Two kinds of information, two different bars
Federal Contract Information (FCI) is information you generate or receive under a contract that is not meant for public release. Nearly every federal contract touches FCI, and a baseline set of safeguarding requirements applies as soon as it does. Controlled Unclassified Information (CUI) is a narrower, more sensitive category, technical data, certain personnel information, export-controlled details, that carries a much heavier set of security obligations under NIST SP 800-171. Which one your contract involves determines which set of rules you are actually signing up for.
NIST SP 800-171, in plain terms
NIST SP 800-171 is a catalog of security controls, organized around things like access control, incident response, encryption, and monitoring. If your contract requires you to handle CUI, the relevant clause typically requires you to implement these controls and document how, usually through a system security plan and a score you self-report. It reads like a compliance document because it is one, but the underlying asks are largely ordinary good practice: know what has access to your systems, log what happens, patch what needs patching.
CMMC layers a certification on top
The Cybersecurity Maturity Model Certification, CMMC, is the Department of Defense's program for verifying that NIST 800-171 compliance is real rather than self-reported. It is being phased into DoD contracts in stages, and exactly which contracts require which level, and on what timeline, is still settling as of 2026, so check the specific solicitation and current DoD guidance rather than assuming last year's rule still applies. As a rough shape, lower levels lean on self-assessment and higher levels require a third-party assessment, and the level tends to track how sensitive the information on that contract actually is.
Start with an honest self-assessment
Whatever level applies to you, the starting move is the same: assess your current systems against the control list honestly, and write down where you actually fall short, not where you hope you stand. A gap list you build yourself, on your own timeline, is a plan. The same gap list discovered by a government assessor, or after an incident, is a problem.
This clause is not a suggestion
Treat the cybersecurity clause in your contract with the same seriousness as the pricing or delivery clauses. Noncompliance can affect your eligibility for the contract you are performing and for future ones that carry the same requirement. If you are unsure which requirements apply to a specific solicitation, ask before you bid, not after you win, since the cost of meeting these controls is real and belongs in your price.