Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
START WITH DATA

CMMC Levels Explained: FCI vs CUI Decision Guide

A data-first way to understand CMMC Level 1 and Level 2 by separating FCI from CUI before choosing controls, tools, or assessors.

Illustration of a nested folder showing CUI data inside a larger FCI folder, representing the data-first CMMC level decision.

Choosing a CMMC level begins with the information, not with a cybersecurity product. Federal Contract Information and Controlled Unclassified Information are different categories with different safeguarding consequences. If sales, engineering, and IT use the labels loosely, the company can either overbuild an expensive environment or, worse, leave CUI in a system designed only for basic FCI safeguards.

The practical method is to keep a small data inventory that records where government information came from, how it is marked or identified, what contract it supports, where it travels, and which systems can reach it. Once the data path is clear, the CMMC level in the solicitation and the technical boundary become much easier to interpret.

FAR 4.1901 defines Federal Contract Information around information provided by or generated for the Government under a contract that is not intended for public release, with exclusions such as information the Government has made public and simple transactional information used to process payments. That definition is narrower than 'anything related to a federal customer.'

FCI is contract information that is not meant for public release

Examples can include non-public delivery details, internal contract communications, or work-product information generated for performance, depending on the facts. Do not invent FCI labels from intuition. Record the contract context and the information source, especially when the same project folder also contains public specifications or ordinary invoicing data that may fall outside the definition.

CUI is a governmentwide controlled category

CUI is information the Government creates or possesses — or that an entity creates or possesses for or on behalf of the Government — that a law, regulation, or governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls. The National Archives CUI Registry is the authoritative place to examine categories and authorities.

That means 'company confidential,' export-controlled, ITAR-related, proprietary, and CUI are not interchangeable labels. They can overlap in a real project, but one term does not automatically prove another. Preserve markings, contract instructions, and the identified CUI category so the security team can protect the right information for the right reason.

How the information type relates to CMMC levels

The current CMMC model associates Level 1 with basic safeguarding of FCI and Level 2 with broad protection of CUI using the NIST SP 800-171 requirement set applied by the program. The solicitation still controls the award requirement, so the data classification exercise should inform your readiness planning rather than replace reading the procurement.

For mixed work, the system boundary becomes critical. A company may keep ordinary corporate operations and FCI in one environment while restricting CUI to a dedicated enclave, provided the architecture and procedures actually prevent unapproved paths. Conversely, letting CUI flow through general email, unmanaged devices, or shared SaaS can pull more of the environment into scope.

Build a data inventory that engineers can use

A useful inventory row includes the data set or document type, contract or program, source, marking, information category, system of record, approved collaboration path, backup location, external recipients, and retention or disposal rule. This is not a giant data-classification project; it is a map of the government information that drives CMMC scope.

Use real samples during workshops. Ask the program manager to bring representative files and messages with sensitive values removed. Trace how each enters the company and where employees actually put it. The exercise often reveals unofficial copies in email, downloads, local folders, printer queues, or ticket attachments that a policy review would miss.

Resolve ambiguous labels before they spread

When a file is unmarked or the handling instruction conflicts with the contract, do not let individual employees guess. Establish an escalation path to the contract or program owner and, when appropriate, the Government point of contact. Keep the resulting clarification with the data inventory so the same question does not reappear in every department.

Also keep internal labels distinct. A banner such as 'sensitive' can be useful operationally, but it should not erase the authoritative category underneath it. Your inventory should preserve whether the material is FCI, CUI, both in different portions, or governed by another requirement entirely. Clear labels make later scoping and incident analysis much faster.

Use the answer to narrow — not weaken — the environment

The point of classification is to apply the right protection and avoid unnecessary scope. If only a small engineering group receives CUI, a properly designed enclave may be more practical than treating every corporate system as part of the Level 2 assessment scope. If everyone receives FCI but no CUI, Level 1 may describe the relevant CMMC requirement for certain solicitations.

Revisit the data map when contracts change. New statements of work, subcontractor relationships, customer portals, file-transfer methods, and engineering deliverables can change what enters the environment. A quarterly review with contracts, program management, and IT is usually enough to catch those changes before the next proposal or assessment.

A classification workshop that avoids acronym arguments

Bring contracts, program management, engineering, and IT together with three to five representative document types. Remove sensitive values if necessary. For each sample, record who created it, the contract it supports, any Government marking or instruction, whether it is intended for public release, and the authoritative category or handling source used for the decision.

Do not begin by asking the IT team to decide whether a file is CUI from its technical appearance. A PDF drawing can be public, proprietary, export-controlled, CUI, or several things at once depending on the source and authority. Contracts and program context have to inform the label before technology can protect it correctly.

When the classification question stays unresolved

After classification, trace each sample through the normal workflow. The group may discover that FCI lives in general business email while CUI is intended for an enclave, but engineers routinely copy CUI project numbers into a standard ticketing system. That finding is a scope and process issue that no abstract definition would reveal.

End the workshop with unresolved items assigned to a named owner and an authoritative source to consult. The objective is not to settle every theoretical classification question. It is to prevent ambiguous data from silently entering systems whose controls were chosen for a different information type.

When the classification is unclear, preserve the ambiguity instead of laundering it into a confident label. Record the document or data set, who supplied it, the contract or program context, why the team thinks it may be FCI or CUI, and who owns the question. Then resolve it with the contracting or program channel that can give an authoritative answer. A temporary 'classification pending' state is healthier than a spreadsheet that quietly marks everything as CUI—or everything as ordinary business data—because nobody wanted to stop the workflow.

WORKING CHECKLIST

A short working check

  • Collect sample contract data
  • Identify FCI and CUI separately
  • Check CUI categories against the Registry
  • Trace where each data type enters and leaves
  • Map systems that touch the data

Common questions

Is all sensitive company data CUI?

No. CUI is a government-defined category. Company-confidential information can be sensitive without being CUI.

Does handling FCI automatically mean Level 2?

Not by itself. Level 1 is associated with FCI; Level 2 becomes relevant when the contract and system involve CUI.

If a file is unmarked, can the team assume it is not CUI?

No. Markings are useful evidence, but classification depends on the contract, the information's source and governing authority, and applicable agency instructions. Escalate ambiguous material instead of treating missing markings as proof that CUI rules do not apply.

Official sources used for this guide

Open the primary source before making a contract-specific decision. Regulations and program implementation can change.