Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
DATA TYPES

CUI vs. FCI vs. CDI: What's the Actual Difference and Why It Determines Your CMMC Level

FCI is nonpublic federal contract information, CUI requires government safeguarding controls, and CDI is a DFARS term tied to covered defense information.

FCI, CUI, and Covered Defense Information are related but not interchangeable. FCI is nonpublic information provided by or generated for the Government under a contract, with exclusions such as public information and simple payment transactions. CUI is information requiring safeguarding or dissemination controls under law, regulation, or government-wide policy.

In practice, the question that matters for a small defense contractor is narrower: does the requirement map to a specific control inside the FCI/CUI boundary, is an owner assigned, and is there current evidence it is actually operating?

The rule in plain English

DFARS 252.204-7012 uses Covered Defense Information in the defense-contracting cybersecurity context and links it to covered contractor information systems and specified information categories.

These definitions matter because CMMC level and safeguarding obligations follow the information handled: Level 1 addresses FCI, while Level 2 is built around CUI protection under the current Rev. 2 baseline.

How to implement it without overbuilding

Create a data-classification decision tree for common business objects: purchase orders, statements of work, drawings, specifications, source code, quality records, emails, proposals, and payment information.

Do not classify data only from a file name or because a prime called it 'sensitive.' Use contract context, markings, the CUI Registry, and the relevant government authority.

What evidence to keep

Keep source markings, contract clauses, prime or government clarification, CUI Registry category, data-flow mapping, and internal classification decisions.

Train users with examples from the company's own work rather than only with abstract definitions.

Where teams get into trouble

Common mistakes include treating every contract email as CUI, treating every unmarked file as non-CUI, and assuming CDI is merely an old synonym that can be ignored in DFARS 252.204-7012 analysis.

Small-contractor walkthrough

A purchase order, drawing, statement of work, invoice, and technical email all enter the same company. The classification process should decide which are FCI, which are CUI, and where DFARS Covered Defense Information applies instead of labeling every contract-related file the same way.

  • Define FCI, CUI, and CDI terms.
  • Use contract language and markings.
  • Check the CUI Registry.
  • Classify common file types.

FCI is the broad federal-contract information layer

FAR 52.204-21 defines FCI as nonpublic information provided by or generated for the Government under a contract to develop or deliver a product or service. It excludes Government-public information and simple transactional information such as what is necessary to process payments. FCI can therefore include ordinary nonpublic contract-performance information that is not CUI.

When CMMC applies and a system handles only FCI, Level 1 is the relevant model. Do not assume every internal company record is FCI; ask whether the information was provided by or generated for the Government under the contract and whether a stated exclusion applies.

CUI requires an authority, not a sensitivity opinion

CUI is information the Government creates or possesses, or an entity creates or possesses for or on behalf of the Government, that law, regulation, or Government-wide policy requires or permits an agency to protect with safeguarding or dissemination controls. The CUI Registry identifies categories and authorities. Commercial secrets do not become CUI merely because a contractor considers them sensitive.

Systems processing CUI fall into the Level 2 model under the current baseline. The category can matter to handling: Controlled Technical Information and Export Controlled information may have different dissemination or access considerations even though both fall within CUI.

CDI is a DFARS contract term layered on CUI

DFARS 252.204-7012 defines Covered Defense Information as unclassified controlled technical information or other CUI requiring safeguards that is either identified in the contract and provided by or on behalf of DoD, or collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of contract performance. CDI therefore adds a DoD contract-performance test.

Do not use CDI as a synonym for all CUI and do not expand it to any 'confidential defense' information. For an active DFARS 252.204-7012 contract, document whether the information meets the CDI definition and then apply the clause's covered-system and incident-reporting obligations.

Use a four-question classification decision

Ask: Is it public or simple payment transaction information? If not, is it FCI under the FAR definition? Does a CUI category/authority apply to information created or held for the Government? For DoD work with DFARS 252.204-7012, does it also satisfy the CDI contract-performance definition? Record the source for the answer rather than relying only on a filename marking.

A file can be FCI without being CUI. CUI in a DoD contract context may also satisfy the CDI definition. The CMMC level then follows the solicitation/contract and the system used for performance, not how sensitive an employee thinks the document feels.

  • Public/simple payment data: usually outside these protected definitions.
  • FCI only: Level 1 path when CMMC applies.
  • CUI: Level 2 path under the current model.
  • CDI: apply DFARS 252.204-7012 in the DoD contract context.
WORKING CHECKLIST

A short working check

  • Define FCI, CUI, and CDI terms.
  • Use contract language and markings.
  • Check the CUI Registry.
  • Classify common file types.
  • Escalate ambiguity.
  • Map each data type to systems.

Common questions

Is all FCI also CUI?

No. FCI is a broader contract-information concept; CUI is information subject to specific safeguarding or dissemination controls.

Is simple payment information FCI?

The FAR definition excludes simple transactional information necessary to process payments.

What is CDI?

Covered Defense Information is a DFARS-defined concept used in 252.204-7012 and tied to covered information and contractor-system obligations.

Why does classification affect CMMC level?

The CMMC program uses the type of information processed, stored, or transmitted by contractor systems to determine the applicable level or status requirement in a solicitation or contract.

Is CDI the same as every CUI item?

No. CDI is a DFARS contractual term using CUI/CTI plus a DoD contract-performance test; do not use it as a synonym for all CUI everywhere.

Official sources used for this guide

Open the primary source before making a contract-specific decision. Regulations and program implementation can change.