Skip to content
Back to Compliance Academy

Product context is educational relevance, not a feature-status or compliance claim.

Context: Visitor
Context: Regulated Access
CMMC / FCI / CUI
Controlled Access
Front Desk
Compliance Manager
Admin

What is CUI vs. FCI?

Two government-information categories with different safeguarding bases: FCI is nonpublic federal contract information; CUI is information subject to government-wide safeguarding or dissemination controls.

Last Reviewed: 2026-09-19Plain-English reference · not legal advice

Plain-English Summary

Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) are defined categories, not simply two labels on a universal sensitivity ladder. FAR 52.204-21 defines FCI for covered contractor information systems. The CUI program defines CUI as information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that law, regulation, or government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. In the current CMMC Phase I structure, FCI aligns with Level 1 and CUI with Level 2 assessment requirements.

Why This Matters

The information category and contract scope determine which safeguarding requirements apply and which systems or environments are in scope. Physical-access practices can be part of those safeguards, but not every room or visitor at an organization automatically falls into the CUI boundary.

Explanation Depth

Concept Explanation

FCI and CUI are two different government-information categories. FCI is nonpublic information tied to a federal contract. CUI is information that has specific government safeguarding or sharing controls. The organization first figures out what information it actually has and where it lives, then protects that scope appropriately.

When You'll See This in SecurePoint

SecurePoint Visitor can help a customer apply and document visitor-access procedures around areas the customer has identified as sensitive or controlled. SecurePoint does not classify information as FCI or CUI and does not determine the customer’s CMMC boundary.

What You Should Do Next

Identify the FCI and CUI your contracts actually create, receive, process, store, or transmit, then determine the systems and physical areas that fall within the applicable safeguarding scope. Build visitor, escort, access-log, and other physical controls around that documented scope rather than treating the entire company as one undifferentiated CUI environment.

What Can Go Wrong

Misclassifying information can cause both under-protection and unnecessary scope expansion. Another error is assuming CUI automatically means every visitor everywhere must follow the same control. The contractor should tie controls to the information, systems, environments, and contract requirements that are actually in scope.

Need structured workflow compliance?

SecurePoint USA builds these checks, watchlists, approvals, and immutable logs directly into your daily operations.

What is CUI vs. FCI? | Compliance Academy | SecurePoint USA