Skip to main content
Back to Home

CMMC Compliance Glossary

63 essential terms for CMMC Level 2, NIST SP 800-171, SPRS scoring, and defense contractor cybersecurity compliance.

A3 terms

Access Control

Security

The largest NIST SP 800-171 control family with 22 controls governing who can access systems and data. Includes account management, separation of duties, least privilege, remote access, and wireless access restrictions.

Assessment Objective

Assessment

A specific determination statement defined in the assessment guidance. The 110 Level 2 requirements expand into 320 assessment objectives. Every applicable objective must be met for a requirement to be assessed as MET.

Audit Log

Security

A chronological record of system activities sufficient to reconstruct and examine security-relevant events. NIST SP 800-171 Audit & Accountability (AU) controls require creating, protecting, retaining, and reviewing audit logs.

B1 term

Body of Evidence

Compliance

The documentation and other objective evidence an organization presents during an assessment. It may include the SSP, any applicable POA&M, network diagrams, policies, procedures, audit logs, configuration evidence, demonstrations, and training records.

Evidence Collection Guide

C16 terms

C3PAO

(Certified Third-Party Assessment Organization)Assessment

An organization authorized by The Cyber AB to conduct CMMC Level 2 certification assessments. C3PAOs employ certified assessors who evaluate the applicable assessment objectives. During the current DoD suspension, solicitations and contracts may not designate Level 2 C3PAO assessments.

C3PAO Assessment Checklist

CAGE Code

(Commercial and Government Entity Code)DoD

A five-character alphanumeric identifier assigned to entities doing business with the federal government. Applicable SPRS and CMMC assessment records identify the organization by CAGE code. U.S. entities receive a CAGE code through SAM.gov registration.

CCA

(Certified CMMC Assessor)Assessment

An individual certified by The Cyber AB to conduct CMMC assessments as part of a C3PAO team. CCAs must complete training, pass exams, and maintain continuing education requirements.

CCP

(Certified CMMC Professional)Assessment

An individual certified by The Cyber AB who can advise organizations on CMMC readiness but cannot conduct official assessments. CCPs often work as consultants helping contractors prepare for C3PAO assessments.

CMMC

(Cybersecurity Maturity Model Certification)CMMC

A DoD verification framework with three levels. Level 2 uses the 110 NIST SP 800-171 Rev 2 security requirements. Although the regulatory framework provides for Level 2 Self and C3PAO assessments, current DoD suspension direction permits only Level 1 Self and Level 2 Self designations, not Level 2 C3PAO or Level 3.

CMMC Level 2 Guide

CMMC Level 1

CMMC

The foundational CMMC tier covering the 15 FAR 52.204-21 safeguards for contractor information systems that handle FCI but not CUI, when Level 1 is specified by an applicable solicitation or contract. Final status requires an annual self-assessment and annual affirmation.

Level 1 vs Level 2

CMMC Level 2

CMMC

The CMMC tier based on all 110 NIST SP 800-171 Rev 2 security requirements. During the current DoD suspension, only Level 2 Self may be designated. Final Level 2 status remains current for up to three years, subject to annual affirmation and status-maintenance conditions; Conditional status lasts no more than 180 days.

CMMC Level 2 Guide

CMMC Level 3

CMMC

The highest CMMC tier, based on the Level 2 requirements plus 24 selected enhanced requirements from the February 2021 NIST SP 800-172 and assessed by DIBCAC. The regulatory model allows DoD to designate Level 3 for selected contracts, but current DoD suspension direction prohibits Level 3 designations.

CMMC Phase 2

CMMC

The planned second phase of the CMMC rollout. DoD suspended the transition to Phase 2 and future implementation milestones on July 13, 2026 while it reviews the program. Phase 1 remains in effect, and current DoD direction permits only Level 1 Self and Level 2 Self designations.

Full CMMC Timeline

Conditional Assessment

Assessment

A temporary CMMC assessment status available only when the score is at least 88 points and the remaining POA&M items satisfy CMMC restrictions. The contractor must complete a closeout assessment within 180 days; contract eligibility still depends on the solicitation and contract.

Configuration Management

Security

The process of maintaining secure baseline configurations for all systems in the CUI scope. NIST SP 800-171 CM family requires documented baselines, change control, least functionality, and restriction of unauthorized software.

Continuous Monitoring

Compliance

An ongoing process to maintain awareness of security posture, vulnerabilities, and threats. Required by NIST SP 800-171 Security Assessment (CA) family. Includes periodic control assessments, system monitoring, and risk reassessment.

