Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

CMMC and NIST 800-171

FCI and CUI: The Difference That Decides Your Entire Scope

What exactly counts as CUI (Controlled Unclassified Information) for your defense contracts? The way you answer that question shapes all your cybersecurity and compliance obligations. Most audit failures and unexpected costs start with misclassifying CUI, either by including data that does not qualify or overlooking information that does. The rules for marking and handling CUI, set by 32 CFR Part 2002, determine how wide your compliance net needs to be, making this classification the foundation for managing cost, effort, and risk.

What is the difference between FCI and CUI, and why does it matter?

Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) are both sensitive, but they trigger very different requirements. FCI is information provided by or generated for the government under contract, not intended for public release. If you only handle FCI, you are subject to Level 1 (Foundational) requirements: 17 practices aligned to FAR 52.204-21, with an annual self-assessment.

CUI, on the other hand, is information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that requires safeguarding or dissemination controls under law, regulation, or government-wide policy. If you receive, process, or store CUI, you are subject to Level 2 (Advanced) requirements: 110 controls from NIST SP 800-171 Rev 2, as cited by CMMC and DFARS 252.204-7012, and assessed through the CMMC Scoping and Assessment Guides L2 v2.13.

The difference matters because handling CUI expands your compliance footprint dramatically. The jump from 17 to 110 practices, and the corresponding increase in documentation, evidence, and technical controls, can mean moving from a manageable self-assessment to a much more rigorous and expensive program.

How do you determine if information is CUI or just FCI?

Misidentifying CUI is the single biggest driver of cost overruns and compliance headaches. Over-marking leads to unnecessary controls, while under-marking exposes you to enforcement action. The federal rules for CUI marking are set by 32 CFR Part 2002. Information must be marked as CUI by the government or by the contractor following clear marking instructions in the contract. Not every document or file you receive from the government is automatically CUI.

Review every contract and statement of work for specific CUI marking instructions. Look for explicit labels such as “CUI” in headers and footers, or references to specific categories under the National Archives CUI Registry. If you generate information for the government, confirm whether it needs to be marked as CUI, and how. If in doubt, seek clarification in writing from your contracting officer before making assumptions.

What are the scoping implications if you misclassify CUI?

Getting CUI wrong affects your entire compliance scope. Under 32 CFR 170.19(c)(1) Table 3, your assets are categorized for assessment as follows:

  • CUI Assets: Assessed against all 110 controls. These are systems that store, process, or transmit CUI.
  • Security Protection Assets: Assessed against controls relevant to their security function.
  • Contractor Risk Managed Assets: Subject to SSP review and limited spot checks. At Level 3, these are treated as CUI Assets.
  • Specialized Assets: Government furnished equipment, IoT, OT, and test equipment are reviewed in the SSP only.
  • Out of Scope Assets: Not assessed, but you must justify their separation.

If you over-mark FCI as CUI, you may needlessly bring entire systems into scope, inflating your cost and effort. If you miss marking true CUI, you risk enforcement under DFARS 252.204-7012 and False Claims Act exposure, especially since the government still enforces self-assessments and select government-led assessments. With the CMMC third party certification requirement currently suspended as of July 2026, your senior official’s signature on the self-assessment is the main assurance. This increases your risk, not lessens it.

What does 32 CFR Part 2002 require for CUI marking?

32 CFR Part 2002 sets the baseline for how CUI must be marked and controlled. CUI markings must be clear and unambiguous, typically placed in the header or footer of documents. Only information that meets the criteria for CUI under law, regulation, or government-wide policy, and is properly marked, should be treated as CUI. For contractors, this often means following the government’s instructions exactly, and not guessing or assuming.

You should establish procedures for reviewing contract documents and deliverables for CUI markings. Train staff to recognize proper CUI markings and to escalate questions before treating information as CUI. Proper marking is a paperwork detail, and it is also the gatekeeper for your entire compliance program.

What documentation and evidence do you need for CUI compliance?

You will be asked for four core scoping artifacts during any assessment: a CUI Flow Diagram, Network Boundary Diagram, Physical Site Diagram, and an Authorized User List. These help an assessor understand where CUI lives, moves, and who can access it.

Remember, policy alone is not enough. You need procedures that describe how you protect CUI, and evidence that proves execution, real, timestamped, system-generated artifacts. Assessment validates reality. Documentation must match what is actually happening in your environment. This chain of proof is what stands up to government scrutiny.

What happens if you get CUI wrong in your self-assessment?

With the CMMC third party certification requirement suspended, the burden of assurance is now fully on your senior official. Their signature on your annual self-assessment and SPRS score is the only assurance the government has. Inflating your score or misrepresenting your scope can trigger False Claims Act liability.

Recent actions have named more than companies but senior officials and private equity owners. Cases have included failures to scan for vulnerabilities, missing system security plans, and using non-compliant email systems. Whistleblowers can file complaints on the government’s behalf. The risk is real, and the consequences are personal.

How can you keep CUI scoping under control and avoid unnecessary cost?

Start with the contract. Insist on clear CUI marking instructions. Map your systems and data flows so you know exactly where CUI lives. Do not bring assets into scope unless you have to. Use diagrams and documentation to justify the boundary of your CUI environment. Train your staff, and review your scoping decisions regularly, especially when contracts change.

Gap assessments can help you identify over- or under-scoping before an audit. Most mid sized DIB companies spend between 200,000 and 500,000 dollars in the first year of compliance, with gap assessments ranging from 10,000 to 50,000 dollars. Getting the scope right up front is the best way to control these costs.

For authoritative details on CUI categories and marking, consult the National Archives CUI Registry.

Common questions

What is the main difference between FCI and CUI? FCI is information from or for the government that is not intended for public release, requiring Level 1 controls. CUI is information that requires safeguarding or dissemination controls under laws or policies, triggering Level 2 requirements.

Who decides if something is CUI? The government is responsible for marking CUI, or your contract will specify how to mark it. Do not assume information is CUI unless it is clearly marked or the contract instructs you to treat it as such.

What should I do if I am not sure whether information is CUI? Ask your contracting officer for clarification in writing. Do not guess or mark everything as CUI; this can expand your compliance scope and costs unnecessarily.

Determine Your Data Classification Now

If you handle CUI and need to ensure your scope is correct, a gap assessment is the best place to start. The Cyber Grants Alliance offers an in kind CMMC Gap Assessment Grant, delivered as services, covering all 110 NIST SP 800-171 controls for qualifying defense contractors. This can help you get your scope right and avoid the most common pitfalls. Learn more at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.

At a glance

The five CMMC asset categories and how each is assessedThe five asset categories, 32 CFR 170.19(c)(1)CUI AssetsProcess, store or transmit CUIAssessed against all 110 controlsSecurity Protection AssetsProvide security functionsAssessed against relevant controlsContractor Risk ManagedCould but should not touch CUISSP review plus limited spot checkSpecialized AssetsGFE, IoT, OT, test equipmentSSP review onlyOut of ScopeCannot touch or protect CUINo assessment, separation must be justified
The five CMMC asset categories and how each is assessed
The three CMMC levels
The three CMMC levels

More on CMMC