Federal Contract Information (FCI)
Overview
Federal Contract Information (FCI) is information provided by or generated for the U.S. Government under a federal contract to develop or deliver a product or service that is not intended for public release. FCI is most commonly encountered in research performed under federal procurement contracts and subcontracts rather than grants or cooperative agreements.
Projects involving FCI may be subject to contractual information protection and cybersecurity requirements established by the sponsoring agency or incorporated into the contract. These requirements are intended to protect government information from unauthorized access, disclosure, or use.
The Office of Research Security (ORS) assists faculty, staff, and students in determining whether FCI requirements apply to a research project, identifying applicable safeguarding requirements, and coordinating with the appropriate University offices to support compliance.
Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) are distinct categories of government information. Some projects may involve FCI, CUI, or both. ORS can assist researchers in determining which requirements apply based on the contract and applicable terms and conditions.
What Is Federal Contract Information?
Federal Contract Information generally includes information that:
- Is provided by or generated for the U.S. Government under a federal contract to develop or deliver a product or service; and
- Is not intended for public release.
FCI does not include information provided by the Government to the public, such as information available on public websites, or simple transactional information necessary to process payments.
Whether particular research or project information constitutes FCI depends on the federal contract and the circumstances under which the information is provided or generated.
How Is FCI Identified?
FCI requirements may be identified through:
- Federal procurement contracts and subcontracts
- Contract terms and conditions
- Information provided by a federal agency or prime contractor
- Government instructions regarding the protection of contract information
- Other contract documentation
Unlike CUI, FCI is generally not identified through standardized CUI markings or categories. Its status depends on the nature of the information and the federal contract under which it is provided or generated.
Researchers should contact ORS if a federal contract includes safeguarding or cybersecurity requirements or if they are uncertain whether information associated with the contract constitutes FCI.
Examples of FCI
Depending on the contract and circumstances, FCI may include:
- Government-provided technical or project information not intended for public release
- Draft reports and deliverables prepared for the Government
- Contract performance documentation
- Government correspondence related to contract performance
- Nonpublic project information generated for the Government
- Other nonpublic information exchanged between the Government and a contractor in connection with contract performance
Not all information associated with a federal contract is necessarily FCI. Publicly available information, simple transactional information, and other excluded information may fall outside the definition.
When Might Researchers Encounter FCI?
Researchers may encounter FCI when:
- Performing research under a federal procurement contract or subcontract.
- Participating as a subcontractor on a federally contracted research project.
- Receiving nonpublic government information to support contract performance.
- Working with a prime contractor on a federal contract.
- Generating nonpublic information or deliverables for the Government under a federal contract.
- Conducting research subject to contractual information protection or cybersecurity requirements.
Federal grants and cooperative agreements generally do not involve Federal Contract Information because FCI is a federal acquisition concept associated with procurement contracts. However, grants and cooperative agreements may establish separate cybersecurity or research information protection requirements through sponsor terms and conditions.
Typical Safeguarding Considerations
Projects involving FCI may require:
- Access limited to authorized personnel.
- Protection of electronic and physical information from unauthorized access or disclosure.
- Secure storage and transmission of information.
- Appropriate cybersecurity safeguards.
- Use of approved research computing environments, when required.
- Compliance with applicable sponsor and contractual requirements.
The specific safeguards required depend on the federal contract, sponsoring agency, information involved, and computing environment.
Researchers should identify applicable safeguarding requirements before receiving, storing, processing, or transmitting FCI.
Related Requirements
Research involving FCI may also involve:
- Controlled Unclassified Information (CUI)
- Federal contract cybersecurity requirements
- Government Information
- Export-Controlled Information
- Research Information Protection
- Research Cybersecurity Baseline
- Data Protection Plans, when applicable
The presence of FCI does not necessarily mean that all of these requirements apply. ORS assists researchers in identifying the requirements applicable to the specific project.
How ORS Can Help
ORS assists researchers by:
- Determining whether a project involves Federal Contract Information or FCI-related requirements.
- Reviewing contracts, subcontracts, and other award documents for information protection and cybersecurity requirements.
- Identifying applicable research information protection, cybersecurity, and export control requirements.
- Determining whether project-specific safeguarding measures are required.
- Coordinating with Research Computing & Informatics (RCI), the Information Security Office, the Office of Sponsored Programs, and other University offices, as appropriate.
- Providing guidance throughout the proposal, award, and research lifecycle.
Federal Regulatory References
| Reference | Description |
|---|---|
| Federal Acquisition Regulation (FAR) | Establishes federal procurement requirements applicable to contracts with the U.S. Government, including requirements related to the protection of Federal Contract Information. |
| Defense Federal Acquisition Regulation Supplement (DFARS) (when applicable) | Supplements the FAR for Department of Defense acquisitions and may establish additional cybersecurity and information protection requirements for covered contracts. |
Need Assistance?
If your research project involves a federal procurement contract, subcontract, or nonpublic government information, or you are uncertain whether Federal Contract Information requirements apply, contact the Office of Research Security before receiving, accessing, storing, processing, or transmitting the information.
ORS will assist in determining applicable requirements, identifying appropriate safeguards, and coordinating with the appropriate University offices.