top of page

FCI vs. CUI: What Small Government Contractors Actually Need to Know

  • Writer: Shay
    Shay
  • Aug 12
  • 12 min read
SNL-Tech Services blog header with "FCI vs. CUI" headline and three-column layout defining Federal Contract Information, Controlled Unclassified Information, and CMMC requirements for small government contractors

A client reached out to me recently while working on a bid. They own a landscaping company, and one of the questions on the bid asked them to identify their CMMC level.

The choices were Level 1, Level 2 or Level 3.


They had no idea what the question meant, so they emailed and texted me to ask what they were supposed to put.


My answer was that they could not honestly claim any of those levels because they had never completed the required assessment. Based on what I knew about their business and the type of work they were bidding on, Level 1 appeared much more likely to be relevant than Level 2. I would still want to review the actual requirements of the contract and understand what information they would handle before making that determination.


I think their experience is a good example of how CMMC can reach businesses that do not necessarily think of themselves as government or defense contractors.


A landscaping company, construction contractor, electrical contractor, manufacturer, engineering firm or another small service business may come across CMMC for the first time while completing a bid. The owner may have never heard the terms FCI or CUI before that moment.


If that happens to your business, there are two terms I think you should understand before you start worrying about CMMC levels, Microsoft licensing or what technology you may need to purchase.

Those terms are FCI and CUI.


What is FCI?

FCI stands for Federal Contract Information.

The federal definition is more formal, but I think the easiest way to understand FCI is to think about non-public information your company receives or creates because you are performing work under a federal contract.


Imagine that you own a small construction company and win a federal contract. You receive information from the government that you need to perform the work, and some of that information is not available to the general public. Your company may also create information specifically for the government while completing that project.


Depending on the information and the contract, some of that information may be FCI.

FCI is not the same thing as classified information. Your employees are not suddenly handling government secrets because your company has FCI. It does mean that your company has information that is not intended for public release and that needs to be appropriately protected.


There are also important exceptions. Information that the government has already made public is not FCI simply because it came from a federal agency. Basic transactional information needed to process a payment is also excluded from the federal definition.


What could FCI look like inside a small business?

I think it becomes easier to understand when you stop thinking about definitions and start following the information.


Suppose you own a ten-person electrical contracting company and your project manager receives non-public contract information by email. The project manager opens the email on a company laptop, downloads an attachment and later saves that attachment in Microsoft 365 so that you can review it.


That information has now interacted with your email system, a computer and your Microsoft 365 environment. Depending on how your systems are configured, another copy may also exist in your backup system.


Now imagine that your project manager needs another employee to review the document. The employee works from home, so the file gets shared with that person as well. Someone may also print a copy because it is easier to use while working on the project.

The information may have started as one email attachment, but it is now potentially stored or accessible in several different places.


This is why one of the first things I want to understand when talking with a business about CMMC is where the information goes after the company receives it.


How does FCI relate to CMMC Level 1?

CMMC stands for the Cybersecurity Maturity Model Certification program.

CMMC Level 1 focuses on the basic safeguarding of FCI. Level 1 currently uses the 15 security requirements contained in FAR 52.204-21.


For a small business, many of the concepts behind those requirements should sound familiar. They include controlling who can access company systems, properly identifying users, protecting the network, maintaining malware protection, correcting vulnerabilities and controlling physical access to systems.


A business may already have some of those protections in place, especially if it has a managed IT provider.


The important question is whether the protections that exist actually meet the requirements.

Having Microsoft 365, a firewall and antivirus software does not automatically make a company CMMC Level 1.


If I were evaluating a small company's environment, I would want to know much more. I would look at who has access to the systems, whether former employees still have active accounts, how users authenticate, whether computers receive security updates, how remote access works and what happens to an old computer before it is sold, recycled or discarded.


I would also want to understand how the company handles the information itself because security does not stop at the computer.


What is CUI?

CUI stands for Controlled Unclassified Information.

CUI is still unclassified information, but there are laws, regulations or government-wide policies that require specific safeguards or controls over how that information is handled or shared.


The word “controlled” sometimes causes confusion because people associate it with classified government information. CUI is not classified information, but it does require specific protection.


There are many categories of CUI, so I would never recommend that a business owner decide something is or is not CUI simply because a document looks sensitive.

If your company will handle CUI, you need to understand what the information is, what the contract requires and how that information will move through your business.


FCI vs. CUI: What Is the Practical Difference?

Imagine that you have three documents sitting on your desk.

The first document is a brochure that anyone can download from a government website. It is public information.

The second document contains non-public information that your company received because you are performing a federal contract. Depending on the circumstances, that document may contain FCI.

The third document contains unclassified information that is subject to specific government safeguarding or dissemination requirements. That document may contain CUI.

