Access Control
SecurityThe largest NIST SP 800-171 control family with 22 controls governing who can access systems and data. Includes account management, separation of duties, least privilege, remote access, and wireless access restrictions.
63 essential terms for CMMC Level 2, NIST SP 800-171, SPRS scoring, and defense contractor cybersecurity compliance.
The largest NIST SP 800-171 control family with 22 controls governing who can access systems and data. Includes account management, separation of duties, least privilege, remote access, and wireless access restrictions.
A specific determination statement defined in the assessment guidance. The 110 Level 2 requirements expand into 320 assessment objectives. Every applicable objective must be met for a requirement to be assessed as MET.
A chronological record of system activities sufficient to reconstruct and examine security-relevant events. NIST SP 800-171 Audit & Accountability (AU) controls require creating, protecting, retaining, and reviewing audit logs.
The documentation and other objective evidence an organization presents during an assessment. It may include the SSP, any applicable POA&M, network diagrams, policies, procedures, audit logs, configuration evidence, demonstrations, and training records.
Evidence Collection GuideAn organization authorized by The Cyber AB to conduct CMMC Level 2 certification assessments. C3PAOs employ certified assessors who evaluate the applicable assessment objectives. During the current DoD suspension, solicitations and contracts may not designate Level 2 C3PAO assessments.
C3PAO Assessment ChecklistA five-character alphanumeric identifier assigned to entities doing business with the federal government. Applicable SPRS and CMMC assessment records identify the organization by CAGE code. U.S. entities receive a CAGE code through SAM.gov registration.
An individual certified by The Cyber AB to conduct CMMC assessments as part of a C3PAO team. CCAs must complete training, pass exams, and maintain continuing education requirements.
An individual certified by The Cyber AB who can advise organizations on CMMC readiness but cannot conduct official assessments. CCPs often work as consultants helping contractors prepare for C3PAO assessments.
A DoD verification framework with three levels. Level 2 uses the 110 NIST SP 800-171 Rev 2 security requirements. Although the regulatory framework provides for Level 2 Self and C3PAO assessments, current DoD suspension direction permits only Level 1 Self and Level 2 Self designations, not Level 2 C3PAO or Level 3.
CMMC Level 2 GuideThe foundational CMMC tier covering the 15 FAR 52.204-21 safeguards for contractor information systems that handle FCI but not CUI, when Level 1 is specified by an applicable solicitation or contract. Final status requires an annual self-assessment and annual affirmation.
Level 1 vs Level 2The CMMC tier based on all 110 NIST SP 800-171 Rev 2 security requirements. During the current DoD suspension, only Level 2 Self may be designated. Final Level 2 status remains current for up to three years, subject to annual affirmation and status-maintenance conditions; Conditional status lasts no more than 180 days.
CMMC Level 2 GuideThe highest CMMC tier, based on the Level 2 requirements plus 24 selected enhanced requirements from the February 2021 NIST SP 800-172 and assessed by DIBCAC. The regulatory model allows DoD to designate Level 3 for selected contracts, but current DoD suspension direction prohibits Level 3 designations.
The planned second phase of the CMMC rollout. DoD suspended the transition to Phase 2 and future implementation milestones on July 13, 2026 while it reviews the program. Phase 1 remains in effect, and current DoD direction permits only Level 1 Self and Level 2 Self designations.
Full CMMC TimelineA temporary CMMC assessment status available only when the score is at least 88 points and the remaining POA&M items satisfy CMMC restrictions. The contractor must complete a closeout assessment within 180 days; contract eligibility still depends on the solicitation and contract.
The process of maintaining secure baseline configurations for all systems in the CUI scope. NIST SP 800-171 CM family requires documented baselines, change control, least functionality, and restriction of unauthorized software.
An ongoing process to maintain awareness of security posture, vulnerabilities, and threats. Required by NIST SP 800-171 Security Assessment (CA) family. Includes periodic control assessments, system monitoring, and risk reassessment.
A logical grouping of related security controls in NIST SP 800-171. There are 14 families: Access Control (AC), Awareness & Training (AT), Audit & Accountability (AU), Configuration Management (CM), Identification & Authentication (IA), Incident Response (IR), Maintenance (MA), Media Protection (MP), Personnel Security (PS), Physical Protection (PE), Risk Assessment (RA), Security Assessment (CA), System & Communications Protection (SC), and System & Information Integrity (SI).
Government-created or owned information that requires safeguarding controls per law, regulation, or government-wide policy. CUI is not classified but must be protected from unauthorized disclosure. Common categories include technical data, export-controlled information, and critical infrastructure data.
CUI Identification GuideA segmented network environment specifically designed to process, store, and transmit CUI. By isolating CUI into an enclave, contractors reduce the number of systems in scope for CMMC, lowering both implementation cost and assessment complexity.
Enclave Architecture GuideAn action taken through computer networks that compromises the security of an information system or the information it processes, stores, or transmits. When DFARS 252.204-7012 applies, covered cyber incidents must be rapidly reported through the DoD-designated process within 72 hours of discovery.
