Federal Contract Information (FCI)

Generate AI summary:

Federal Contract Information (FCI) is information provided by or generated for the U.S. Government under a federal contract that is not intended for public release. FCI can include information created by the government and shared with a contractor as well as information produced by the contractor while performing federal work. The concept is especially important in federal cybersecurity because contractors may be required to protect FCI even when the information does not qualify as Controlled Unclassified Information (CUI).

The formal definition appears in FAR 4.1901 and FAR 52.204-21. FCI excludes information provided by the government to the public, such as information published on public websites, and simple transactional information necessary to process payments. When FCI is stored or processed on a contractor’s information system, FAR 52.204-21 establishes basic safeguarding requirements that can apply to that system.

What Information Qualifies as FCI?

The FAR defines Federal Contract Information as information, not intended for public release, that is provided by or generated for the government under a contract to develop or deliver a product or service to the government. The definition does not depend on whether a document has a particular security marking. The central questions are where the information came from, why it was created, and whether it is intended for public release.

FCI can therefore cover a broad range of information generated during contract performance. Depending on the contract and circumstances, examples can include:

  • nonpublic contract-related communications;
  • internal information generated to perform contract requirements;
  • nonpublic schedules and delivery information;
  • contract performance information that has not been publicly released;
  • nonpublic technical or operational information generated for the government;
  • information exchanged with the agency in connection with performing the contract.

Not every piece of information associated with a federal contract is FCI. Public solicitation documents, public contract award information, agency publications, and other information intentionally released to the public are outside the definition. The FAR also excludes simple transactional information, such as information necessary to process payments.

This distinction is important for contractors working with large volumes of federal procurement information. A company may download a publicly available solicitation from SAM.gov, prepare internal documents related to its response, receive nonpublic information after award, and generate additional information while performing the contract. These materials should not automatically be treated as though they all have the same federal information status.

FCI is also different from a contractor’s ordinary confidential business information. Internal pricing models, employee records, sales strategies, and other proprietary information may require protection for commercial, privacy, or legal reasons, but they do not become FCI merely because the company also performs federal contracts.

FCI and CUI Are Not the Same

FCI and Controlled Unclassified Information are closely related in federal cybersecurity discussions, but they should not be treated as interchangeable terms. FCI is defined through the federal acquisition regulations, while CUI is governed by the governmentwide CUI framework and requires safeguarding or dissemination controls pursuant to applicable law, regulation, or governmentwide policy.

CUI can be viewed as a more specifically controlled category of unclassified government information. FCI does not require the information to belong to a category in the CUI Registry. This means a contractor may possess FCI that does not qualify as CUI.

CharacteristicFCICUI
Full nameFederal Contract InformationControlled Unclassified Information
Classified informationNoNo
Intended for public releaseNoNo
Primary regulatory contextFAR32 CFR Part 2002 and applicable agency or contract requirements
CUI Registry category requiredNoYes, CUI must be based on an approved category and authority
Common baseline for contractor systemsFAR 52.204-21 when applicableMore extensive controls may apply depending on the contract and agency

The difference has practical cybersecurity consequences. A contractor system containing FCI may be subject to the basic safeguarding requirements in FAR 52.204-21. Systems handling CUI can be subject to more extensive requirements depending on the agency and contract. For example, certain Department of Defense contracts involving CUI are associated with NIST SP 800-171 requirements and the CMMC framework.

Contractors should therefore determine what type of federal information they actually handle rather than assuming that all nonpublic federal information is CUI. Treating FCI and CUI as synonyms can result in misunderstanding the contractual requirements that apply to a particular information system.

At the same time, the distinction should not lead contractors to treat FCI as ordinary business data. FCI is still nonpublic federal contract information and is subject to safeguarding requirements when the applicable FAR clause is included in the contract.

FAR 52.204-21 and Basic Safeguarding Requirements

FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, establishes minimum security requirements for covered contractor information systems. A covered contractor information system is generally a contractor-owned information system that processes, stores, or transmits FCI.

The clause requires contractors to apply 15 basic safeguarding requirements and procedures. These controls address fundamental cybersecurity practices rather than a highly specialized security framework.

The requirements cover areas including:

  1. Limiting system access to authorized users.
  2. Limiting access to the types of transactions and functions authorized users are permitted to execute.
  3. Verifying and controlling connections to external information systems.
  4. Controlling information posted or processed on publicly accessible systems.
  5. Identifying system users, processes acting on behalf of users, and devices.
  6. Authenticating or verifying identities before allowing access.
  7. Sanitizing or destroying information system media containing FCI before disposal or reuse.
  8. Limiting physical access to systems, equipment, and operating environments.
  9. Escorting visitors and monitoring visitor activity where appropriate.
  10. Maintaining physical access audit logs.
  11. Managing physical access devices.
  12. Monitoring and controlling communications at external system boundaries and key internal boundaries.
  13. Implementing subnetworks for publicly accessible system components that are separated from internal networks.
  14. Identifying, reporting, and correcting information and information system flaws in a timely manner.
  15. Providing protection from malicious code and updating protection mechanisms when new releases become available.