The fact that all three documents are connected to the government does not mean that they require the same protection.


That distinction matters because the type of information your company handles helps determine which cybersecurity requirements apply.


Does my industry determine whether I need CMMC Level 1 or Level 2?

Your industry does not determine your CMMC level.

The landscaping client I mentioned earlier is a good example. They were not automatically Level 1 because they are landscapers, and I could not assume that Level 2 was impossible simply because of the work they normally perform.


I needed to understand what the bid was asking and what type of information they would receive if they won the work. The same thing applies to construction companies, manufacturers, engineering firms and other small contractors.


A five-person manufacturer could have very different requirements from a fifty-person construction company. The number of employees and the type of business do not answer the most important question, which is what information the company will process, store or transmit under the contract.


What if my company only has five employees?

This is where I think CMMC becomes particularly challenging for small businesses.

A five-person company probably does not have a cybersecurity department. It probably does not have a compliance officer either.


The owner may be responsible for sales, operations, hiring, accounting and technology while also trying to win new work. Then a bid asks for the company's CMMC level.


That owner does not need a sales pitch filled with cybersecurity acronyms. The owner needs someone to help determine what the requirement means for that particular business.

The first step should be understanding what the contract requires and what information the company will handle. I would not start by purchasing new software or replacing an existing Microsoft 365 environment.


Start by following the information

If your company is going to receive FCI or CUI, I want to understand its entire path through the business.

Suppose an employee receives information by email and downloads it to a company laptop. The employee saves another copy in OneDrive and later shares it with someone who works from home.


I would want to know whether that second employee is using a company-owned computer. I would look at who else can access that OneDrive location, how the Microsoft 365 environment is configured and whether the data is being backed up somewhere else.

I would also ask what happens when someone prints the document.


That last question becomes especially important when we start talking about CUI and CMMC Level 2.


CMMC Level 2 is more than an IT project

This is one area where I think small businesses can easily misunderstand what they are getting into.

If a company needs CMMC Level 2, SNL-Tech Services can handle the technical side of the project. I can evaluate the existing IT environment, identify technical gaps and implement the technology changes that are needed. Depending on the environment, that work may involve Microsoft 365, computers, networks, firewalls, endpoint security, authentication, access controls, backups and other systems that process, store or transmit CUI.


The technical work is only one part of CMMC Level 2.

Imagine that an employee receives CUI electronically and prints it because a paper copy is needed while working on the project. Protecting the electronic copy does not address what happens to the printed document.


Where is that paper stored when it is not being used?

Who can access the room where it is kept?

Can visitors or other employees enter that area?

What happens to the document when it is no longer needed?

How is it destroyed?


Those questions cannot be answered by configuring Microsoft 365 or installing a firewall.

This is why I would recommend bringing a trusted CMMC compliance partner into a Level 2 project. For example, I could work alongside a company such as Steadfast Partners. SNL-Tech Services would handle the technical IT work while the compliance partner helps guide the broader CMMC process, including scoping, CUI data-flow mapping, policies, procedures, documentation and the System Security Plan.


The technology, documentation and everyday business practices need to support each other. A written policy that says printed CUI is securely stored will not help if employees leave those documents sitting on their desks. A secure Microsoft 365 environment will not solve the problem if employees download CUI to personal computers.


I would rather have the right people involved from the beginning than build an expensive technical environment and discover later that the scope, documentation, physical security or business processes were not properly addressed.


Do I automatically need Microsoft GCC High?

I would not assume that you need to purchase GCC High simply because someone mentioned CMMC.

The technology your business needs depends on the information you handle, the contractual requirements that apply and which systems will process, store or transmit that information.


For a very small contractor, getting this decision wrong can become expensive quickly.

If you already use Microsoft 365, I would first want to understand what you have, how it is configured and what the contract requires before recommending that you replace it or move to a different environment.

The same principle applies to Google Workspace.

I want the requirements to drive the technology decision rather than choosing the technology first and trying to make the requirements fit afterward.


What should I do if CMMC appears on a bid?

If you are completing a bid and suddenly see a question asking about CMMC, I would not guess at the answer.

Start by looking at exactly what the bid or solicitation says. Find out what CMMC level is being required and whether the work will involve FCI or CUI.


Then start thinking about how that information would actually move through your company if you won the work.

Who would receive it?

Would it arrive through email?

Would employees save it in Microsoft 365 or Google Workspace?

Would anyone download it to a computer?

Would employees work with it from home?

Would anyone print it? Would it be stored on a local server?

Where would it be backed up?

Those questions give you a much clearer picture of the environment that needs to be evaluated.


How SNL-Tech Services can help

I work with small businesses that often do not have internal IT or cybersecurity departments. If CMMC appears in a bid or contract and you have no idea what it means, I can help you understand the technology side of what you are being asked to do.


