Plain-English definitions for every acronym and term you will encounter in CMMC, NIST 800-171, and defense contractor cybersecurity compliance. 40 terms, alphabetically organized.
The CMMC Accreditation Body (officially: The Cyber AB) is the independent non-profit organization that manages the CMMC ecosystem - authorizing C3PAOs, RPOs, and individual assessors, and maintaining the Cyber AB Marketplace where contractors can find authorized organizations. Learn more →
A senior official at each defense contractor must annually affirm in SPRS that their organization's security plan is current and their controls are implemented as described. Submitting a false affirmation is a potential False Claims Act violation. Learn more →
The defined set of systems, people, and locations that are in scope for a CMMC or NIST 800-171 assessment. Systems that store, process, or transmit CUI are in scope. Shrinking the assessment boundary (through network segmentation or limiting which systems touch CUI) reduces assessment cost and complexity.
A timestamped record of events occurring within a system, including user logins, file access, configuration changes, and administrative actions. NIST SP 800-171 practice 3.3.1 requires creating and retaining audit logs. Logs must be protected from unauthorized modification and retained long enough to support incident investigation. Learn more →
Microsoft's full-disk encryption technology for Windows. Encrypts entire drive volumes, protecting data if a device is lost or stolen. CMMC practice 3.13.16 (protect CUI at rest) is commonly implemented using BitLocker for Windows endpoints, enforced via Intune MDM policy. Learn more →
An organization authorized by the Cyber AB to conduct official CMMC Level 2 assessments. C3PAOs employ Certified CMMC Assessors (CCAs) who conduct the actual assessment. Only a C3PAO can issue a CMMC Level 2 certification - an RPO cannot. As of mid-2026, approximately 100 C3PAOs are authorized to assess over 100,000 defense contractors. Learn more →
An individual certified by the Cyber AB to conduct CMMC assessments. CCAs must be employed by an authorized C3PAO to conduct official Level 2 assessments. CCAs are trained in the NIST SP 800-171A assessment methodology and certified through a Cyber AB examination process. Learn more →
A DoD cybersecurity program requiring defense contractors to meet specified security standards to handle Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC has three levels: Level 1 (17 practices, self-assessment), Level 2 (110 practices, third-party assessment), and Level 3 (110+ practices, government-led assessment). Learn more →
Information that requires safeguarding per law, regulation, or government-wide policy, but is not classified. CUI includes technical data, export-controlled information, privacy information, and sensitive contract information. The presence of CUI in a contract is what triggers CMMC Level 2 requirements. CUI is marked with specific designations like CUI//SP-CTI or CUI//PRVCY. Learn more →
An Azure Active Directory (Entra ID) feature that enforces access policies based on conditions such as user role, device compliance state, location, and risk level. Used to implement CMMC practices including MFA requirements (3.5.3) and remote access controls (3.1.12-3.1.15). Learn more →
See Accreditation Body. The Cyber AB maintains the official marketplace at cybermarketplace.com where contractors can verify that a C3PAO or RPO is legitimately authorized. Learn more →
The DoD agency responsible for industrial security, including oversight of facilities that handle classified information and support for the CMMC program. DCSA operates DISS (Defense Information System for Security) and supports contractor security clearance processing.
Regulations supplementing the Federal Acquisition Regulation (FAR) for DoD contracts. DFARS clause 252.204-7012 requires contractors to implement NIST SP 800-171 and report cyber incidents. DFARS 252.204-7021 is the CMMC clause that will require certification. Learn more →
The network of companies and organizations that provide goods and services to the U.S. Department of Defense. Includes prime contractors, subcontractors, suppliers, and research institutions at all tiers. CMMC requirements apply throughout the DIB supply chain via flow-down clauses. Learn more →
The DoD organization that conducts government-led CMMC assessments (High assessments) for the most sensitive defense programs. DIBCAC assessments are required for Level 3 and may be triggered by anomalous SPRS scores, cyber incidents, or specific contract requirements.
Security technology that continuously monitors endpoints (workstations, servers, mobile devices) for malicious activity, records endpoint telemetry, and provides detection and response capabilities. EDR satisfies CMMC practices including 3.14.2 (malicious code protection) and 3.14.6 (monitor for attacks).
A network segment or isolated environment that contains all systems handling CUI, separated from the rest of the organization's network. Creating a CUI enclave limits the CMMC assessment boundary to the enclave rather than the entire organization, reducing assessment scope and cost.
Microsoft's cloud identity platform (formerly Azure Active Directory). The foundational identity and access management system for Microsoft 365 environments. Used to implement CMMC identity and authentication practices including MFA, conditional access, password policies, and privileged account management. Learn more →
The DoD system used to manage security assessment results and authorizations. C3PAO assessment results for CMMC Level 2 are submitted to CMMC eMASS, creating the official record of a contractor's certification status.
A federal law that imposes liability on individuals and organizations that defraud the federal government. In CMMC/cybersecurity contexts, submitting an inflated SPRS score - claiming compliance you have not achieved - is a potential FCA violation. DoJ has settled multiple cybersecurity FCA cases including MORSECORP ($4.6M) and LOGZONE ($507K). Learn more →
Information provided by or generated for the government under a contract, not intended for public release. FCI triggers CMMC Level 1 requirements (17 practices). FCI that meets additional sensitivity thresholds becomes CUI and triggers Level 2 requirements.