These requirements establish a basic security baseline for systems containing FCI. They address familiar cybersecurity practices such as access control, authentication, network protection, physical security, media handling, patching, and malware protection.

The clause applies to covered contractor information systems rather than automatically to every computer, server, or device owned by a company. Contractors therefore need to understand where FCI enters their environment and which systems process, store, or transmit it.

FAR 52.204-21 also includes a subcontract flowdown requirement. Contractors must include the substance of the clause in subcontracts, including subcontracts for the acquisition of commercial products or commercial services other than commercially available off-the-shelf items, when the subcontractor may have FCI residing in or transiting through its information system.

Where Contractors Encounter FCI

FCI can enter a contractor’s environment through routine contract administration. A company does not need to be performing a classified defense program or a highly technical cybersecurity contract to receive nonpublic federal contract information.

Consider a contractor performing a federal services contract. The agency may send nonpublic project instructions, schedules, operational information, or other materials needed for performance. The contractor may then generate reports, work products, or other information for the government. If those materials meet the FAR definition and are not intended for public release, they can constitute FCI.

Contractors should identify where this information moves throughout the organization. Relevant locations may include:

  • employee computers used for contract work;
  • company email systems;
  • internal file storage;
  • collaboration platforms;
  • servers and cloud environments;
  • systems used by subcontractors;
  • removable media when permitted;
  • backup and archival environments.

This exercise is useful because cybersecurity requirements apply to the systems handling the information. A contractor that does not know where FCI is stored or transmitted will have difficulty determining which systems fall within the scope of FAR 52.204-21.

Cloud services require the same basic analysis. Moving contract information from a local server to a commercial cloud platform does not change whether the underlying information is FCI. Contractors still need to determine whether the systems involved meet applicable contractual safeguarding requirements.

Public disclosure is another area that requires attention. FAR 52.204-21 requires contractors to control information posted or processed on publicly accessible systems. Contractors should verify that FCI is not posted publicly unless the information has been reviewed and authorized for public release in accordance with applicable procedures.

FCI in DoD Contracts and CMMC

FCI has additional significance in Department of Defense contracting because it is incorporated into the Cybersecurity Maturity Model Certification framework. CMMC uses different assessment levels based on the type of information contractors handle and the cybersecurity requirements associated with the contract.

CMMC Level 1 focuses on protecting FCI and is based on the 15 safeguarding requirements contained in FAR 52.204-21. This provides a direct connection between the governmentwide FAR safeguarding requirements and the DoD cybersecurity assessment framework.

CMMC Level 2 addresses contractors handling CUI and is associated with substantially more extensive security requirements. The distinction illustrates why contractors should determine whether their systems contain only FCI or also contain CUI.

A company should not assume that handling FCI automatically means CMMC applies. CMMC is a DoD program and its requirements apply when incorporated into applicable DoD solicitations and contracts. Contractors performing work for civilian agencies may still be required to safeguard FCI under FAR 52.204-21 without being subject to CMMC.

For companies pursuing DoD opportunities, however, FCI can become relevant even when they do not expect to receive CUI. Contractors should review each solicitation to determine the applicable CMMC level, assessment requirements, FAR and DFARS clauses, and cybersecurity obligations before submitting an offer.

Managing FCI in Federal Contract Performance

Federal contractors should approach FCI management by identifying information flows rather than attempting to label every internal file associated with a government customer. The objective is to determine what nonpublic information is provided by or generated for the government and then ensure that systems containing that information satisfy applicable requirements.

A practical process starts with the contract. Contractors should review the relevant FAR clauses, identify systems expected to handle FCI, determine which employees and subcontractors require access, and document how the information moves through the organization.

Companies should also revisit this analysis when their technology environment changes. Moving federal contract work to a new cloud platform, introducing a new collaboration system, adding subcontractors, or changing how employees remotely access information can alter the systems through which FCI passes.

For GSA Schedule contractors, the presence of FCI depends largely on the work performed under individual contracts and orders. Simply holding a Multiple Award Schedule contract does not mean that every company system contains FCI. Likewise, publicly available GSA Schedule information such as published contract details and authorized catalog information does not become FCI merely because it relates to a federal contract.

The important distinction is whether the information is provided by or generated for the government under a contract and is not intended for public release. Once that threshold is met, contractors need to identify the systems handling the information and apply the safeguarding requirements established by their contracts. Understanding that boundary helps companies protect federal information without incorrectly treating every piece of government-related data as CUI or applying unnecessary controls to information that is already public.

Contact our GSA Expert
Call 201.567.6646 or provide your details for a free consultation:

    Click to rate
    [Total: 0 Average: 0]

    Get a Consultation

    Fill out the form below and one of our experts will contact you to discuss next steps.






      We'll get back to you within one business day.