Federal Contract Information
Federal Contract Information (FCI) is information that is not meant to be released to the public and that a contractor either receives from the government or creates for the government while performing a contract. It is tied directly to the work of delivering a product or service to a federal agency. It generally does not include information the government intends to make publicly available or simple transactional information such as that needed to process payments.
Federal Contract Information, as defined in FAR 48 CFR 52.204-21, means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. Under the FAR safeguarding framework, contractors handling FCI on a 'covered contractor information system' (an information system owned or operated by a contractor that processes, stores, or transmits FCI) are generally subject to the basic safeguarding requirements set out in FAR 52.204-21. FCI is distinct from Controlled Unclassified Information (CUI); while related, the two are governed by different authorities and carry different safeguarding obligations, and practitioners should not treat them as interchangeable. Readers should verify the current text of FAR 52.204-21 and 4.1901, as well as any applicable exclusions (for example, information the Government intends to make public or that is required to process payment), against authoritative sources, since specific scope determinations can carry agency- and contract-specific interpretations not fully captured here.
Why it matters
Federal Contract Information marks the entry point at which a federal contractor's information systems come under baseline government safeguarding obligations. Any organization that receives non-public information from an agency, or generates such information while developing or delivering a product or service under a contract, is generally handling FCI. Under FAR 52.204-21, contractors whose covered information systems process, store, or transmit FCI are subject to a set of basic safeguarding requirements. Because the FAR clause is incorporated into a wide range of federal contracts, FCI often defines the minimum floor of security responsibility a contractor must meet, and misjudging whether information qualifies can leave a contractor out of compliance with clause terms it has already agreed to.
A frequent and consequential error is conflating FCI with Controlled Unclassified Information (CUI). The two categories are related but distinct: they are governed by different authorities and carry different safeguarding obligations, and treating them as interchangeable can lead a contractor either to under-protect CUI or to misapply requirements to information that is only FCI. The National Archives' Information Security Oversight Office has publicly addressed this distinction to help practitioners understand where the line falls. Compliance officers should map their contract data flows carefully rather than assuming a single control set covers everything.
Equally important is recognizing what FCI is not. Information the Government intends to make public, and simple transactional information such as that required to process payment, is generally excluded from the definition. Overclassifying ordinary or public-facing information as FCI can create unnecessary safeguarding burden, while failing to recognize genuine FCI can create compliance gaps. Because scope determinations can carry agency- and contract-specific interpretations, practitioners should verify the current FAR text and any applicable exclusions against authoritative sources rather than relying on general summaries.
Who it's relevant to
Inside FCI
Common questions
Answers to the questions practitioners most commonly ask about FCI.