FCI vs CUI: Which CMMC Level Actually Applies to You

Contributors

Shantanoo Govilkar
Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions

CMMC does not apply the same requirements to every defense contractor. The type of federal information your organization handles, whether Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), and the CMMC level specified in the applicable contract determine the cybersecurity requirements for the relevant contractor information systems. Current DFARS language distinguishes between Level 1, Level 2, and Level 3 requirements and ties the required level to systems processing, storing, or transmitting FCI or CUI.

Current CMMC status: Since July 13, 2026, the Department of War (DoW) has paused third-party CMMC certification requirements. As a result, new solicitations generally designate Level 2 (Self) rather than Level 2 (C3PAO). Contract-specific requirements should still be reviewed carefully to determine the applicable assessment approach.

This guide explains the practical difference between FCI and CUI, how they relate to CMMC Level 1 and Level 2, and why the contract itself matters when determining your obligations. It also walks through where FCI and CUI may exist, compares the two CMMC levels, and provides a 10-question decision tool to help you identify which level is relevant to your environment.

Also Read: The DoD Suspended CMMC Phase 2: What It Means for Your Business

FCI vs. CUI: Understanding the Difference

The distinction between Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) is important because it can determine the cybersecurity requirements that apply to a DoD contractor. FCI is information provided by or generated for the Government under a contract that is not intended for public release, while CUI is information that requires safeguarding or dissemination controls under applicable laws, regulations, or government-wide policies.

FactorFCICUI
What it isNon-public information provided by or generated for the Government under a contract.Government information requiring safeguarding or dissemination controls under applicable authority.
CMMC relevanceGenerally associated with Level 1 requirements.Generally associated with Level 2 requirements.
CMMC baseline15 basic safeguarding requirements from FAR 52.204-21.110 security requirements based on NIST SP 800-171 Rev. 2.
Assessment approachAnnual organizational self-assessment.Assessment type depends on the applicable Level 2 requirement and contract.
POA&MNot permitted.Permitted only under defined CMMC conditions.
Key questionDoes the contract involve FCI that must be safeguarded?Does the contract require your organization to handle CUI?

CMMC Level 1: When FCI Is the Information in Scope

CMMC Level 1 applies when the applicable DoW contract requires protection of Federal Contract Information (FCI) and specifies Level 1. FCI is information that is not intended for public release and is provided by or generated for the Government under a contract, excluding information already made public and simple transactional information such as payment-processing data.

For an organization operating at Level 1, the focus is on the 15 basic safeguarding requirements in FAR 52.204-21. These requirements address areas such as authorized access, authentication, external connections, physical protection, communications security, system flaw remediation, malicious-code protection, and system scanning. Level 1 requires an annual organizational self-assessment and annual affirmation, with assessment results entered into SPRS, and POA&Ms are not permitted.

The important point is that FCI determines the information being protected, but the contract determines whether CMMC Level 1 is required. Organizations should therefore identify where FCI resides or moves, determine the systems that fall within the applicable assessment scope, and then verify the CMMC requirement stated in the solicitation or contract.

CMMC Level 2: When CUI Enters the Picture

When a DoD contract requires an organization to protect Controlled Unclassified Information (CUI), CMMC Level 2 may apply, depending on the CMMC level specified in the solicitation or contract. Level 2 addresses the protection of CUI through 110 security requirements from NIST SP 800-171 Revision 2, creating a substantially broader security baseline than the 15 requirements associated with Level 1.

The difference also extends to assessment expectations. Under the current CMMC framework, Level 2 Self involves an organizational self-assessment every three years with annual affirmation, while a Level 2 C3PAO assessment is required when the contract specifies that assessment type. Level 2 also permits POA&Ms under defined conditions, unlike Level 1. [32 CFR 170.16; 32 CFR 170.22]

For contractors, the practical starting point is to determine whether CUI will actually be processed, stored, or transmitted by the systems used for contract performance and then review the CMMC level specified in the contract. The required CMMC status applies to the applicable contractor information systems handling FCI or CUI, and the status must remain current for the duration of a contract when required.

Also Read: CMMC Level 1 Compliance for DoD Contractors

Where FCI and CUI Can Exist in Your Environment

FCI and CUI can move through far more than a dedicated compliance repository. Depending on how contract work is performed, covered information may appear in employee workstations, file servers, email systems, collaboration platforms, cloud storage, applications, engineering environments, backup systems, and removable media. Mapping where information is created, received, accessed, stored, transmitted, and backed up helps organizations establish an accurate CMMC assessment boundary.

Common locations to review include:

  • Employee Workstations: Documents downloaded from a DoD contract, working files, attachments, and locally cached information can place FCI or CUI on endpoints.
  • File Servers & Shared Drives: Central repositories may contain contract documents, technical information, project records, or other covered data accessed by multiple teams.
  • Email & Collaboration Platforms: Contract-related attachments and messages can introduce covered information into email, messaging, or document-sharing environments.
  • Cloud Storage: SaaS platforms, cloud file repositories, and hosted applications may store or process covered information depending on how they are configured and used.
  • Engineering & Business Applications: ERP, PLM, CAD, project-management, and other systems may handle contract information as part of normal workflows.
  • Backups & Archives: Backup systems and long-term archives can retain covered information even after it has been removed from production systems.
  • Removable Media: USB drives, external storage, and other portable media can create additional locations where covered information resides.
  • Third-Party Connections: Managed service providers, subcontractors, and other external parties may access or process information as part of contract performance.

CMMC Level 1 vs. Level 2: Key Differences at a Glance

CMMC Level 1 and Level 2 address different types of information and security expectations. Level 1 focuses on safeguarding FCI through 15 requirements, while Level 2 addresses CUI through 110 security requirements based on NIST SP 800-171 Rev. 2. The applicable contract determines which CMMC level an organization must meet.

FactorCMMC Level 1CMMC Level 2
Primary InformationFederal Contract Information (FCI)Controlled Unclassified Information (CUI)
Security Requirements15 requirements from FAR 52.204-21110 requirements based on NIST SP 800-171 Rev. 2
AssessmentAnnual self-assessmentNew solicitations generally designate Level 2 (Self) while third-party CMMC certification remains paused; assessment approach should still be confirmed against the applicable contract.
AffirmationAnnual affirmation requiredAnnual affirmation required
POA&MNot permittedPermitted under defined conditions
Security ScopeSystems handling FCISystems handling CUI and applicable connected assets
Overall FocusBasic safeguardingMore comprehensive protection of CUI
CTA-Banner

Moving Ahead

Understanding whether your organization handles FCI or CUI is the starting point for determining the CMMC requirements that may apply to your contract. Level 1 provides a baseline for FCI protection, while Level 2 introduces broader safeguards for environments handling CUI. By reviewing contract requirements, mapping where covered information exists, and defining the systems in scope, organizations can choose the appropriate compliance path and prepare for the assessment of expectations that follow.

Also Read: CMMC Level 1 vs Level 2: Which Does Your Contract Require?

Frequently Asked Questions About CMMC Level 1 vs. Level 2

Back
to Top