Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
FCI or CUI? Copy This Classification Script Before Your Next DoD BidAudit & Certification
4 min readFor Compliance Officers

FCI or CUI? Copy This Classification Script Before Your Next DoD Bid

Bidding on Department of Defense contracts means navigating CMMC level requirements. But do you have a reliable process for determining whether the information you'll handle is Federal Contract Information (FCI) or Controlled Unclassified Information (CUI)? Misclassifying can lead to overspending on unnecessary controls or violating contract terms.

This classification script guides you through the determination process before committing to a CMMC level in your proposal.

Purpose of the Script

This decision tree helps classify information types for DoD contract work. Determine if you need CMMC Level 1 (15 practices from FAR 52.204-21) or CMMC Level 2 (110 controls from NIST SP 800-171 Revision 2). Use it during proposal development, contract review, and onboarding new DoD work.

The script doesn't cover CMMC Level 3 requirements. Those are determined by the Defense Industrial Base Cybersecurity Assessment Center based on Advanced Persistent Threat exposure.

Prerequisites

Before using this script, ensure you have:

  • The complete contract solicitation or statement of work
  • Access to the NIST CUI Registry
  • Your organization's data flow documentation
  • Contact information for the DoD contracting officer or program manager

Remember, handling CUI as FCI violates contracts. Handling FCI as CUI costs time and money but doesn't violate terms. When uncertain, classify up.

The Classification Script

Follow these questions for each information type under the contract:

Question 1: Does the contract explicitly state a CMMC level requirement?

  • If yes: Use that level. Proceed to validation.
  • If no: Continue to Question 2.

Question 2: Does the contract reference DFARS clause 252.204-7012?

  • If yes: You're handling CUI. You need CMMC Level 2.
  • If no: Continue to Question 3.

Question 3: List every category of information you'll handle.

For each category, ask:

  • Is it about the contract itself (pricing, schedules, deliverables)?
  • Does it support contract performance but isn't specifically about the contract (employee records, facility access logs)?
  • Is it government-provided or created on behalf of the government?

Question 4: For government-provided or created information, check the NIST CUI Registry.

Search the CUI Registry for matching terms. Examples:

  • Export-controlled technical data → Export Controlled Information (CUI Specified)
  • Personnel security clearance files → Personnel Security Information (CUI Basic)
  • Unclassified technical specifications for defense systems → Critical Infrastructure Security Information (CUI Specified)
  • Financial records related to government contracts → Procurement and Acquisition Information (CUI Basic)

If you find a match: You're handling CUI. You need CMMC Level 2.

Question 5: For contract-related information not in the CUI Registry, apply the FCI test.

FCI includes:

  • Information not for public release
  • Provided by or generated for the government under a contract
  • Related to contract performance

Common FCI examples:

  • Bid proposals and cost/pricing data
  • Delivery schedules and milestone reports
  • Site measurements and facility access details
  • Invoice records and payment documentation
  • Email exchanges with contracting officers about project scope

If the information meets all FCI criteria but isn't in the CUI Registry: You're handling FCI. You need CMMC Level 1.

Question 6: Document your classification decision.

Create a record for each information category:

  • Information type: [description]
  • Classification: FCI or CUI
  • Registry category (if CUI): [category name]
  • CMMC level required: Level 1 or Level 2
  • Justification: [your reasoning]
  • Date classified: [date]
  • Classified by: [your name and role]

Customizing the Script

Your organization's risk tolerance and contract portfolio will influence script use:

Multiple DoD contracts: Build a master information inventory. Run the script for each type, then apply classifications across contracts. Update quarterly or with new contract types.

Subcontractors: Add a question before Question 1: "What CMMC level does the prime contractor require?" Prime contractors may impose their CMMC level on subs. Clarify this in negotiations.

CUI Specified categories: After Question 4, identify specific handling requirements. CUI Specified categories have additional rules beyond NIST SP 800-171. For example, Naval Nuclear Propulsion Information has specific DoD handling procedures.

Unsure about a classification: Add an escalation step. Require contacting the DoD contracting officer with specific questions. Document their response in your classification record.

Validation Steps

After classifying information and determining your CMMC level, validate your work:

  1. Cross-check with the contract: Review clauses on information security, data handling, or compliance. Ensure your classification aligns.
  2. Compare with similar contracts: If you've worked on similar DoD contracts, review past classification records. Document any differences.
  3. Review your data flows: Map where each classified information type enters, who accesses it, where it's stored, and how it exits. Reclassify or segregate systems if necessary.
  4. Consult with a C3PAO or CMMC expert: Before finalizing your proposal, have a Certified Third-Party Assessment Organization review your decisions.
  5. Update your System Security Plan: Ensure your SSP lists every information type and its classification. Update the SSP if needed before submitting your proposal.

The cost difference between CMMC Level 1 and Level 2 is significant. You're looking at 15 practices versus 110 controls. But the cost of getting it wrong is higher. Run this script every time you bid, and keep your classification records current.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like