Control Family

NIST

A logical grouping of related security controls in NIST SP 800-171. There are 14 families: Access Control (AC), Awareness & Training (AT), Audit & Accountability (AU), Configuration Management (CM), Identification & Authentication (IA), Incident Response (IR), Maintenance (MA), Media Protection (MP), Personnel Security (PS), Physical Protection (PE), Risk Assessment (RA), Security Assessment (CA), System & Communications Protection (SC), and System & Information Integrity (SI).

CUI

(Controlled Unclassified Information)DoD

Government-created or owned information that requires safeguarding controls per law, regulation, or government-wide policy. CUI is not classified but must be protected from unauthorized disclosure. Common categories include technical data, export-controlled information, and critical infrastructure data.

CUI Identification Guide

CUI Enclave

Security

A segmented network environment specifically designed to process, store, and transmit CUI. By isolating CUI into an enclave, contractors reduce the number of systems in scope for CMMC, lowering both implementation cost and assessment complexity.

Enclave Architecture Guide

Cyber Incident

Security

An action taken through computer networks that compromises the security of an information system or the information it processes, stores, or transmits. When DFARS 252.204-7012 applies, covered cyber incidents must be rapidly reported through the DoD-designated process within 72 hours of discovery.

D8 terms

DCMA

(Defense Contract Management Agency)DoD

The DoD agency responsible for contract administration and oversight. DCMA's DIBCAC division conducts CMMC Level 3 assessments and oversees the assessment ecosystem.

DFARS

(Defense Federal Acquisition Regulation Supplement)DoD

Supplemental regulations to the FAR that apply specifically to DoD acquisitions. DFARS 252.204-7012 includes safeguarding, covered cyber-incident reporting, preservation, access, and applicable subcontract flow-down duties.

DFARS 252.204-7012

DoD

The contract clause titled "Safeguarding Covered Defense Information and Cyber Incident Reporting." It requires adequate security for covered contractor information systems and reporting of covered cyber incidents within 72 hours, with additional preservation, access, malicious-software, cloud-provider, and applicable subcontract flow-down duties.

DFARS 252.204-7019

DoD

A solicitation provision requiring an offeror that must implement NIST SP 800-171 to have a current assessment on record in SPRS before award.

DFARS 252.204-7021

DoD

The contract clause requiring the contractor to maintain the CMMC level and assessment type specified in the solicitation or contract for relevant systems. It also contains affirmation, SPRS, and subcontract flow-down requirements.

DIB

(Defense Industrial Base)DoD

The network of companies, universities, and research organizations that designs, builds, and sustains U.S. defense systems. CMMC applicability and assessment type are established by the applicable solicitation or contract; separate safeguarding duties apply to FCI and CUI.

DIBCAC

(Defense Industrial Base Cybersecurity Assessment Center)DoD

A division of DCMA responsible for conducting CMMC Level 3 assessments (government-led) and overseeing the C3PAO ecosystem for Level 2 assessments. DIBCAC assessors are government employees.

DLP

(Data Loss Prevention)Security

Technologies and processes that prevent sensitive information (including CUI) from being transmitted outside authorized boundaries. DLP is a key technical control for Media Protection (MP) and System & Communications Protection (SC) families.

E2 terms

EDR

(Endpoint Detection and Response)Security

Security software that continuously monitors endpoints (workstations, servers, mobile devices) for suspicious activity. EDR supports multiple NIST SP 800-171 control families including System & Information Integrity (SI) and Audit & Accountability (AU).

Evidence Artifact

Compliance

A document, screenshot, log, configuration export, or other record that may support assessment of a security requirement. The current DoD Level 2 guide uses examine, interview, and test methods across 320 objectives; no single artifact type proves every objective or guarantees acceptance.

Evidence Collection Best Practices

F6 terms

FAR

(Federal Acquisition Regulation)DoD

The primary regulation governing all federal government acquisitions. FAR 52.204-21 defines the 15 basic safeguarding requirements for FCI that form the basis of CMMC Level 1.

FCI

(Federal Contract Information)DoD

Information provided by or generated for the government under a contract that is not intended for public release. FCI is subject to the FAR 52.204-21 safeguards when that clause applies. If an applicable solicitation or contract includes DFARS 252.204-7021, Level 1 may be designated for systems processing FCI but not CUI; systems processing CUI may be designated Level 2. Verify the solicitation, contract, and current modification.

