Built by Velocity Technologies for defense contractors, manufacturers, and subcontractors.
(602) 425-5630
Velocity CMMC Resource Center

CMMC glossary: plain-English definitions for the terms buyers and assessors use

Use this glossary to decode CMMC terms quickly, compare vendor claims against official language, and keep buyers, owners, program managers, and technical teams aligned.

CMMC terms in plain English

Use this glossary when owners, program managers, and technical teams need quick CMMC definitions without digging through multiple regulations. It uses the current official framework but keeps the explanations plain.

Glossary

Affirmation

The electronic confirmation by an affirming official that the company continues to meet the applicable requirements. It is required at the time of assessment and annually thereafter.

C3PAO

A Certified Third-Party Assessment Organization authorized or accredited to perform Level 2 certification assessments.

CMMC Assessment Scope

The set of all assets in the environment being assessed.

CMMC UID

The Cybersecurity Maturity Model Certification unique identifier associated with the relevant system or scope in contracting workflows.

Contractor Risk Managed Asset

An asset that is capable of processing, storing, or transmitting CUI but is not intended to do so because of policy, procedure, and practice.

CSP

Cloud service provider. In CMMC discussions, this matters when the offering stores, processes, or transmits CUI.

CUI

Controlled unclassified information. Unclassified information that requires safeguarding or dissemination controls pursuant to law, regulation, or Government-wide policy.

CUI Asset

An asset that processes, stores, or transmits CUI.

DIBCAC

Defense Industrial Base Cybersecurity Assessment Center. DCMA DIBCAC performs Level 3 assessments and may also investigate status issues.

ESP

External service provider. A provider whose services support the organization’s compliance and are assessed within the organization’s scope when used to meet requirements.

FCI

Federal contract information. Information provided by or generated for the Government under contract that is not intended for public release.

FedRAMP Moderate

The baseline cloud security level that official CMMC guidance points to when a cloud offering stores, processes, or transmits CUI.

Final Status

The completed CMMC status after the company achieves the required passing result without remaining allowable POA&M items.

POA&M

Plan of action and milestones. A limited and time-bounded path for certain remaining items under Level 2 or Level 3, when allowed by the rule.

Security Protection Asset

An asset that provides security functions or capabilities for the environment, such as logging, monitoring, identity, or perimeter controls.

SPRS

Supplier Performance Risk System. The official system used for certain cybersecurity assessment reporting and affirmations.

SSP

System Security Plan. The document that describes how the organization implements the required controls in the scoped environment.

VDI

Virtual desktop infrastructure. In CMMC scoping, certain VDI endpoint designs can be out of scope if they do not process, store, or transmit CUI beyond keyboard, video, and mouse.

Frequently asked questions

What is the difference between FCI and CUI?

FCI is contract information not intended for public release. CUI is a broader category of unclassified information requiring safeguarding or dissemination controls.

What is the difference between a CSP and an ESP?

A CSP question centers on a cloud offering storing, processing, or transmitting CUI. An ESP question centers on external services that support your compliance and are assessed within your scope when used to meet requirements.

What is the difference between conditional and final status?

Conditional status exists only where the rule allows it and must be closed out on time. Final status is the completed status after the required passing result is achieved without remaining allowable POA&M items.

What does OSA mean?

OSA means organization seeking assessment.

Official sources reviewed

Use this guide to plan readiness and communicate clearly with buyers, primes, and internal stakeholders. Contract language, current regulations, and assessor guidance control.

Want help turning this into a real readiness plan?

Velocity CMMC can scope the environment, map CUI flows, organize the documentation package, support remediation, and help your team prepare for the right assessment path without pretending to be the certifier.