CMMC terms in plain English
Use this glossary when owners, program managers, and technical teams need quick CMMC definitions without digging through multiple regulations. It uses the current official framework but keeps the explanations plain.
Glossary
Affirmation
The electronic confirmation by an affirming official that the company continues to meet the applicable requirements. It is required at the time of assessment and annually thereafter.
C3PAO
A Certified Third-Party Assessment Organization authorized or accredited to perform Level 2 certification assessments.
CMMC Assessment Scope
The set of all assets in the environment being assessed.
CMMC UID
The Cybersecurity Maturity Model Certification unique identifier associated with the relevant system or scope in contracting workflows.
Contractor Risk Managed Asset
An asset that is capable of processing, storing, or transmitting CUI but is not intended to do so because of policy, procedure, and practice.
CSP
Cloud service provider. In CMMC discussions, this matters when the offering stores, processes, or transmits CUI.
CUI
Controlled unclassified information. Unclassified information that requires safeguarding or dissemination controls pursuant to law, regulation, or Government-wide policy.
CUI Asset
An asset that processes, stores, or transmits CUI.
DIBCAC
Defense Industrial Base Cybersecurity Assessment Center. DCMA DIBCAC performs Level 3 assessments and may also investigate status issues.
ESP
External service provider. A provider whose services support the organization’s compliance and are assessed within the organization’s scope when used to meet requirements.
FCI
Federal contract information. Information provided by or generated for the Government under contract that is not intended for public release.
FedRAMP Moderate
The baseline cloud security level that official CMMC guidance points to when a cloud offering stores, processes, or transmits CUI.
Final Status
The completed CMMC status after the company achieves the required passing result without remaining allowable POA&M items.
POA&M
Plan of action and milestones. A limited and time-bounded path for certain remaining items under Level 2 or Level 3, when allowed by the rule.
Security Protection Asset
An asset that provides security functions or capabilities for the environment, such as logging, monitoring, identity, or perimeter controls.
SPRS
Supplier Performance Risk System. The official system used for certain cybersecurity assessment reporting and affirmations.
SSP
System Security Plan. The document that describes how the organization implements the required controls in the scoped environment.
VDI
Virtual desktop infrastructure. In CMMC scoping, certain VDI endpoint designs can be out of scope if they do not process, store, or transmit CUI beyond keyboard, video, and mouse.
Frequently asked questions
What is the difference between FCI and CUI?
FCI is contract information not intended for public release. CUI is a broader category of unclassified information requiring safeguarding or dissemination controls.
What is the difference between a CSP and an ESP?
A CSP question centers on a cloud offering storing, processing, or transmitting CUI. An ESP question centers on external services that support your compliance and are assessed within your scope when used to meet requirements.
What is the difference between conditional and final status?
Conditional status exists only where the rule allows it and must be closed out on time. Final status is the completed status after the required passing result is achieved without remaining allowable POA&M items.
What does OSA mean?
OSA means organization seeking assessment.
Related articles
Official sources reviewed
Use this guide to plan readiness and communicate clearly with buyers, primes, and internal stakeholders. Contract language, current regulations, and assessor guidance control.
Want help turning this into a real readiness plan?
Velocity CMMC can scope the environment, map CUI flows, organize the documentation package, support remediation, and help your team prepare for the right assessment path without pretending to be the certifier.