Quick answer
Federal Contract Information is information provided by or generated for the government under contract that is not intended for public release, triggering basic cybersecurity requirements.
Federal Contract Information (FCI) is information provided by or generated for the US government under contract that is not intended for public release, as defined in FAR 52.204-21, triggering basic cybersecurity requirements for contractor information systems that process this information.
What is Federal Contract Information?
FCI is defined in FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems) as information that is provided by or generated for the government under a contract to develop or deliver a product or service to the government, but not information provided by the government to the public (such as information on public websites) or simple transactional information (such as payment information related to performance). The FCI definition is intentionally broad - most operational information on a federal contract qualifies.
FAR 52.204-21 imposes 15 basic security requirements on contractors whose information systems process FCI. These requirements include: limiting system access to authorized users, using access controls, identifying and authenticating system users, sanitizing or destroying information before system disposal, protecting information during transmission, performing maintenance on systems, providing security awareness training, managing configurations, performing periodic assessments, and several others. These 15 requirements correspond to a subset of the 110 controls in NIST SP 800-171 and align with CMMC Level 1.
The distinction between FCI and CUI (Controlled Unclassified Information) is important for calibrating compliance requirements. FCI is the broader category requiring FAR 52.204-21 compliance (15 controls, CMMC Level 1). CUI is a subcategory of more sensitive FCI requiring NIST SP 800-171 compliance (110 controls, CMMC Level 2). All CUI is FCI, but not all FCI is CUI. A contractor that only handles routine contract deliverables without any government-designated CUI category is subject to FAR 52.204-21 but not NIST SP 800-171 or CMMC Level 2.
Why FCI matters for government contractors
FCI classification is the threshold that determines whether CMMC Level 1 or Level 2 requirements apply. Many contractors mistakenly assume that because they do not work on classified or sensitive programs, cybersecurity compliance is minimal. In reality, FAR 52.204-21 applies to essentially any federal contractor whose systems process contract-related information - which includes most contractor work product, proposals, and operational data. Understanding FCI helps contractors calibrate their compliance investment appropriately: Level 1 compliance for FCI-only environments is significantly less costly than Level 2 compliance for CUI environments.
Example
A professional services firm provides administrative support services to a federal agency, generating reports, maintaining schedules, and managing document workflows. The firm's work generates and processes large volumes of FCI - agency operational information not intended for public release - but none of the information the firm handles is designated CUI. The firm implements the 15 FAR 52.204-21 security requirements, completes a CMMC Level 1 self-assessment, and annually affirms compliance to the DoD. The firm is not required to implement NIST SP 800-171 or pursue Level 2 CMMC certification because no CUI flows through its systems. This calibrated compliance approach saves the firm hundreds of thousands of dollars compared to unnecessary Level 2 implementation.
Frequently Asked Questions
How do I know if my contract involves FCI versus CUI?
If your systems process any non-public information related to the performance of a government contract, you almost certainly handle FCI. Whether you handle CUI depends on whether the government has specifically designated any of the information as CUI using the categories in the CUI Registry. Your contracting officer or program manager is the appropriate contact for CUI designation questions. If information is not explicitly designated as CUI by the government, it is FCI (if non-public contract information) but not CUI.
Does FAR 52.204-21 apply to all federal contractors?
FAR 52.204-21 is included in contracts based on the FAR council's contracting officer guidance and is intended for contracts where the contractor's system processes FCI. Not every contract in every situation will include the clause explicitly, but the underlying policy intent is that any contractor handling federal contract information should implement basic safeguarding. Contractors should review their contract clauses to determine whether 52.204-21 is included and treat FCI appropriately regardless.
Can a company be CMMC Level 1 compliant if it also handles some CUI?
No. If any of a contractor's systems process CUI, those systems must meet CMMC Level 2 requirements (110 NIST SP 800-171 controls). A company can have CMMC Level 1 for systems that only handle FCI and pursue CMMC Level 2 for systems that handle CUI, effectively maintaining separate compliance environments. This scope-limited approach is a legitimate and often cost-effective strategy for contractors who handle CUI in only some of their work.
Is FCI a classification of information or a regulatory category?
FCI is a regulatory category defined in FAR 52.204-21, not a government information classification marking. Unlike CUI (which is formally designated by the government using specific marking requirements) or classified information (which is formally stamped or marked), FCI is not explicitly labeled on documents. Any non-public information created or received in the performance of a federal contract is FCI by definition, without any government marking required. This means contractors must recognize FCI by context rather than by markings.
How Bidovate helps
Bidovate puts Federal Contract Information (FCI) to work inside your capture and proposal workflow.
Federal contractingSee Bidovate in action
Book a demo and we will show you the platform using your actual contract data.
Related terms
Controlled Unclassified Information (CUI)
Controlled Unclassified Information is government-designated sensitive information that is not classified but requires safeguarding controls and access restrictions by contractors.
ViewNIST SP 800-171
NIST SP 800-171 is the federal cybersecurity standard defining 110 security controls that contractors must implement to protect Controlled Unclassified Information in non-federal systems.
ViewCybersecurity Maturity Model Certification (CMMC)
CMMC is the DoD's mandatory cybersecurity certification framework requiring defense contractors to demonstrate compliance with NIST security controls before receiving contracts.
ViewFedRAMP (Federal Risk and Authorization Management Program)
FedRAMP is the federal government's standardized security authorization program for cloud services, enabling agencies to use cloud products that have been pre-approved for federal use.
View