CMMC terms and abbreviations
| Term | Plain-language meaning |
|---|---|
| C3PAO | A CMMC Third-Party Assessment Organization authorized to conduct specified certification assessments. |
| CMMC | Cybersecurity Maturity Model Certification, the program used to assess cybersecurity requirements for defense contractors and subcontractors. |
| CUI | Controlled Unclassified Information that requires safeguarding or dissemination controls under applicable law, regulation, or policy. |
| DFARS | The Defense Federal Acquisition Regulation Supplement, which adds acquisition rules for defense contracts. |
| External service provider | A third party that provides a service relevant to the CMMC assessment scope. Its role and responsibilities must be understood and documented. |
| FCI | Federal Contract Information that is not intended for public release and is provided by or generated for the government under a contract. |
| NIST SP 800-171 | The NIST publication that defines requirements for protecting CUI in nonfederal systems and organizations. |
| POA&M | A Plan of Action and Milestones that records an allowed gap, the work required to close it, the owner, and the deadline. CMMC limits when POA&Ms may be used. |
| SPRS | The Supplier Performance Risk System, where specified assessment results and affirmations are recorded. |
| SSP | A System Security Plan that describes the system boundary, environment, roles, and how security requirements are implemented. |
For formal definitions, use 32 CFR part 170 and the applicable contract.
Published by Eagle Ridge Advisory. Public guidance only: this site holds no client information, completed security plans, evidence, or legal advice. Current CMMC rules and contract terms control.