For CMMC Level 1, I can evaluate your existing IT environment against the applicable technical requirements, identify gaps and help implement the changes needed so that your company can complete its required self-assessment based on what is actually in place.


For CMMC Level 2, SNL-Tech Services can handle the technical side of the project, but I would recommend involving a qualified CMMC compliance partner to help address the broader requirements surrounding documentation, policies, procedures, physical security, CUI handling and assessment readiness.


I do not think a small business should have to figure out which specialists it needs after spending money in the wrong places. If a project needs expertise outside of the technical IT work I provide, I would rather bring the right partner into the conversation.

My goal is to understand what your business is required to protect, determine what you already have in place and identify what actually needs to change.


Frequently Asked Questions About FCI, CUI and CMMC

Does my small business need CMMC just because I bid on government work?

Not necessarily. The requirements depend on the solicitation or contract and the information your company will handle. If CMMC is included in a bid or contract, you should determine the required level rather than assuming that every federal contract has the same requirements.


How do I know whether I need CMMC Level 1 or Level 2?

The required CMMC level should be identified in the solicitation and resulting contract. The type of information involved is also important. Level 1 focuses on protecting FCI, while Level 2 addresses the protection of CUI.

If you are unsure what a bid is requiring, I recommend reviewing the actual contract language before making technology decisions or claiming a particular CMMC level.


Is CMMC Level 1 a certification?

CMMC Level 1 currently requires an annual self-assessment against the 15 security requirements in FAR 52.204-21. The results are entered into the Supplier Performance Risk System, commonly called SPRS, and an annual affirmation is also required.

This is why I prefer to talk about helping a company prepare for and meet the Level 1 requirements rather than telling a client that I can simply “certify” the business.


If I have antivirus, a firewall and Microsoft 365, am I already Level 1?

Not necessarily.

Those technologies may help you meet some of the requirements, but CMMC is concerned with how your systems are actually configured and managed.

I would still need to look at areas such as user access, authentication, system updates, malware protection, network security, physical access and how FCI moves through the business.


Does my whole company have to be included in CMMC?

This is a scoping question, and it should be answered based on your actual environment rather than your total number of employees.

The important issue is where FCI or CUI is processed, stored or transmitted and which people, systems and services are involved.

For a small business, properly understanding the scope can be extremely important before making expensive technology changes.


Do I need GCC or GCC High for CMMC Level 1?

You should not assume that GCC or GCC High is required simply because you need CMMC Level 1.

Level 1 is focused on safeguarding FCI under FAR 52.204-21. Your existing environment should be evaluated against the actual requirements before you purchase a different Microsoft 365 environment.

CUI and Level 2 introduce additional considerations that need to be evaluated separately.


Can employees work from home if we have CMMC requirements?

Remote work does not make the requirement disappear. You need to consider how the employee accesses the information, what device is being used, how the connection is protected and whether FCI or CUI is being stored somewhere outside of the intended environment.

This is another reason I want to understand how information actually moves through a company rather than looking only at the equipment sitting in the office.


What is SPRS?

SPRS stands for the Supplier Performance Risk System. It is the system used for submitting applicable CMMC assessment results and affirmations.

For a small contractor encountering CMMC for the first time, SPRS may be another unfamiliar part of the process. I would not let that acronym distract from the first task, which is understanding what CMMC level applies and whether your environment actually meets the requirements.


Should I buy new technology before starting CMMC?

I would not.

I would first determine what the contract requires, whether you will handle FCI or CUI, where that information will go and which systems are actually involved.

Once I understand the environment and the requirements, I can make much better decisions about what needs to be changed.

You may need new technology, but I would rather identify that need through an assessment than assume that buying a particular product makes a business compliant.


What should I do if a prime contractor suddenly asks for my CMMC level?

Do not guess.

Ask what CMMC level is required for the work and review the applicable contract or solicitation language. You also need to understand whether your company will receive FCI or CUI.

If you have never dealt with CMMC before, this is a good time to involve someone who can help you understand the requirements before you answer the question or start changing your IT environment.


What should I remember about FCI and CUI?

You do not need to become a CMMC expert simply because a government bid introduced you to FCI and CUI.

You do need to understand that FCI is non-public information associated with performing a federal contract and that CUI is unclassified information that is subject to additional safeguarding or dissemination requirements.

If CMMC appears in a bid or contract, find out what the contract actually requires before you claim a CMMC level or start purchasing technology.

Then follow the information through your business. Understand who receives it, where it is stored, how it is shared, whether it is printed and what systems or people can access it.

Once you understand that, you can have a much more useful conversation about what your company actually needs to do.



This article provides general educational information and is not legal advice, a CMMC certification, or a determination of the requirements that apply to a particular contract.

Comments


bottom of page