For defense suppliers Practical guide

FCI or CUI? Start with the information and the contract

A request for a security status needs a clear description of the information behind it. Start with the contract and the information flow. Then choose the route.

Federal Contract Information, or FCI, is information provided by or generated for the Government under a contract to develop or deliver a product or service when it is not intended for public release. Public information and simple payment information are excluded. FAR 52.204-21 requires basic safeguarding of covered contractor information systems that process, store, or transmit FCI. It also sets a subcontract condition, subject to the clause’s stated exclusions.

Controlled Unclassified Information, or CUI, is government-related information for which law, regulation, or government-wide policy requires or permits safeguarding or dissemination controls. In defense work, contract terms and the actual information determine whether your work involves covered defense information and the security obligations that follow. DFARS 252.204-7012 addresses covered defense information and refers to NIST SP 800-171 requirements for covered contractor information systems. Use the revision named in the governing terms. Rev. 2 remains the baseline in the Department’s current CMMC implementation guidance, even though NIST has published Rev. 3. Current baseline.

The labels do not rank maturity. FCI is not “light CUI.” CUI is not a name for every sensitive customer file. Treating either as a shortcut leads to the wrong scope or evidence request.

Deep Fathom Updated September 13, 2026

Ask five questions before you choose a path

What do the terms say?

Read the contract and subcontract. The clause and flowed-down terms set the obligation.

What is the information?

Identify its source, markings, handling instructions, and unresolved questions. A customer label alone may not settle the classification.

NDIA’s 2026 report describes industry concerns about inconsistent CUI markings. Record the uncertainty and ask your customer to resolve it before planning around a label. NDIA report, page 32.

Where does it move?

Map receipt, storage, processing, sharing, and disposal through the work. That map shows where the obligation applies.

Which systems and people touch it?

Define the operational boundary your implementation must cover. Include service providers when their services support the covered work.

What response does the customer require?

Separate basic safeguards, NIST-based work, assessment status, evidence, and customer review. Each asks your team to do something different.

For example, a distributor receives a purchase order and delivery schedule for a government program. That information may call for an FCI analysis under the relevant terms. Later, the distributor receives technical drawings with controlled markings and stores them in a separate collaboration environment. The second fact changes the questions. Document the information, system boundary, and clauses for that work rather than applying the first conclusion to both environments.

Keep Level 1 and Level 2 in their lanes

The CMMC clause describes different levels and assessment routes. In broad terms, Level 1 aligns to the FAR basic safeguarding requirements and uses a self-assessment route when the governing terms require it. Level 2 concerns the NIST SP 800-171 Rev. 2 requirements for the relevant systems and has its own assessment and affirmation structure. The solicitation or contract, work, and current implementation direction decide the route. A request for “CMMC” does not decide it by itself.

For current context, the Department announced a suspension of Phase II requirements in July 2026 while retaining Phase I self-assessments. That announcement does not resolve an individual contract. Read the announcement, then check the implementing instructions, your actual terms, and applicable amendments or modifications.

Deep Fathom helps teams organize requirements, assigned work, and evidence tied to the relevant systems and information. It does not classify information or decide applicability for your contract. Bring one requirement, a description of the information, and the supporting systems to a platform evaluation conversation.

Build the implementation plan. Return to the hub.

Related reading

Put the requirements into practice.

Work with Deep Fathom

See how Deep Fathom fits your work.

Tell us what defense work you are pursuing or performing, the requirement your customer has raised, and where your team needs help. Our team will discuss the relevant platform workflow and support options.