Your obligations are driven by the information, not by your org chart or your tech stack. FCI is information provided by or generated for the government under a contract that isn't intended for public release — it triggers FAR 52.204-21 and its 15 basic safeguards. CUI is information that law, regulation, or government-wide policy requires safeguarding for. CDI is the DFARS category that actually switches on DFARS 252.204-7012 and the 110 requirements of NIST SP 800-171 Rev 2. Protection escalates with sensitivity — FCI-that-isn't-CUI, then CUI/CDI, then CUI on a priority program (Level 3). Sitting across all of it, independently, is the ITAR/EAR export overlay, which can apply at any tier and is not answered by a CUI marking.
Why the order matters
Most compliance confusion in the Defense Industrial Base starts in the same place: a team tries to decide what security to build before deciding what information they actually hold.
The stack runs the other way. It is driven first by the information involved, and only then by the clauses, assessment level, and contract-specific requirements that attach to the system handling it. Get the information question wrong and every downstream decision — boundary, licensing, assessment scope, evidence — inherits the error.
FCI, CUI, and CDI are related categories, not perfectly separate buckets. Treating them as three tidy bins is the fastest route to a mis-scoped boundary.
The three information categories
Federal Contract Information (FCI)
Information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service — excluding information the government makes public and simple transactional information.
When describing the population that sits at CMMC Level 1, the precise phrase is “FCI that does not also qualify as CUI.” Plain “FCI” is broader than the Level 1 population, because a great deal of CUI is also FCI.
Controlled Unclassified Information (CUI)
Information the government creates or possesses — or that an entity creates or possesses for or on behalf of the government — that law, regulation, or government-wide policy requires or permits an agency to safeguard or control for dissemination.
CUI is a government-wide construct governed by the NARA CUI Registry, not a DoD invention. That matters more each year, because the proposed government-wide FAR CUI rule would extend a common method across civilian agencies too.
Covered Defense Information (CDI)
The defined DFARS category that actually activates the covered-contractor-information-system obligations in DFARS 252.204-7012. It covers qualifying unclassified controlled technical information or other CUI Registry information that is identified in the contract and either provided by the Department of Defense, or collected, developed, received, transmitted, used, or stored in support of contract performance.
CUI is the government-wide category. CDI is the contractual trigger. You can hold information that looks like CUI, but it is the contract's identification of CDI — plus that second clause, “in support of contract performance” — that switches on the 7012 machinery. Read the contract, not just the marking.
The escalation map
Protection escalates with the sensitivity of the information:
- FCI that is not CUI — FAR 52.204-21, CMMC Level 1, 15 basic safeguarding requirements.
- CUI / CDI — DFARS 7012 / 7019 / 7020, CMMC Level 2, NIST SP 800-171 Rev 2 and its 110 requirements.
- CUI on a priority DoW program — CMMC Level 3, which is Level 2 plus 24 selected requirements from NIST SP 800-172.
Each tier contains the one below it. Nothing about the higher tiers relieves you of the lower-tier duties — and, importantly, none of these tiers answers the export-control question.
Authority, protection, and current acquisition posture
| Information / program | Primary authority | Core protection | Current acquisition posture (July 2026) |
|---|---|---|---|
| FCI that is not CUI | FAR 52.204-21; CMMC L1 | 15 basic safeguarding requirements | Level 1 self-assessment may be required; annual affirmation when CMMC applies |
| CUI / CDI | DFARS 7012, 7019, 7020; CMMC L2 | NIST SP 800-171 Rev 2; SPRS; incident and cloud obligations | Level 2 (Self) permitted; Level 2 (C3PAO) designation is suspended |
| CUI on a priority DoW program | CMMC L3 when specified | All Level 2 requirements plus 24 selected NIST SP 800-172 requirements | Level 3 (DIBCAC) designation is suspended during the review |
| Export-controlled CUI | Applicable CUI clauses plus ITAR, EAR or other export authority | Cybersecurity plus authorization, release, transfer, destination and access restrictions | Requires authority-specific analysis; CMMC alone does not establish export compliance |
The right-hand column reflects the July 13, 2026 suspension of the CMMC Phase II transition and will change after the program review — see CMMC Phase II Is Suspended. The first three columns are the durable part. Build your data model on those.
