CMMC ANSWER ENGINE

Does CMMC apply to my company if we only handle FCI, not CUI?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-14

Most defense subcontractors handle FCI but not CUI — janitorial, landscaping, food service, basic supplies. For these contractors, Level 1 is the floor and Level 2 is not required.

What FCI is

Federal Contract Information is non-public information provided by or generated for the government under a contract that is not intended for public release. It covers contract terms, performance data, communications with the contracting officer, and similar artifacts. FCI is not:

  • Press releases or other public-release information.
  • Information about basic transactions (the FAR exempts simple commercial purchases).
  • Controlled Unclassified Information (CUI) — a separate, more sensitive category with its own markings.

If your contract has any FCI handling, FAR 52.204-21 applies, which makes CMMC Level 1 the floor under 32 CFR § 170.15.

The 17 Level 1 practices

Level 1 implements the 15 basic safeguarding requirements from FAR 52.204-21(b)(1) as 17 CMMC practices. They cover:

  • Access control (limit access to authorized users and authorized functions; control external connections; control public-facing systems).
  • Identification and authentication (identify users and authenticate them).
  • Media protection (sanitize or destroy media before disposal).
  • Physical protection (limit physical access, escort visitors, maintain physical access logs and physical access devices).
  • System and communications protection (monitor and control communications at external boundaries; subnetwork publicly accessible systems).
  • System and information integrity (patch flaws; antivirus / malicious code protection; update protection mechanisms; scan files from external sources).

The Level 1 process

  1. Annual self-assessment against the 17 practices.
  2. Score submitted to the Supplier Performance Risk System (SPRS).
  3. Annual affirmation by a senior company official affirming compliance.
  4. No C3PAO involvement.

When you cross into Level 2

The Level 1 floor stops applying the moment any of the following is true:

  • A contract delivers or generates information marked CUI.
  • The contract includes DFARS clauses governing CUI handling.
  • Your organization generates information that would be CUI under 32 CFR Part 2002.

At that point you are at CMMC Level 2 under 32 CFR § 170.16 (self-assessment, where allowed) or § 170.17 (C3PAO certification assessment), and the L2 scoping guide applies.

Common errors

  • Assuming Level 1 covers CUI. It doesn't. FAR 52.204-21 protections are weaker than the protections required for CUI.
  • Skipping the annual affirmation. Without the affirmation, you are not Level 1 compliant regardless of technical controls in place.
  • Not reading contract clauses carefully. Contracts often include CMMC-relevant clauses without a sentence calling out "CMMC" by name.

Sources

  • FAR 52.204-21 — Basic Safeguarding of Covered Contractor Information Systems — link
  • 32 CFR Part 170 — § 170.15 — CMMC Level 1 self-assessment; § 170.22 — Affirmation — link
  • CMMC Assessment Guide — Level 1 — link
Rulebook version: CMMC 2.0 Final Rule (32 CFR 170); FAR 52.204-21
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.