CMMC Glossary
Key terms and acronyms for CMMC compliance professionals, assessors, and defense contractors.
An authorized organization accredited by the Cyber AB to conduct CMMC Level 2 and Level 3 assessments.
An individual certified to conduct CMMC assessments as part of a C3PAO assessment team.
A DoD framework requiring defense contractors to demonstrate cybersecurity practices at specific maturity levels to protect sensitive information.
Information that requires safeguarding or dissemination controls per government regulations but is not classified. CMMC Level 2 protects CUI.
The organization responsible for accrediting C3PAOs and certifying CMMC assessors. Formerly known as CMMC-AB.
The network of companies that provide products and services to the Department of Defense. All DIB organizations handling CUI need CMMC certification.
Information provided by or generated for the government under contract, not intended for public release. Protected at CMMC Level 1.
A U.S. government standard for cryptographic modules. CMMC requires FIPS-validated encryption for CUI protection.
A standard protocol that allows AI assistants (Claude, ChatGPT) to use specialized tools. Cubelet simulators run as MCP servers for in-the-flow-of-work training.
The NIST standard defining 110 security requirements for protecting CUI in non-federal systems. CMMC Level 2 is based on NIST 800-171.
A defense contractor or subcontractor undergoing a CMMC assessment to achieve certification.
A document identifying security weaknesses, planned remediation actions, and target completion dates. Limited POA&Ms are allowed under CMMC.
A document describing how an organization implements security controls for its information systems. Required evidence for CMMC assessments.
A DoD system where contractors submit self-assessment scores. CMMC Level 1 self-assessments are recorded in SPRS.
Put these terms into practice
The CMMC Simulator covers all 110 practices across 14 domains with AI-guided coaching.
Try CMMC Simulator