Back to Blog

Does Your GSA Consultant have Safeguards in Place to Handle FCI and CUI?

by | Jul 21, 2026

Hiring a GSA consultant to help with a GSA Multiple Award Schedule offer or modification is often a smart business decision. The process is document-heavy, time-sensitive, and full of details that can affect pricing, contract scope, compliance obligations, and future sales.

But before you send files to an outside advisor, you should ask a serious question: is this GSA Schedule consultant qualified to handle Federal Contract Information (FCI) and Controlled Unclassified Information (CUI)?

GSA Schedule new offers and modifications often require contractors to transfer sensitive federal contract materials. Some are proprietary business records. Some are Federal Contract Information, or FCI. Some are Controlled Unclassified Information, or CUI. In all cases, the contractor is responsible for making sure its suppliers, subcontractors, and consultants have safeguards in place before receiving that information.

Emailing CUI documents to a consultant that does not have proper safeguards creates a security violation and exposes the contractor to compliance, contractual, and reputational risk.

What Are FCI and CUI?

Federal Contract Information is information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service. FAR 52.204-21 requires contractors to apply basic safeguarding requirements to covered contractor information systems that process, store, or transmit FCI.

Controlled Unclassified Information is a separate and more controlled category. The National Archives describes CUI as unclassified information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy. NIST SP 800-171 provides security requirements for protecting CUI in nonfederal systems and organizations.

For GSA Schedule contractors, the practical point is this: when a GSA consultant receives, stores, edits, uploads, or transmits sensitive contract materials on your behalf, that consultant becomes part of the information-handling chain.

CPARS Reports Are CUI and Often Enter the GSA Offer Process

One of the clearest examples is CPARS.

CPARS reports are produced by a government system. CPARS itself states that the system contains CUI, and FAR 42.1503 explains that past performance evaluations are used to support future award decisions and should be marked as Source Selection Information. CPARS guidance also treats past performance information as For Official Use Only/Source Selection Information.

That makes CPARS reports very different from ordinary marketing past performance summaries. They are government-generated performance records used in source selection. They may include ratings, narrative assessments, agency comments, contractor responses, and other details that are not intended for unrestricted distribution.

For new GSA Schedule offers, and for some contract actions where past performance support is required, contractors may need to provide CPARS reports or other past performance documentation through GSA eOffer. GSA eOffer is the system used to prepare and submit MAS offers to the Federal Acquisition Service, and it allows offerors to add supporting documents as part of the offer package.

If a GSA consultant asks a contractor to email CPARS reports as ordinary attachments, that should raise a red flag. CPARS reports should be handled as controlled information, transferred through appropriate secure channels, and accessed only by personnel with a legitimate need to know.

PWS and SOW Documents May Also Require Controlled Handling

CPARS reports are not the only concern. Many Performance Work Statements, Statements of Work, Statements of Objectives, task order documents, and project narratives used to support a GSA offer or modification may contain sensitive government or customer information.

Some PWS and SOW documents may be marked For Official Use Only, or FOUO. Others may include CUI markings, procurement-sensitive information, technical details, facility information, customer contact information, security requirements, or contract-specific operational details.

Even when a document is not perfectly marked, contractors should avoid treating it as ordinary paperwork. If the document came from a government customer, relates to nonpublic contract performance, or contains information that could harm the government, the customer, or the contractor if disclosed, it should be handled carefully.

That includes not emailing it to the GSA consultant who lack proper safeguards.

Coley GCS is Available to Help

Since 2001, Coley GCS has helped thousands of companies successfully WIN and manage GSA MAS Schedules, GWACs, and IDIQ contracts.

Book Your Free Consultation or Contact us by Email or at (210) 402-6766

What Information Typically Gets Shared During a GSA Offer or Modification?

A GSA Schedule consultant may need to review a wide range of materials, including:

  • CPARS reports and past performance records
  • PWS, SOW, SOO, and task order documents
  • Customer references and project narratives
  • Commercial pricing files and discount policies
  • Customer invoices and sales history
  • Commercial Sales Practices disclosures, when applicable
  • Basis of Award and discount relationship information
  • Product catalogs, part numbers, descriptions, and manufacturer data
  • Labor category descriptions, resumes, qualifications, and service narratives
  • Financial statements or revenue support
  • Subcontractor, teaming, supplier, or reseller authorization documents
  • Contract award documents and modification history
  • GSA correspondence, clarification requests, and negotiation records
  • SAM.gov, UEI, small business, and representations information
  • Trade secrets, proprietary methods, and internal cost assumptions

Some of this information is commercially sensitive. Some may be FCI. Some may be CUI. Some may include legacy markings such as FOUO. The contractor should not assume that because a GSA consultant is helping with a GSA Schedule, that the consultant is automatically prepared to receive and protect these materials.

