FCI vs. CUI: What Every Defense Subcontractor Needs to Know

FCI vs. CUI comparison for defense subcontractors explaining CMMC Level 1, CMMC Level 2, Federal Contract Information, and Controlled Unclassified Information

FCI vs. CUI: What the Difference Actually Means for Your Subcontractors 

Federal Contract Information (FCI) is protected by 15 controls under Cybersecurity Maturity Model Certification (CMMC) Level 1 and can be shared through standard email and stored in ordinary business cloud accounts. 

Controlled Unclassified Information (CUI) is protected by all 110 controls under CMMC Level 2 and has to be handled far more carefully, including FedRAMP-authorized storage. Whether you’re dealing with FCI or CUI decides whether working with an uncertified subcontractor is a minor detail or a real compliance problem.

Related Topic: Why Passing CMMC Starts With Finding the Gaps First?

The Practical Difference: 15 Controls vs. 110 

Most of what a small defense manufacturer handles day to day is FCI, not CUI. FCI is information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service to the government. It’s not intended for public release, but it also isn’t sensitive enough to require the heavier CUI protections. Under FAR 52.204-21, the federal regulation that actually defines FCI, this covers routine contract communications and simple transactional information, not the technical substance of what you’re building. 

CMMC Level 1 protects FCI through 15 controls, pass-or-fail self-attestation, and allows standard email and cloud storage without FedRAMP.

CUI protects technical drawings, specifications, and engineering data requiring safeguarding, while manufacturers handle controlled technical information during daily production operations.

CUI requires all 110 NIST SP 800-171 controls under CMMC Level 2, FedRAMP-authorized cloud storage, documented System Security Plan implementation.

The government doesn’t always label things clearly. If something you’re handling is explicitly marked CUI, treat it as CUI and safeguard it accordingly, since how you handle CUI is exactly what an assessor will want to see evidence of. If it isn’t marked and doesn’t obviously fit that category, FCI is usually the safer default assumption, though when you’re unsure, it’s worth confirming directly with your contracting officer rather than guessing. 

Related Topic: CMMC Enclave vs. Enterprise: Which Compliance Model Works Best?

Why This Split Matters So Much for Subcontractors?

Here’s where the FCI-versus-CUI distinction stops being academic. As a prime or a subcontractor yourself on a defense contract, you’re required under DFARS flow-down clauses to pass the relevant CMMC controls down to anyone else you share that information with. If you’re only dealing with FCI, that means flowing down 15 Level 1 controls. If it’s CUI, you’re flowing down all 110. 

The Real Problem: No Way to Verify a Subcontractor’s Status 

One manufacturer we worked with ran into this directly while managing bids that involved Department of Defense contract requirements. Many specialized subcontractors lacked CMMC certification, and the shop discovered undocumented bid information sharing only after mapping its supply chain.

There’s no public lookup where you can check whether a given supplier meets Level 1. The only way to find out is to ask them directly, or to request the PDF a company receives when they submit their own Level 1 self-attestation. For a shop juggling dozens of small vendors, chasing that down for every one of them isn’t realistic, and plenty of those vendors won’t have an answer ready anyway. The honest version of the problem wasn’t that anyone had done something wrong. It was that nobody had built a habit around checking before information went out the door. 

The Ownership Loophole That Actually Works 

Here’s the detail that actually solves the problem, and it applies to both FCI and CUI. The DFARS flow-down obligation is triggered by transferring ownership of information, not simply by someone being able to see it. 

If a subcontractor never takes ownership of a document, sharing it with them doesn’t require them to be certified. Share FCI through view-only OneDrive or SharePoint links, disable downloads, and provide handling instructions to satisfy flow-down requirements without certification.

It’s not a workaround in the sense of skirting the requirement. It’s a legitimate distinction the requirement itself is built around, and it’s the difference between telling a subcontractor they can’t see your bid documents at all and finding a compliant way to keep working with the vendors you already trust. 

Related Topic: Why Every Business Needs an IT Risk Assessment?

Why Getting This Wrong Is Riskier Than It Looks?

This isn’t just a documentation nicety. When you submit your own CMMC self-attestation, you’re certifying that your environment, including how information moves to your subcontractors, actually meets the security controls you’re claiming. If your flow-down practices don’t hold up, that’s not a subcontractor’s problem to sort out later. Accurate FCI and CUI classification strengthens self-attestations, reduces False Claims Act risks, and demonstrates compliance with applicable CMMC requirements.

What This Actually Looks Like Day to Day?

In practice, this means a shift in habit more than a technology purchase. Instead of attaching a spec sheet or a set of drawings to an email, the file goes into a shared, permission-controlled folder, and the subcontractor gets a link instead of a copy. Set link expiration dates and record recipient access to demonstrate controlled sharing during CMMC assessments or prime contractor compliance reviews.

This doesn’t remove every obligation. Subcontractors needing permanent document access must meet applicable CMMC requirements, obtain contracting approval, or organizations should select compliant alternatives.

Building This Into Your Actual Workflow

The shops that handle this well don’t treat it as a one-time decision. They build a habit around it: before a document goes to an outside vendor, someone asks whether it’s FCI or CUI, and whether that vendor has any certification at all. Share files through view-only links instead of email attachments to protect subcontractor data and reduce CMMC 2.0 compliance risks consistently.

The Longer-Term Option: Helping Subcontractors Get There

The read-only approach solves the immediate problem, but it’s worth being honest about its limits. It works for sharing information. It doesn’t work if a subcontractor needs to actively collaborate on CUI, build something derived from it, or take any real ownership of the work product. For those relationships, there’s no substitute for the subcontractor actually meeting the relevant CMMC requirements themselves. 

Discuss cybersecurity requirements early with small subcontractors; Level 1 self-attestation uses fifteen controls and prevents compliance delays before contract awards.

Related Topic: Why Your Small Business Network Setup Matters More Than You Think?

What To Do With This?

Confirm whether shared information is FCI or CUI and review subcontractor practices before DFARS assessments or audits expose compliance gaps.

Schedule a free consultation with our CMMC-certified team to talk through how your shop shares information with its subcontractor network today. If you’re already working through CMMC compliance services with us, this is exactly the kind of practical gap worth closing early, before it shows up as a finding on someone else’s assessment. 

FAQ 

Are invoices considered FCI? 

Invoices and purchase orders usually are not FCI because FCI covers contract information supporting federal products or services, not routine billing.

Is a purchase order considered FCI? 

Treat purchase orders as FCI when they include contract requirements or technical details; confirm classifications with your contracting officer promptly.

What’s the difference between DoD FCI vs CUI? 

FCI applies to nonpublic federal contract information protected by fifteen CMMC Level 1 controls; CUI requires all 110 Level 2.

Our Blog

FCI vs. CUI: What Every Defense Subcontractor Needs to Know

FCI vs. CUI: What Every Defense Subcontractor Needs to Know

FCI vs. CUI: What the Difference Actually Means for Your Subcontractors  Federal Contract Information (FCI)…

Why Passing CMMC Starts With Finding the Gaps First?

Why Passing CMMC Starts With Finding the Gaps First?

A CMMC gap assessment checks your environment against all 320 assessment objectives behind the 110 NIST…

CMMC Enclave vs. Enterprise: Which Compliance Model Works Best?

CMMC Enclave vs. Enterprise: Which Compliance Model Works Best?

A CMMC enclave separates the systems and people who handle Controlled Unclassified Information (CUI)…