Skip to content

CMMC terms and abbreviations

Term Plain-language meaning
C3PAO A CMMC Third-Party Assessment Organization authorized to conduct specified certification assessments.
CMMC Cybersecurity Maturity Model Certification, the program used to assess cybersecurity requirements for defense contractors and subcontractors.
CUI Controlled Unclassified Information that requires safeguarding or dissemination controls under applicable law, regulation, or policy.
DFARS The Defense Federal Acquisition Regulation Supplement, which adds acquisition rules for defense contracts.
External service provider A third party that provides a service relevant to the CMMC assessment scope. Its role and responsibilities must be understood and documented.
FCI Federal Contract Information that is not intended for public release and is provided by or generated for the government under a contract.
NIST SP 800-171 The NIST publication that defines requirements for protecting CUI in nonfederal systems and organizations.
POA&M A Plan of Action and Milestones that records an allowed gap, the work required to close it, the owner, and the deadline. CMMC limits when POA&Ms may be used.
SPRS The Supplier Performance Risk System, where specified assessment results and affirmations are recorded.
SSP A System Security Plan that describes the system boundary, environment, roles, and how security requirements are implemented.

For formal definitions, use 32 CFR part 170 and the applicable contract.

Published by Eagle Ridge Advisory. Public guidance only: this site holds no client information, completed security plans, evidence, or legal advice. Current CMMC rules and contract terms control.