The DoD agency responsible for contract administration and oversight. DCMA's DIBCAC division conducts CMMC Level 3 assessments and oversees the assessment ecosystem.
Supplemental regulations to the FAR that apply specifically to DoD acquisitions. DFARS 252.204-7012 includes safeguarding, covered cyber-incident reporting, preservation, access, and applicable subcontract flow-down duties.
The contract clause titled "Safeguarding Covered Defense Information and Cyber Incident Reporting." It requires adequate security for covered contractor information systems and reporting of covered cyber incidents within 72 hours, with additional preservation, access, malicious-software, cloud-provider, and applicable subcontract flow-down duties.
A solicitation provision requiring an offeror that must implement NIST SP 800-171 to have a current assessment on record in SPRS before award.
The contract clause requiring the contractor to maintain the CMMC level and assessment type specified in the solicitation or contract for relevant systems. It also contains affirmation, SPRS, and subcontract flow-down requirements.
The network of companies, universities, and research organizations that designs, builds, and sustains U.S. defense systems. CMMC applicability and assessment type are established by the applicable solicitation or contract; separate safeguarding duties apply to FCI and CUI.
A division of DCMA responsible for conducting CMMC Level 3 assessments (government-led) and overseeing the C3PAO ecosystem for Level 2 assessments. DIBCAC assessors are government employees.
Technologies and processes that prevent sensitive information (including CUI) from being transmitted outside authorized boundaries. DLP is a key technical control for Media Protection (MP) and System & Communications Protection (SC) families.
Security software that continuously monitors endpoints (workstations, servers, mobile devices) for suspicious activity. EDR supports multiple NIST SP 800-171 control families including System & Information Integrity (SI) and Audit & Accountability (AU).
A document, screenshot, log, configuration export, or other record that may support assessment of a security requirement. The current DoD Level 2 guide uses examine, interview, and test methods across 320 objectives; no single artifact type proves every objective or guarantees acceptance.
Evidence Collection Best PracticesThe primary regulation governing all federal government acquisitions. FAR 52.204-21 defines the 15 basic safeguarding requirements for FCI that form the basis of CMMC Level 1.
Information provided by or generated for the government under a contract that is not intended for public release. FCI is subject to the FAR 52.204-21 safeguards when that clause applies. If an applicable solicitation or contract includes DFARS 252.204-7021, Level 1 may be designated for systems processing FCI but not CUI; systems processing CUI may be designated Level 2. Verify the solicitation, contract, and current modification.
A government-wide program providing a standardized approach to security assessment, authorization, and monitoring for cloud services. Applicable DFARS and CMMC provisions may require a CSP product or service to be FedRAMP Moderate authorized or meet the specified equivalency criteria. That status may support inherited responsibilities but does not, by itself, establish the organization's compliance or remove connected assets and services from scope.
U.S. government security requirements for cryptographic modules. NIST SP 800-171 Rev. 2 requirement 3.13.11 requires FIPS-validated cryptography when cryptography is used to protect the confidentiality of CUI. Validate the module, certificate status, operating mode, and the specific safeguarding requirement; an algorithm or protocol name alone does not establish compliance.
"Standards for Security Categorization of Federal Information and Information Systems." Defines three impact levels (low, moderate, high) for confidentiality, integrity, and availability. CUI is categorized as moderate confidentiality, which drives the 800-171 control selection.
The requirement to pass applicable CMMC and DFARS cybersecurity obligations to subcontractors. Under 32 CFR 170.23, a subcontractor processing only FCI needs at least Level 1; one processing CUI needs at least Level 2 Self, or Level 2 C3PAO when the prime contract requires that assessment type. During the current DoD suspension, solicitations and contracts may designate only Level 1 Self or Level 2 Self.
A systematic evaluation of the difference between a contractor's current security posture and the requirements of NIST SP 800-171. Gap analysis identifies unimplemented or partially implemented controls and prioritizes remediation by SPRS weight impact.
Try Free Gap AnalysisA documented set of procedures for detecting, responding to, and recovering from security incidents. Required by NIST SP 800-171 Incident Response (IR) family. Must include preparation, detection, containment, eradication, recovery, and lessons learned phases.
A security responsibility implemented wholly or partly by an external entity, such as a cloud service provider. The organization must document the inherited implementation and evidence in its SSP and the provider's customer-responsibility information. Provider authorization does not, by itself, establish the organization's compliance.
An authentication method requiring two or more verification factors: something you know (password), something you have (token), or something you are (biometric). Required by NIST SP 800-171 control IA.L2-3.5.3 for all network access to privileged and non-privileged accounts.
"Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations." A NIST special publication defining 110 security controls across 14 families. Rev 2 is the current CMMC Level 2 baseline. Rev 3 was published in 2024 but CMMC still references Rev 2.
