Skip to main content
Category: Controlled Unclassified Information

Federal Contract Information

Also known as:
Simply put

Federal Contract Information (FCI) is information that is not meant to be released to the public and that a contractor either receives from the government or creates for the government while performing a contract. It is tied directly to the work of delivering a product or service to a federal agency. It generally does not include information the government intends to make publicly available or simple transactional information such as that needed to process payments.

Formal definition

Federal Contract Information, as defined in FAR 48 CFR 52.204-21, means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. Under the FAR safeguarding framework, contractors handling FCI on a 'covered contractor information system' (an information system owned or operated by a contractor that processes, stores, or transmits FCI) are generally subject to the basic safeguarding requirements set out in FAR 52.204-21. FCI is distinct from Controlled Unclassified Information (CUI); while related, the two are governed by different authorities and carry different safeguarding obligations, and practitioners should not treat them as interchangeable. Readers should verify the current text of FAR 52.204-21 and 4.1901, as well as any applicable exclusions (for example, information the Government intends to make public or that is required to process payment), against authoritative sources, since specific scope determinations can carry agency- and contract-specific interpretations not fully captured here.

Why it matters

Federal Contract Information marks the entry point at which a federal contractor's information systems come under baseline government safeguarding obligations. Any organization that receives non-public information from an agency, or generates such information while developing or delivering a product or service under a contract, is generally handling FCI. Under FAR 52.204-21, contractors whose covered information systems process, store, or transmit FCI are subject to a set of basic safeguarding requirements. Because the FAR clause is incorporated into a wide range of federal contracts, FCI often defines the minimum floor of security responsibility a contractor must meet, and misjudging whether information qualifies can leave a contractor out of compliance with clause terms it has already agreed to.

A frequent and consequential error is conflating FCI with Controlled Unclassified Information (CUI). The two categories are related but distinct: they are governed by different authorities and carry different safeguarding obligations, and treating them as interchangeable can lead a contractor either to under-protect CUI or to misapply requirements to information that is only FCI. The National Archives' Information Security Oversight Office has publicly addressed this distinction to help practitioners understand where the line falls. Compliance officers should map their contract data flows carefully rather than assuming a single control set covers everything.

Equally important is recognizing what FCI is not. Information the Government intends to make public, and simple transactional information such as that required to process payment, is generally excluded from the definition. Overclassifying ordinary or public-facing information as FCI can create unnecessary safeguarding burden, while failing to recognize genuine FCI can create compliance gaps. Because scope determinations can carry agency- and contract-specific interpretations, practitioners should verify the current FAR text and any applicable exclusions against authoritative sources rather than relying on general summaries.

Who it's relevant to

Government contractors and subcontractors
Organizations performing under federal contracts that incorporate FAR 52.204-21 need to identify which of their systems handle FCI, since those covered contractor information systems are generally subject to the clause's basic safeguarding requirements. Subcontractors receiving or generating non-public information in support of contract performance may carry the same obligations and should verify how the clause flows down.
Compliance officers and ISSMs
Those responsible for compliance should map contract data flows to distinguish FCI from CUI and from excluded categories such as public or payment-processing information. Because FCI and CUI are governed by different authorities and carry different safeguarding obligations, treating them as interchangeable risks both over- and under-protection, and scope determinations should be confirmed against current authoritative text.
Contracting and acquisition personnel
Personnel who draft, negotiate, or administer contracts should understand where FAR 52.204-21 applies and how the FCI definition and its exclusions affect safeguarding expectations. Where a specific scope determination is unclear, they are positioned to consult the current FAR text and agency-specific interpretations rather than relying on general summaries.
Auditors and assessors
Those evaluating a contractor's safeguarding posture need to confirm whether information at issue meets the FCI definition, whether the relevant systems qualify as covered contractor information systems, and whether recognized exclusions apply. Assessment findings should be anchored to the current authoritative text, since scope can carry agency- and contract-specific nuance.

Inside FCI

Definition and Origin
Federal Contract Information (FCI) is information provided by or generated for the U.S. Government under a contract to develop or deliver a product or service to the Government. The term is defined in the FAR, notably in connection with FAR clause 52.204-21.
Exclusions
FCI generally does not include information the Government provides to the public (such as content on public-facing websites) or simple transactional information, such as that necessary to process payments. Practitioners should verify current FAR text for the precise scope.
Relationship to Basic Safeguarding Requirements
FAR clause 52.204-21 generally establishes a set of basic safeguarding requirements applicable to covered contractor information systems that process, store, or transmit FCI. These are considered a baseline of security requirements rather than a comprehensive control set.
Distinction from CUI
FCI is a distinct category from Controlled Unclassified Information (CUI). CUI carries additional safeguarding obligations, and requirements for protecting CUI are handled under separate authorities (for example, DFARS clause 252.204-7012 and NIST SP 800-171) rather than the basic FCI safeguarding requirements.
Role in Emerging Assessment Frameworks
The handling of FCI is relevant to the Cybersecurity Maturity Model Certification (CMMC) program, where the protection of FCI generally corresponds to a foundational tier. Because CMMC has been subject to phased rollout and revisions, readers should confirm current requirements against official DoD CIO and CMMC program sources.

