR 52.204-21(a):

Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments.

Three moving parts:

“Not intended for public release.” FCI is non-public by definition. If the information was meant to be published, it isn’t FCI.

“Provided by or generated for the Government under a contract to develop or deliver a product or service.” Both directions count — what the Government hands you and what you create for the Government in performance. And it’s tied to a contract: information floating around your company with no connection to developing or delivering something for the Government doesn’t meet the definition.

The two exclusions. First, information provided by the Government to the public — the example the FAR itself gives is public websites. A specification posted on a public site doesn’t become FCI because it later shows up in your contract folder. Second, simple transactional information, such as necessary to process payments — routine banking and invoicing plumbing isn’t FCI either.

What typically remains inside the definition, applying its own terms: the non-public content of your contract and orders, deliverables and technical work products you generate for the Government, performance information exchanged with your contracting office — the working substance of the engagement that was never meant for public release. When in doubt, run the two-part test: non-public? provided-by-or-generated-for, under the contract? If both yes and no exclusion applies, treat it as FCI.

FCI vs. CUI

The distinction that decides your compliance tier — and your cost structure:

// FCI vs. CUI — what each category triggers
FCICUI
Defined byFAR 4.1901Executive Order 13556 (the CUI program)
Baseline safeguardsThe 15 basic safeguards of FAR 52.204-21NIST SP 800-171 (110 controls) under DFARS 252.204-7012
CMMC levelLevel 1Level 2 at minimum
VerificationAnnual self-assessment in SPRS + annual affirmationSelf-assessment; the third-party (C3PAO) path is currently suspended
Cloud requirementNone specific in FAR 52.204-21FedRAMP Moderate (authorized or equivalent) per DFARS 252.204-7012(b)(2)(ii)(D)
Incident reportingNone in FAR 52.204-2172-hour cyber incident reporting under DFARS 252.204-7012

Two notes on reading that table honestly. First, the categories nest in practice: a contractor handling CUI almost certainly handles FCI too, so the CUI column’s obligations sit on top of the FCI column’s — FAR 52.204-21(b)(2) says explicitly that the clause doesn’t relieve you of CUI safeguarding requirements under Executive Order 13556. Second, the CMMC program even encodes the relationship: Level 1 assessment objectives are the NIST SP 800-171A objectives with FCI substituted wherever the objective says CUI (32 CFR § 170.15(c)(1)(i)). Level 1 genuinely is the foundation layer of CMMC Level 2 — the same control families, at basic depth.

What handling FCI obligates you to do

If FCI touches your systems, three things follow:

The fifteen safeguards apply. FAR 52.204-21 requires them on every covered contractor information system — meaning every system of yours that processes, stores, or transmits FCI. That system-level scoping is the practical mercy of Level 1: the CMMC assessment scope is those systems (32 CFR § 170.19(b)(1)), not your entire company, and Specialized Assets — IoT, operational technology, Government-Furnished Equipment, Restricted Information Systems, Test Equipment — are not part of the Level 1 scope and are not assessed.

A CMMC Level 1 self-assessment, when your solicitation specifies it. New DoD solicitations have carried CMMC requirements since November 10, 2025, and when a CMMC level is specified it must be met before award. For FCI-only contractors that means Level 1: an annual self-assessment against the 15 CMMC Level 1 requirements and their 59 objectives, results entered in SPRS, affirmed annually by a senior company official — the mechanics are in our SPRS score submission walkthrough. Since the CMMC Phase II suspension, Level 1 (Self) is one of only two CMMC postures a contracting officer may currently designate, which has made the honest self-assessment the primary trust artifact rather than a warm-up act.

It flows down. Paragraph (c) of the clause pushes the same substance into subcontracts wherever FCI resides in or transits a sub’s systems. Being small, commercial, or two tiers down doesn’t exempt you — only COTS items are carved out.

None of that requires a certification, a consultant, or — for most small shops — new hardware. It requires knowing where FCI lives in your systems and being able to answer 59 plain questions honestly. That’s exactly what our free CMMC Level 1 self-assessment builder does: it walks you through scoping and all fifteen requirements in plain language, then generates the full document package if you pass — or a prioritized gap plan if you don’t. Free, in your browser, answers never uploaded.

Frequently asked

What does FCI stand for?
Federal Contract Information — information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. The definition excludes information the Government provides to the public (such as on public websites) and simple transactional information, such as that necessary to process payments.
Where is FCI defined?
In FAR 4.1901, and verbatim in paragraph (a) of FAR 52.204-21 itself. The CMMC program rule (32 CFR § 170.4) defines FCI by reference to 48 CFR 4.1901, so the FAR definition is the one that governs everywhere.
Is FCI the same as CUI?
No. FCI is the broader, lower-sensitivity category: non-public information provided by or generated for the Government under contract. CUI — Controlled Unclassified Information, established by Executive Order 13556 — carries its own federal safeguarding requirements: the NIST SP 800-171 control set under DFARS 252.204-7012 and at least CMMC Level 2. FCI alone triggers only the 15 basic safeguards of FAR 52.204-21 and CMMC Level 1.
Is every document on a government contract FCI?
No — the definition has two built-in exclusions. Information the Government has provided to the public (a spec posted on a public website, for example) is not FCI, and neither is simple transactional information such as that necessary to process payments. What remains — non-public information provided by or generated for the Government under the contract — is.
Does handling FCI mean I need a CMMC certification?
No certification exists at Level 1. Handling FCI puts you in CMMC Level 1 territory, which is verified by an annual self-assessment entered in SPRS plus an annual affirmation — no third-party assessor. When a solicitation specifies a CMMC requirement, it must be met before award.
Do subcontractors have to worry about FCI?
Yes. FAR 52.204-21(c) requires primes to flow the substance of the clause into subcontracts — including subcontracts for commercial products and services, COTS items excepted — wherever the subcontractor may have FCI residing in or transiting through its information system.
§ Field notes — monthly

One email a month. Not a vendor blog.

// Signing up gets you the AI pilot go/no-go checklist + one field-note a month — no drip, one-click unsub