Standards published by NIST for use in federal computer systems. FIPS 140-2 (and the current FIPS 140-3) define requirements for cryptographic modules. CMMC practice 3.13.11 requires FIPS-validated cryptography for protecting CUI. Commercial encryption products used in CMMC environments must be FIPS 140-2 validated.
A condition where a foreign interest holds ownership, control, or the ability to influence the operations of a U.S. defense contractor in a manner that could adversely affect national security. FOCI can limit a company's eligibility for classified contracts and affects CMMC assessment requirements.
The requirement for prime contractors to pass CMMC and NIST 800-171 compliance requirements down to their subcontractors who handle CUI. If you receive CUI from a prime, their CMMC obligations flow to you. Primes are increasingly requiring proof of compliance before awarding subcontracts. Learn more →
Microsoft cloud environments specifically designed for government contractors. GCC (Government Community Cloud) and GCC High are FedRAMP authorized and provide enhanced data residency and sovereignty controls. Contractors handling CUI typically need GCC at minimum; more sensitive programs may require GCC High or Azure Government. Learn more →
Microsoft Intune is a cloud-based mobile device management (MDM) and mobile application management (MAM) platform. Used in CMMC environments to enforce endpoint configuration baselines (3.4.1), deploy encryption (3.13.16), manage mobile devices (3.1.18), and block non-compliant devices via Conditional Access integration. Learn more →
Authentication requiring two or more factors: something you know (password), something you have (authenticator app or hardware token), or something you are (biometric). CMMC practice 3.5.3 requires MFA for all privileged account access and for network access to non-privileged accounts. One of the highest-weight practices at -5 points. Learn more →
A company that remotely manages and supports a client's IT infrastructure. MSPs that access CUI systems are subject to CMMC requirements and may be in scope for an assessment. MSPs must maintain their own CMMC compliance posture for the environments they manage.
A U.S. federal agency that develops and publishes cybersecurity standards and frameworks. NIST SP 800-171 defines the 110 security requirements for protecting CUI in non-federal systems. NIST CSF (Cybersecurity Framework) provides a voluntary framework for managing cybersecurity risk. Learn more →
The NIST Special Publication defining 110 security requirements for protecting Controlled Unclassified Information in non-federal systems and organizations. CMMC Level 2 maps directly to all 110 practices in NIST SP 800-171 Rev 2. Rev 3 was published in 2024 but CMMC Level 2 assessments still reference Rev 2 as of mid-2026. Learn more →
The NIST assessment methodology for NIST SP 800-171. Defines how each of the 110 practices is examined during an assessment - what documentation to request, what configurations to check, what personnel to interview. C3PAOs use 800-171A as their assessment guide. Learn more →
The term used in the CMMC program for a defense contractor pursuing CMMC Level 2 certification. The OSC is the organization being assessed by the C3PAO.
A document that identifies security gaps, describes remediation actions, assigns responsibility, and establishes timelines for closing each gap. POA&Ms are required for practices not yet fully implemented. They demonstrate to assessors that known gaps are being actively addressed. Learn more →
Microsoft Purview (formerly Azure Purview and Microsoft Information Protection) is a suite of data governance and compliance tools. Used in CMMC environments for sensitivity labeling of CUI (3.1.3), data classification, audit logging (3.3.1), and compliance management. Learn more →
An individual CMMC consultant with advanced Cyber AB credentials. RPAs can provide CMMC consulting and preparation services but cannot conduct official assessments. They typically work through an RPO. Learn more →
An organization authorized by the Cyber AB to provide CMMC consulting, gap assessments, and preparation services. RPOs cannot conduct official CMMC assessments - only C3PAOs can do that. An RPO is the right partner for preparing for an assessment; a C3PAO is who conducts it. Learn more →
A platform that aggregates, correlates, and analyzes security event data from multiple sources. Used in CMMC environments to satisfy audit and accountability practices (3.3.x) including log correlation (3.3.5) and anomaly detection (3.14.6). Microsoft Sentinel is Microsoft's SIEM product; alternatives include Splunk, IBM QRadar, and various MDR providers.
The DoD system where defense contractors submit their cybersecurity self-assessment scores. SPRS scores are calculated using the DoD Assessment Methodology: start at 110, subtract weighted points for each unimplemented or partially implemented NIST SP 800-171 practice. Contracting officers review SPRS scores before awarding contracts. Learn more →
The master document describing how a contractor implements all 110 NIST SP 800-171 practices across their information systems. The SSP describes system boundaries, the operating environment, how each control is implemented (or why it is not applicable), and system interconnections. The SSP is typically the first document a C3PAO assessor requests. Learn more →
The cryptographic protocol that secures network communications. TLS 1.2 and 1.3 are required for CMMC; older versions (TLS 1.0, 1.1, SSL) must be disabled. CMMC practice 3.13.8 requires encrypting CUI in transit, which is commonly satisfied by enforcing TLS on email, web applications, and API connections.
Knowing what a term means is step one. The CMMC Level 2 Certification Kit gives you the SSP, POA&M, and all 12 domain policies to document your implementation.
View the Certification Kit - $299All 110 NIST SP 800-171 practices organized by domain - formatted for assessment prep. Free PDF, instant access.