This looks like FCI, not CUI.
Federal contract information is information provided by or generated for the government under a contract that is not intended for public release. It is in scope, but for the basic safeguarding requirements of FAR 52.204-21 rather than all 110.
What to do
- Check the contract for FAR 52.204-21, the basic safeguarding clause.
- Meet the requirements in that clause. They map to a subset of 800-171, listed below.
- Do not assume this stays FCI. A modification or a new deliverable can introduce CUI.
- If the contract also contains DFARS 252.204-7012, work through this worksheet again for the data that clause covers.
FAR 52.204-21; CMMC Level 1, 32 CFR 170.15.
The Level 1 practices
FAR 52.204-21 lists fifteen basic safeguarding requirements. CMMC assesses them as these seventeen practices from NIST SP 800-171.
- 3.1.1 Know who and what is allowed on your systems
- 3.1.2 Limit what each person can do once inside
- 3.1.20 Verify and limit outside systems
- 3.1.22 Review what goes on public sites
- 3.5.1 Give every user, process, and device an identity
- 3.5.2 Prove those identities
- 3.8.3 Destroy or wipe media properly
- 3.10.1 Limit physical access
- 3.10.3 Escort visitors
- 3.10.4 Keep physical access logs
- 3.10.5 Manage keys and badges
- 3.13.1 Guard your boundaries
- 3.13.5 Put public services in their own subnet
- 3.14.1 Find and fix flaws on a clock
- 3.14.2 Run malware protection
- 3.14.4 Keep malware definitions current
- 3.14.5 Scan on schedule and in real time
Not the outcome you expected?
Run the worksheet again for one specific set of information, or read the other outcomes.
Whether information is CUI is the government's decision. This page sorts your situation; it does not designate anything. See FCI, CUI and CDI.