The overlay that isn't a tier
The ITAR / EAR export-control overlay can apply at any tier, and it is a separate body of law with its own authorities, penalties, and analysis. It governs authorization, release, transfer, destination, and person-level access — questions that no cybersecurity control set answers.
This is the single most common structural mistake in DIB compliance programs: treating “we handle CUI, and we're doing CMMC” as though it resolves export exposure. It does not. If any of your information is export controlled, read CUI Is Not an Export License before you design the environment.
What 800-171 is actually optimizing for
It is worth being precise about what the control set is for, because it shapes how you should argue your implementation:
| Property | Role in this stack | Representative mechanisms |
|---|---|---|
| Confidentiality | The primary regulatory objective for FCI/CUI safeguarding | Authorized access, identity, media protection, boundaries, FIPS-validated cryptography, export controls |
| Integrity | A strong supporting property | Auditability, configuration management, flaw remediation, malware protection, evidence preservation |
| Availability | Indirect and operational support | Resilience, response readiness, recovery planning and continuity |
This confidentiality/integrity/availability framing is an analytical aid, not regulatory scoring. NIST SP 800-171's stated objective is the confidentiality of CUI; integrity- and availability-supporting requirements help achieve that objective but do not turn the publication into a balanced C-I-A standard. Don't cite this table as though it were the rule.
One practical consequence: the DFARS 72-hour report is a reporting obligation, not an availability control. Teams that file it under “resilience” tend to under-build the actual reporting pathway — see DFARS 7012's 72-Hour Rule.
How to classify your own data
- Start from contracts, not systems. List every active contract and order, and pull the clauses actually included. Clause applicability is not the same thing as general data sensitivity.
- Identify what each contract designates. Does it identify CDI? Does it include 7012, 7019/7020, 7021? Does it flow anything to your subcontractors?
- Follow the information, not the folder. CDI includes information collected, developed, received, transmitted, used, or stored in support of contract performance — which reaches well past the folder someone labeled “CUI.”
- Separate the export question. Ask independently whether any of it is ITAR- or EAR-controlled. Answer it with the controlling authority, not the CUI banner.
- Write it down as a data inventory. This is the artifact that makes scoping defensible — and it is the same inventory IT-02 asks you to build.
Key takeaways
- The information drives everything. Decide what you hold before you decide what to build.
- FCI, CUI and CDI overlap. Use “FCI that is not CUI” when you mean the Level 1 population, and remember CDI is the contractual trigger for DFARS 7012.
- Protection escalates in three tiers — 15 safeguards, then 110 Rev 2 requirements, then +24 from 800-172 on priority programs.
- The export overlay is independent and can apply at any tier. CMMC status never establishes export compliance.
- 800-171 optimizes for confidentiality. Integrity and availability support that objective — they don't rebalance the standard.
Sources
- Acquisition.gov — FAR 52.204-21 (basic safeguarding of covered contractor information systems) ↗
- Acquisition.gov — DFARS 252.204-7012 (safeguarding CDI and cyber incident reporting) ↗
- NARA — CUI Registry (categories, markings and authorities) ↗
- eCFR — 32 CFR Part 170 (CMMC Program: levels, scoping and assessments) ↗
- NIST SP 800-171 Rev 2 (Protecting CUI in nonfederal systems) ↗
- NIST SP 800-172 (enhanced requirements for CUI) ↗
Cloud consoles and federal guidance change; confirm control text and clause language against the official publication that applies to your contract. This article is independent education and does not by itself establish compliance or confer CMMC certification.