FedRAMP

(Federal Risk and Authorization Management Program)Compliance

A government-wide program providing a standardized approach to security assessment, authorization, and monitoring for cloud services. Applicable DFARS and CMMC provisions may require a CSP product or service to be FedRAMP Moderate authorized or meet the specified equivalency criteria. That status may support inherited responsibilities but does not, by itself, establish the organization's compliance or remove connected assets and services from scope.

FIPS 140-2

Security

U.S. government security requirements for cryptographic modules. NIST SP 800-171 Rev. 2 requirement 3.13.11 requires FIPS-validated cryptography when cryptography is used to protect the confidentiality of CUI. Validate the module, certificate status, operating mode, and the specific safeguarding requirement; an algorithm or protocol name alone does not establish compliance.

FIPS 199

Security

"Standards for Security Categorization of Federal Information and Information Systems." Defines three impact levels (low, moderate, high) for confidentiality, integrity, and availability. CUI is categorized as moderate confidentiality, which drives the 800-171 control selection.

Flow-Down

DoD

The requirement to pass applicable CMMC and DFARS cybersecurity obligations to subcontractors. Under 32 CFR 170.23, a subcontractor processing only FCI needs at least Level 1; one processing CUI needs at least Level 2 Self, or Level 2 C3PAO when the prime contract requires that assessment type. During the current DoD suspension, solicitations and contracts may designate only Level 1 Self or Level 2 Self.

G1 term

Gap Analysis

Assessment

A systematic evaluation of the difference between a contractor's current security posture and the requirements of NIST SP 800-171. Gap analysis identifies unimplemented or partially implemented controls and prioritizes remediation by SPRS weight impact.

Try Free Gap Analysis

I2 terms

Incident Response Plan

Security

A documented set of procedures for detecting, responding to, and recovering from security incidents. Required by NIST SP 800-171 Incident Response (IR) family. Must include preparation, detection, containment, eradication, recovery, and lessons learned phases.

Inherited Control

Compliance

A security responsibility implemented wholly or partly by an external entity, such as a cloud service provider. The organization must document the inherited implementation and evidence in its SSP and the provider's customer-responsibility information. Provider authorization does not, by itself, establish the organization's compliance.

M1 term

MFA

(Multi-Factor Authentication)Security

An authentication method requiring two or more verification factors: something you know (password), something you have (token), or something you are (biometric). Required by NIST SP 800-171 control IA.L2-3.5.3 for all network access to privileged and non-privileged accounts.

N3 terms

NIST SP 800-171

NIST

"Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations." A NIST special publication defining 110 security controls across 14 families. Rev 2 is the current CMMC Level 2 baseline. Rev 3 was published in 2024 but CMMC still references Rev 2.

Rev 3 Changes Explained

NIST SP 800-171A

NIST

"Assessing Security Requirements for CUI." The companion assessment publication underlying the 320 objectives used for CMMC Level 2 assessments. Each of the 110 requirements has one or more objectives, and every applicable objective must be met for the requirement to be assessed as MET.

NIST SP 800-172

NIST

"Enhanced Security Requirements for Protecting CUI." CMMC Level 3 currently incorporates 24 selected enhanced requirements from the February 2021 publication. NIST published SP 800-172 Revision 3 in May 2026, but DoD has not adopted that revision as the CMMC Level 3 baseline.

O3 terms

OSA

(Organization Seeking Assessment)Assessment

The 32 CFR Part 170 term for an organization seeking any CMMC assessment. An organization seeking a Level 2 C3PAO or Level 3 certification assessment is both an OSA and an OSC.

OSC

(Organization Seeking Certification)Assessment

Under 32 CFR Part 170, an organization seeking a Level 2 C3PAO or Level 3 certification assessment. An OSC is also an Organization Seeking Assessment (OSA). During the current DoD suspension, solicitations and contracts may not designate Level 2 C3PAO or Level 3 assessments.

OSD

(Office of the Secretary of Defense)DoD

The principal staff element of the Secretary of Defense. OSD oversees the CMMC program and publishes the CMMC rules under 32 CFR Part 170.

P3 terms

POA&M

(Plan of Action and Milestones)Compliance

A document identifying security requirements that are not yet fully implemented and the plan to close each gap. A POA&M does not substitute for implementation, and each requirement assessed as NOT MET is still deducted under the DoD scoring methodology.

