Federal Contract Information (FCI)
Overview
Federal Contract Information (FCI) is information provided by or generated for the U.S. Government under a federal contract to develop or deliver a product or service that is not intended for public release. FCI is most commonly encountered in research performed under federal procurement contracts and subcontracts rather than grants or cooperative agreements.
Projects involving FCI may be subject to contractual information protection and cybersecurity requirements established by the sponsoring agency or incorporated into the contract. These requirements are intended to protect government information from unauthorized access, disclosure, or use.
The Office of Research Security (ORS) assists faculty, staff, and students in determining whether FCI requirements apply to a research project, identifying applicable contractual safeguarding and cybersecurity requirements, and coordinating with the appropriate University offices to assess and support implementation of those requirements.
Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) are distinct categories of government information. Some projects may involve FCI, CUI, or both. ORS can assist researchers in determining which requirements apply based on the contract and applicable terms and conditions.
What Is Federal Contract Information?
Federal Contract Information generally includes information that:
- Is provided by or generated for the U.S. Government under a federal contract to develop or deliver a product or service; and
- Is not intended for public release.
FCI does not include information provided by the Government to the public, such as information available on public websites, or simple transactional information necessary to process payments.
Whether particular research or project information constitutes FCI depends on the federal contract and the circumstances under which the information is provided or generated.
How Is FCI Identified?
FCI requirements may be identified through:
- Federal procurement contracts and subcontracts
- Contract terms and conditions
- Information provided by a federal agency or prime contractor
- Government instructions regarding the protection of contract information
- Other contract documentation
Unlike CUI, FCI is generally not identified through standardized CUI markings or categories. Its status depends on the nature of the information and the federal contract under which it is provided or generated.
Researchers should contact ORS if a proposed or existing federal contract or subcontract includes safeguarding or cybersecurity requirements, references Federal Contract Information, or may involve nonpublic information provided by or generated for the Federal Government. ORS can assist in determining whether FCI requirements apply and identifying the applicable contractual requirements.
Examples of FCI
Depending on the contract and circumstances, FCI may include:
- Government-provided technical or project information not intended for public release
- Draft reports and deliverables prepared for the Government
- Contract performance documentation
- Government correspondence related to contract performance
- Nonpublic project information generated for the Government
- Other nonpublic information exchanged between the Government and a contractor in connection with contract performance
Not all information associated with a federal contract is necessarily FCI. Publicly available information, simple transactional information, and other excluded information may fall outside the definition.
When Might Researchers Encounter FCI?
Researchers may encounter FCI when:
- Performing research under a federal procurement contract or subcontract.
- Participating as a subcontractor on a federally contracted research project.
- Receiving nonpublic government information to support contract performance.
- Working with a prime contractor on a federal contract.
- Generating nonpublic information or deliverables for the Government under a federal contract.
- Conducting research subject to contractual information protection or cybersecurity requirements.
Federal grants and cooperative agreements generally do not involve Federal Contract Information because FCI is a federal acquisition concept associated with procurement contracts. However, grants and cooperative agreements may establish separate cybersecurity or research information protection requirements through sponsor terms and conditions.
Typical Safeguarding Considerations
Projects involving FCI may be subject to contractual requirements including:
- Access limited to authorized personnel.
- Protection of electronic and physical information from unauthorized access or disclosure.
- Cybersecurity safeguards specified by the applicable federal contract.
- Secure storage, processing, and transmission requirements.
- Appropriate access controls and authentication.
- Incident reporting requirements.
- Other sponsor-, agency-, or contract-specific information protection requirements.
The specific safeguards required depend on the federal contract, sponsoring agency, information involved, and applicable contractual cybersecurity requirements.
Researchers should not assume that standard University computing, storage, cloud, or collaboration resources satisfy requirements applicable to FCI. Applicable requirements should be identified before FCI is received, accessed, stored, processed, or transmitted using University resources.
When specialized computing, storage, cybersecurity, or other technical safeguards are required, ORS coordinates with the appropriate University technology offices to assess whether and how the requirements can be supported.
Federal Contract Cybersecurity Requirements
FCI is a federal acquisition concept associated with procurement contracts and subcontracts and generally does not apply to federal grants or cooperative agreements. Grants and cooperative agreements may, however, establish separate cybersecurity or research information protection requirements through sponsor terms and conditions.
The specific requirements depend on the federal agency, contract, subcontract, and clauses incorporated into the agreement. Requirements may differ between civilian agency and Department of Defense contracts and may change depending on whether the project involves FCI, CUI, or other categories of government information.
ORS reviews applicable contract and subcontract requirements in coordination with the Office of Sponsored Programs and appropriate University technology offices to identify cybersecurity and information protection requirements that may affect the proposed research.
Researchers should contact ORS before making commitments regarding the University's ability to meet federal contract cybersecurity requirements.
Related Requirements
Research involving FCI may also involve:
- Controlled Unclassified Information (CUI)
- Federal contract cybersecurity requirements
- Government Information
- Export-Controlled Information
- Research Information Protection
- Research Cybersecurity Baseline
- Data Protection Plans, when applicable
The presence of FCI does not necessarily mean that all of these requirements apply. ORS assists researchers in identifying the requirements applicable to the specific project.
How ORS Can Help
ORS assists researchers by:
- Determining whether a proposed or existing research activity involves FCI or FCI-related requirements.
- Reviewing applicable federal contracts, subcontracts, solicitations, and other award documents for safeguarding and cybersecurity requirements.
- Identifying applicable research information protection, cybersecurity, export control, and other requirements.
- Assessing applicable contractual requirements against current University capabilities in coordination with the appropriate University offices.
- Identifying whether a Data Protection Plan, System Security Plan, or other project-specific safeguarding documentation may be required.
- Coordinating with Research Computing & Informatics (RCI), DoIT, the Office of Sponsored Programs, and other appropriate University offices.
- Providing guidance throughout the proposal, contract review, award, and research lifecycle.
Federal Regulatory References
| Reference | Description |
|---|---|
| Federal Acquisition Regulation (FAR) | Establishes federal procurement requirements applicable to contracts with the U.S. Government, including requirements related to the protection of Federal Contract Information. |
| Defense Federal Acquisition Regulation Supplement (DFARS) (when applicable) | Supplements the FAR for Department of Defense acquisitions and may establish additional cybersecurity and information protection requirements for covered contracts. |
Need Assistance?
If your research project involves a federal procurement contract or subcontract, nonpublic government information, or federal contract cybersecurity requirements, contact the Office of Research Security before making commitments regarding information protection or cybersecurity requirements and before receiving, accessing, storing, processing, or transmitting FCI.
ORS will assist in identifying applicable contractual requirements and coordinate with the appropriate University offices to assess current University capabilities and determine whether and how the proposed activity can be supported.