CMMC Index
Have questions about CMMC? Confused by the number of acronyms and terms?
This index will provide guidance and resources to dive further into CMMC.
A Plan Of Action & Milestone (POAM)
A Plan of Action & Milestone (POAM) is a document outlining what CMMC controls haven't been implemented, and how the organization will go about remediating that.
C3PAO
A C3PAO is a "Certified 3rd Party Assessment Organization" and is authorized to audit DoD contractors for CMMC compliance. For many contracts, a C3PAO audit will be required.
CMMC Level 2 Certified (C3PAO)
A level 2 certified (C3PAO) organization has undergone a third-party audit to achieve CMMC certification. This audit must be conducted by a C3PAO.
Controlled Unclassified Information (CUI)
Controlled Unclassified Information (CUI) is data that is entrusted to contractors in order to carry out DIB contracts. This data is created, transmitted, or stored by contractors and must be secured. This data's security contributed to the overall security posture of the nation.
CyberAB
The CyberAB is the organization that certifies C3PAO's, RPO's and provides resources for organizations seeking CMMC compliance.
Cybersecurity Maturity Model Certification (CMMC)
Data Flow Diagram (DFD)
Maps out how CUI moves through your organization. It should answer where CUI comes from, where it is stored, how is it processed and by which applications, where does it leave the organization, and who has access to it?
Defense Federal Acquisition Regulation (DFARS)
DFARS stands for "Defense Federal Acquisition Regulation Supplement" and refers to cybersecurity standards that are applicable to defense contractors and suppliers to the federal government.
Defense Industrial Base (DIB)
The Defense Industrial Base (DIB) is a network of organization that provides products or services to the federal government. These services contribute to the nation's defense and require a certain level of security.
Department of War (DoW, formerly DoD)
Formerly the Department of Defense. “The name “Department of War,” more than the current “Department of Defense,” ensures peace through strength, as it demonstrates our ability and willingness to fight and win wars on behalf of our Nation at a moment’s notice, not just to defend. This name sharpens the Department’s focus on our own national interest and our adversaries’ focus on our willingness and availability to wage war to secure what is ours. I have therefore determined that this Department should once again be known as the Department of War and the Secretary should be known as the Secretary of War.” -President Donald Trump
External Service Provider (ESP)
Managed Service Providers (MSPs) and External Service Providers (ESPs) are organization that provide IT or cybersecurity solutions to businesses. CMMC refers to MSPs as "ESPs" in their documentation.
Federal Acquisition Regulation (FAR)
The far is a set of rules outlining the procedures executive agencies must follow when acquiring products or services.
Federal Contract Information (FCI)
Federal Contract Information (FCI) is information that is not intended for public release and contains details on contracts.
Governance, Risk and Compliance (GRC)
GRC stands for Governance, Risk, and Compliance. Every contractor should have a GRC that documents the actions being taken to reduce risk, remain compliance, and govern who is responsible and how controls are implemented.
International Traffic in Arms Regulations (ITAR)
ITAR stands for International Traffic in Arms Regulations and is a set of regulations regarding the export and import of defense-related articles, services, and technical data.
MSP Collective
The MSP Collective is an organization that provides resources for contractors seeking help with CMMC compliance. Their ESP database provides a list of CMMC certified MSPs.
NIST 800-171
NIST 800-171 is the framework that CMMC is founded on. It consists of 110 controls with 320 assessment objectives that contractors must adhere to in order to be considered compliant. These requirements have been in place since 2017, but CMMC required third-party audits to ensure compliance.
Organization Seeking Certification (OSC)
An OSC is an "Organization Seeking Certification". This is any organization that must comply with CMMC requirements and is pursuing a third-party audit via a C3PAO.
Registered Practitioner Organization (RPO)
RPO stands for Registered Practitioner Organization and is a company that is certified by the Cyber AB to offer their security and compliance services to DoD contractors.
Risk Management Program (RMP)
RMP or Risk Management Program is how you organization deals with risk that is present within your IT systems. What controls do you have in place to mitigate them? Who is in charge of doing so, etc.?
Shared Responsibility Matrix (SRM)
A Customer Responsibility Matrix (CRM), formally known as Shared Responsibility Matrix (SRM) is a document that outlines the compliance relationship between a contractor and their service provider. It details whose responsibility each control belongs to, and which ones are shared.
SPRS Score
An organizations SPRS score is a score that represents how accurately they've implemented the controls within NIST 800-171. In order to pass, a contractor must score a perfect 110.
System Security Plan (SSP)
Your SSP is a living document that details how your organization is currently satisfying each of the NIST 800-171 assessment objectives.
TAS for CMMC Compliance
Technology Assurance Services (TAS) for CMMC Compliance is CorpInfoTech's managed CMMC compliance product that helps contractors achieve and maintain regulatory requirements.
CMMC Related Blogs
Why Organizations Fail Their CMMC Audit - Scoping Is the Answer
As CMMC is finalized, many organizations will find themselves scrambling to schedule their...
What is a System Security Plan (SSP)?
A System Security Plan (SSP) is an active document outlining how each objective of NIST 800-171 is...
48 CFR CMMC Final Rule
The Department of War (DoW, formerly known as the DoD), officially published 48 CFR CMMC Final Rule...