The Contractor Remains Responsible for Its Information

A common mistake is assuming that once documents are sent to a GSA consultant, the consultant owns the safeguarding problem. That is not how contractors should think about it.

The contractor is responsible for deciding who gets access to sensitive government contract information and whether those recipients have appropriate safeguards. FAR 52.204-21 also requires contractors to include the substance of the clause in certain subcontracts where a subcontractor may have Federal Contract Information in or transiting through its information system.

Even when a consultant is not performing under a formal subcontract, the principle still matters: if a supplier, advisor, or consultant will receive FCI, CUI, CPARS reports, or sensitive government documents, the contractor should confirm that the consultant can protect the information before transfer.

Risks of Using an Unqualified GSA Consultant

The risks are practical and serious.

First, there is unauthorized disclosure. A CPARS report, PWS, SOW, invoice package, or negotiation record sent through unsecured channels can expose source selection information, competitive information, government-sensitive details, or proprietary contractor data.

Second, there is compliance risk. If FCI or CUI is stored or transmitted through systems without appropriate safeguards, the contractor may have violated contract requirements or government handling rules.

Third, there is business risk. Sensitive pricing, project performance, and customer information can affect negotiations, future proposals, competitive positioning, and customer trust.

Fourth, there is audit and accountability risk. If documents are scattered across unmanaged inboxes, personal drives, shared consumer accounts, or unsupported collaboration tools, the contractor may struggle to show who accessed the information, where it was stored, and whether it was later deleted.

Finally, there is reputational risk. Federal customers expect contractors to understand that CPARS, CUI, FOUO, and source selection information are not ordinary business records. A contractor that casually circulates those documents can undermine confidence in its internal controls.

Questions to Ask Before Sending Files

Before sharing CPARS reports, PWS documents, SOWs, or other sensitive materials with a GSA Schedule consultant, ask:

  • Do you have procedures for handling FCI and CUI?
  • How do you receive and store sensitive client documents?
  • Do you use secure file transfer instead of ordinary email attachments?
  • Who on your team can access our documents?
  • Do you use multifactor authentication?
  • Do you restrict access by client and project?
  • Do you use subcontractors, offshore support, or AI tools to process client files?
  • How do you prevent CUI from being uploaded into unauthorized systems?
  • How do you handle document retention and deletion after the engagement?
  • Can you comply with our contract-specific handling requirements?

A qualified consultant should be able to answer these questions clearly. If the answer is vague, the contractor should slow down before transferring sensitive materials.

Choose a GSA Consultant Who Understands Both GSA and Safeguarding

The right GSA consultant should understand GSA Schedule mechanics: offer preparation, pricing strategy, modifications, catalog updates, negotiation, compliance, and contract maintenance.

But technical GSA knowledge is not enough.

A GSA consultant helping with a GSA Schedule offer or modification may handle CPARS reports, PWS documents, SOWs, project narratives, pricing records, and contract correspondence. That consultant should understand that some of those materials may be CUI, FCI, FOUO, or Source Selection Information.

Contractors should choose a partner that uses secure intake processes, controlled access, appropriate file storage, and disciplined document handling. A GSA Schedule project should not become an uncontrolled data-sharing exercise.

Need Help With a GSA Schedule Offer or Modification?

Coley GCS helps companies pursue, modify, and manage GSA MAS Contracts with practical support throughout the contract lifecycle. If your team is preparing a new GSA Schedule offer, adding SINs, updating pricing, refreshing a catalog, or responding to GSA questions, Coley GCS can help you move through the process while keeping sensitive contract information organized and handled appropriately.

Schedule a consultation at https://calendly.com/coley-gcs/contracting-support or contact Coley GCS at hello@coleygcs.com.

About Coley GCS

With over 25 years of experience, Coley GCS has helped thousands of companies successfully win and manage GSA MAS Schedules, GWACs, and IDIQ contracts. Our dedicated team of experts provides ongoing support to ensure your Schedule stays compliant, competitive, and positioned for long-term success in the federal marketplace. From initial acquisition to modifications and annual compliance, we make the process easy and efficient, so you can focus on growing your government business.

Need help maximizing return on investment? Coley GCS also provides Business Development support and training that has helped companies win over $26 Billion in new contracts.

Contact us at hello@coleygcs.com, call us at 210-402-6766, or book time with our team to speak with one of our contracting expert.

0 Comments

Explore:Toggle Table of Content

Subscribe to Our Blog

Categories