FCI vs. CUI: What DoD Subcontractors Need to Know Before CMMC
The information your systems process, store, or transmit can change the CMMC level and assessment path that applies to a DoD subcontract.
“Do we have CUI?” is one of the most important pre-award questions in a DoD subcontract. But it helps to start one step earlier: determine what Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) will actually move through your company’s systems during performance.
The difference matters because the CMMC program ties subcontractor requirements to the information handled on contractor information systems, not simply to the fact that the customer is the Department of Defense.
What is Federal Contract Information?
FAR 4.1901 defines FCI as information not intended for public release that is provided by or generated for the Government under a contract to develop or deliver a product or service. The definition excludes information the Government has made public and simple transactional information such as information necessary to process payments.
FAR Subpart 4.19 applies when a contractor information system may contain FCI, and FAR 52.204-21 provides the basic safeguarding requirements used by CMMC Level 1.
Official source: FAR 4.1901, Definitions.
What is Controlled Unclassified Information?
CUI is unclassified information that a law, regulation, or Government-wide policy requires or permits an agency to protect with safeguarding or dissemination controls. In the CMMC context, the current DFARS clause uses the 32 CFR definition and ties system requirements to whether FCI or CUI will be processed, stored, or transmitted during contract performance.
CUI is not simply “anything sensitive.” The underlying information category, contract requirement, marking, distribution controls, and guidance from the Government or prime all matter. If the package is unclear about what information you will receive or create, treat that as a pre-award clarification issue.
Why the distinction changes CMMC
32 CFR 170.23 sets the subcontractor flowdown framework. If a subcontractor will process, store, or transmit FCI but not CUI, Level 1 (Self) is required. If the subcontractor will handle CUI, Level 2 (Self) is the minimum, with a Level 2 C3PAO assessment required when the associated prime contract requires Level 2 (C3PAO). A Level 3 prime contract generally flows a minimum Level 2 (C3PAO) requirement to a subcontractor handling CUI unless specific guidance changes the result.
That is why asking only “What CMMC level does the prime have?” can produce the wrong answer. The subcontractor’s information flow and the associated contract requirement both matter.
Regulatory source: 32 CFR 170.23, Application to subcontractors.
Map the information before mapping the systems
Before buying tools or assuming every corporate system is in scope, map the expected information path:
- What nonpublic federal information will the prime send you?
- What information will your team generate for the Government or prime?
- Which items are FCI, which are CUI, and which are neither?
- Which email, file-storage, endpoint, cloud, engineering, accounting, and collaboration systems will touch that information?
- Will any lower-tier supplier need the same information to perform its scope?
A narrow, accurate information map can prevent both under-scoping and over-scoping. It also gives you a better basis for asking the prime what will actually be shared.
Pre-award questions for the prime
- Will our scope require us to process, store, or transmit FCI?
- Will our scope require CUI? If yes, what categories and markings should we expect?
- What CMMC level and assessment type is assigned to our subcontract?
- Which systems or interfaces will exchange controlled information with us?
- What must flow to our lower-tier suppliers?
Next: compare CMMC Level 1 vs. Level 2, then review how CMMC flows to lower tiers. For the broader 2026 framework, see our CMMC requirements guide.
Find the Cyber Triggers in the Package
SubPreCheck can surface DFARS and CMMC clauses, CUI references, incorporated cyber attachments, flowdown language, and missing documents before you commit.
View Sample ReportSee Review PlansGeneral educational information only. Information classification, CMMC scope, assessment type, and contract requirements should be confirmed against the actual solicitation, subcontract, and current DoD rules.