Rev 3 Changes Explained"Assessing Security Requirements for CUI." The companion assessment publication underlying the 320 objectives used for CMMC Level 2 assessments. Each of the 110 requirements has one or more objectives, and every applicable objective must be met for the requirement to be assessed as MET.
"Enhanced Security Requirements for Protecting CUI." CMMC Level 3 currently incorporates 24 selected enhanced requirements from the February 2021 publication. NIST published SP 800-172 Revision 3 in May 2026, but DoD has not adopted that revision as the CMMC Level 3 baseline.
The 32 CFR Part 170 term for an organization seeking any CMMC assessment. An organization seeking a Level 2 C3PAO or Level 3 certification assessment is both an OSA and an OSC.
Under 32 CFR Part 170, an organization seeking a Level 2 C3PAO or Level 3 certification assessment. An OSC is also an Organization Seeking Assessment (OSA). During the current DoD suspension, solicitations and contracts may not designate Level 2 C3PAO or Level 3 assessments.
The principal staff element of the Secretary of Defense. OSD oversees the CMMC program and publishes the CMMC rules under 32 CFR Part 170.
A document identifying security requirements that are not yet fully implemented and the plan to close each gap. A POA&M does not substitute for implementation, and each requirement assessed as NOT MET is still deducted under the DoD scoring methodology.
A formal statement of management intent that defines rules and expectations for a security topic. NIST SP 800-171 requires organizations to provide evidence that applicable requirements are satisfied, but it does not prescribe one separate policy document for every control family.
Policy Documentation TemplatesA company that holds a direct contract with the DoD. When DFARS 252.204-7021 applies, a prime must flow the clause to a subcontractor that will process, store, or transmit FCI or CUI, require the appropriate level under 32 CFR 170.23, and verify the required current CMMC status before subcontract award.
The process of closing security gaps identified during a gap analysis or assessment. Remediation may include implementing technical controls, writing policies, training personnel, or reconfiguring systems. Effective remediation is prioritized by SPRS weight impact.
The process of identifying the assessment boundary and all applicable asset categories, people, facilities, and external providers. Under 32 CFR 170.19, Level 2 scope includes CUI assets, security protection assets, contractor risk-managed assets, specialized assets, and applicable ESP or CSP dependencies. Reducing asset count does not reduce the 110-requirement baseline or guarantee less assessment time or cost.
A specific safeguard or countermeasure prescribed by NIST SP 800-171 to protect CUI. Each control has an ID (e.g., AC.L2-3.1.1), a description, and one or more assessment objectives defined in 800-171A.
An organization's evaluation of its own safeguard or security-requirement implementation. When DFARS 252.204-7019 applies and the offeror is required to implement NIST SP 800-171, a current assessment must be recorded in SPRS before award. CMMC Level 1 and Level 2 Self also require results and affirmations in SPRS when contractually required.
A framework where the cloud service provider and the contractor each bear responsibility for specific security controls. The contractor must document which controls are fully implemented, partially inherited, or fully inherited from the provider.
A system that collects, correlates, and analyzes security event data from across an organization's IT environment. SIEM supports NIST SP 800-171 audit and accountability controls (AU family) by providing centralized log management and alerting.
A DoD system that stores applicable NIST SP 800-171 and CMMC assessment results and affirmations. When DFARS 252.204-7019 applies, an offeror required to implement NIST SP 800-171 must have a current assessment in SPRS before award. Basic Assessment scores range from -203 to 110 and do not, by themselves, establish CMMC status.
SPRS Score CalculatorA numerical value from -203 to 110 representing a contractor's NIST SP 800-171 implementation status. The DoD assessment methodology deducts 1, 3, or 5 points for each applicable requirement that is not met; placing an item on a POA&M does not prevent the deduction.
How to Calculate Your SPRS ScoreA formal document describing how an organization implements each of the 110 NIST SP 800-171 security controls. The SSP defines the system boundary, describes the operating environment, and details each control's implementation. Required for CMMC Level 2 assessment.
The defined perimeter of all hardware, software, and network components that process, store, or transmit CUI. Everything inside the boundary is in scope for CMMC assessment. Reducing the boundary through enclave architecture lowers compliance cost.
Formerly the CMMC Accreditation Body (CMMC-AB). The sole authorized accreditation body for the CMMC ecosystem. The Cyber AB accredits C3PAOs, certifies individual assessors, and maintains the CMMC marketplace.
A 12-character alphanumeric identifier assigned through SAM.gov that replaced the DUNS number as the primary identifier for entities registered to do business with the federal government.
The automated process of probing systems for known security weaknesses. NIST SP 800-171 control RA.L2-3.11.2 requires scanning for vulnerabilities in organizational systems periodically and when new vulnerabilities are identified.
A security model that assumes no user, device, or network is inherently trusted. Every access request is verified regardless of location. While not explicitly required by CMMC Level 2, zero trust principles align with Access Control (AC) and Identification & Authentication (IA) controls.
Review all 110 NIST SP 800-171 requirements and see an estimated SPRS score update from your entered statuses. No credit card required.
Start Free Assessment