Common questions

Answers to the questions practitioners most commonly ask about FCI.

Is Federal Contract Information the same as Controlled Unclassified Information (CUI)?
No. FCI and CUI are distinct categories, and treating them as interchangeable is a common error. FCI is generally understood as information provided by or generated for the government under a contract that is not intended for public release, but it is not identical to CUI. CUI is a broader designation governed by the National Archives and Records Administration (NARA) CUI program and carries additional safeguarding and marking requirements. Some CUI may also be FCI, but FCI is not automatically CUI, and the safeguarding expectations differ. Verify the specific category of your information against the applicable contract terms and current authoritative sources before assigning protections.
Does meeting FCI safeguarding requirements mean my organization is also compliant with CUI or higher-level requirements?
Not necessarily. The safeguarding measures generally associated with protecting FCI represent a baseline and should not be assumed to satisfy the more extensive requirements applied to CUI. Organizations handling CUI are typically subject to additional obligations beyond those tied to FCI alone. Compliance with FCI-level expectations does not, on its own, demonstrate readiness for CUI protection, DoD-specific requirements, or any particular assessment or certification level. Confirm which category of information you handle and map your controls to the correct set of requirements in the current governing text.
How do we determine whether information in our contract qualifies as FCI?
Determination generally begins with reviewing the contract language and the nature of the information involved. FCI is commonly described as information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service. Information already made public or intended for public release is generally excluded. Because contract-specific terms and agency interpretations can affect the determination, coordinate with your contracting officer and confirm the classification against the applicable contract clauses and current authoritative guidance rather than relying on assumptions.
Who within our organization should be responsible for identifying and protecting FCI?
Responsibility is typically shared across contracts, information security, and program management functions. Contracts personnel generally help identify FCI obligations flowing from contract clauses, while information system security roles address the safeguarding measures. Assigning clear ownership helps ensure that FCI is identified when received or generated and that appropriate protections are applied to the systems that process, store, or transmit it. The specific allocation of roles should align with your organization's governance structure and any role-related expectations stated in the applicable contract.
What systems need to be scoped when protecting FCI?
Scoping generally focuses on the information systems and components that process, store, or transmit FCI. Accurately defining this boundary is important because it determines where safeguarding measures apply and can affect the effort required for any related assessment. Overly broad scoping can increase burden, while overly narrow scoping can leave FCI unprotected. Document the flow of FCI through your environment and confirm the scope against contract requirements and current authoritative guidance, as scoping expectations can be affected by agency-specific interpretations.
How does the presence of FCI in a contract affect our compliance obligations?
The presence of FCI generally triggers safeguarding expectations that flow from the contract's clauses, and those obligations may increase if the same contract also involves CUI or DoD-specific requirements. Because obligations depend on the exact clauses incorporated and can change across revisions of the governing text, review each contract individually rather than assuming a uniform requirement set. Confirm the applicable clauses with your contracting officer and verify current safeguarding expectations against the authoritative sources referenced in the contract.

Common misconceptions

FCI and CUI are the same thing, so protecting one automatically satisfies the other.
FCI and CUI are distinct categories governed by different requirements. The basic safeguarding requirements associated with FCI (FAR 52.204-21) are generally a baseline, whereas CUI protection is addressed under separate authorities such as DFARS 252.204-7012 and NIST SP 800-171. Meeting FCI safeguarding requirements does not, on its own, satisfy CUI obligations.
Any information exchanged with the Government under a contract counts as FCI.
FCI generally excludes information the Government provides to the public and simple transactional information necessary to process payments. The precise scope depends on the applicable FAR definition, which should be verified against current authoritative text.
Complying with the basic FCI safeguarding requirements means a contractor is fully secure or fully compliant with all federal cybersecurity obligations.
The FCI safeguarding requirements represent a baseline rather than a comprehensive security program, and compliance is not equivalent to security. Contracts involving CUI or subject to CMMC or DFARS requirements typically impose additional obligations that must be confirmed against the specific contract and current authorities.

Best practices

Review each contract and its clauses to determine whether FAR 52.204-21 applies and to identify whether the engagement also involves CUI subject to additional authorities such as DFARS 252.204-7012 and NIST SP 800-171.
Maintain a clear inventory of which information systems process, store, or transmit FCI so that the basic safeguarding requirements can be applied to the correct covered systems.
Distinguish FCI from CUI in your data classification and handling procedures, since the two categories carry different safeguarding obligations.
Treat the FCI safeguarding requirements as a baseline and confirm against the specific contract whether additional controls or assessment obligations (for example, under CMMC) apply.
Verify the current scope and definition of FCI against the applicable FAR text rather than relying on prior versions, as terminology and requirements can change across revisions.
Monitor DoD CIO and CMMC program guidance for updates relevant to FCI handling, given the phased rollout and revisions of the CMMC framework.