Policy Document

Compliance

A formal statement of management intent that defines rules and expectations for a security topic. NIST SP 800-171 requires organizations to provide evidence that applicable requirements are satisfied, but it does not prescribe one separate policy document for every control family.

Policy Documentation Templates

Prime Contractor

DoD

A company that holds a direct contract with the DoD. When DFARS 252.204-7021 applies, a prime must flow the clause to a subcontractor that will process, store, or transmit FCI or CUI, require the appropriate level under 32 CFR 170.23, and verify the required current CMMC status before subcontract award.

R1 term

Remediation

Compliance

The process of closing security gaps identified during a gap analysis or assessment. Remediation may include implementing technical controls, writing policies, training personnel, or reconfiguring systems. Effective remediation is prioritized by SPRS weight impact.

S9 terms

Scope Determination

Compliance

The process of identifying the assessment boundary and all applicable asset categories, people, facilities, and external providers. Under 32 CFR 170.19, Level 2 scope includes CUI assets, security protection assets, contractor risk-managed assets, specialized assets, and applicable ESP or CSP dependencies. Reducing asset count does not reduce the 110-requirement baseline or guarantee less assessment time or cost.

Security Control

NIST

A specific safeguard or countermeasure prescribed by NIST SP 800-171 to protect CUI. Each control has an ID (e.g., AC.L2-3.1.1), a description, and one or more assessment objectives defined in 800-171A.

Self-Assessment

Assessment

An organization's evaluation of its own safeguard or security-requirement implementation. When DFARS 252.204-7019 applies and the offeror is required to implement NIST SP 800-171, a current assessment must be recorded in SPRS before award. CMMC Level 1 and Level 2 Self also require results and affirmations in SPRS when contractually required.

Shared Responsibility Model

Compliance

A framework where the cloud service provider and the contractor each bear responsibility for specific security controls. The contractor must document which controls are fully implemented, partially inherited, or fully inherited from the provider.

SIEM

(Security Information and Event Management)Security

A system that collects, correlates, and analyzes security event data from across an organization's IT environment. SIEM supports NIST SP 800-171 audit and accountability controls (AU family) by providing centralized log management and alerting.

SPRS

(Supplier Performance Risk System)Assessment

A DoD system that stores applicable NIST SP 800-171 and CMMC assessment results and affirmations. When DFARS 252.204-7019 applies, an offeror required to implement NIST SP 800-171 must have a current assessment in SPRS before award. Basic Assessment scores range from -203 to 110 and do not, by themselves, establish CMMC status.

SPRS Score Calculator

SPRS Score

Assessment

A numerical value from -203 to 110 representing a contractor's NIST SP 800-171 implementation status. The DoD assessment methodology deducts 1, 3, or 5 points for each applicable requirement that is not met; placing an item on a POA&M does not prevent the deduction.

How to Calculate Your SPRS Score

SSP

(System Security Plan)Compliance

A formal document describing how an organization implements each of the 110 NIST SP 800-171 security controls. The SSP defines the system boundary, describes the operating environment, and details each control's implementation. Required for CMMC Level 2 assessment.

System Boundary

Security

The defined perimeter of all hardware, software, and network components that process, store, or transmit CUI. Everything inside the boundary is in scope for CMMC assessment. Reducing the boundary through enclave architecture lowers compliance cost.

T1 term

The Cyber AB

Assessment

Formerly the CMMC Accreditation Body (CMMC-AB). The sole authorized accreditation body for the CMMC ecosystem. The Cyber AB accredits C3PAOs, certifies individual assessors, and maintains the CMMC marketplace.

U1 term

UEI

(Unique Entity Identifier)DoD

A 12-character alphanumeric identifier assigned through SAM.gov that replaced the DUNS number as the primary identifier for entities registered to do business with the federal government.

V1 term

Vulnerability Scanning

Security

The automated process of probing systems for known security weaknesses. NIST SP 800-171 control RA.L2-3.11.2 requires scanning for vulnerabilities in organizational systems periodically and when new vulnerabilities are identified.

Z1 term

Zero Trust Architecture

Security

A security model that assumes no user, device, or network is inherently trusted. Every access request is verified regardless of location. While not explicitly required by CMMC Level 2, zero trust principles align with Access Control (AC) and Identification & Authentication (IA) controls.

Put These Terms Into Practice

Review all 110 NIST SP 800-171 requirements and see an estimated SPRS score update from your entered statuses. No credit card required.

Start Free Assessment