CMMC Level 2 · Defense Industrial Base · Leesburg, VA+1 571 410-3066
Capital Cyber Compliance

CMMC terms

CMMC, in plain words.

The words your contract, your prime and your assessor will use, each explained in a sentence or two. No sales pitch in any of them.

Most of CMMC is a handful of acronyms used over and over. Once they are clear, the rest of the program reads like a checklist rather than a code.

The program

5 TERMS

DIB

Defense Industrial Base

The companies that design, make, repair or supply anything for the Department of Defense, from primes down to the machine shop three tiers below them. If a DoD contract or subcontract touches your work, you are in it.

CMMC

Cybersecurity Maturity Model Certification

The DoD program, written into regulation at 32 CFR Part 170, that checks whether a contractor actually protects the information it is given. It has three levels, and your contract says which one applies.

Level 1

CMMC Level 1, Foundational

For companies that handle Federal Contract Information but no CUI. It covers the 15 basic safeguarding requirements in FAR 52.204-21, self-assessed every year, with an annual affirmation.

Level 2

CMMC Level 2, Advanced

For companies that handle CUI. It covers the 110 requirements in NIST SP 800-171 Rev 2. Your contract decides whether you self-assess or need a certification assessment, every three years either way, with an affirmation every year.

Level 3

CMMC Level 3, Expert

For a small number of the most sensitive programs. Level 2 plus enhanced requirements from NIST SP 800-172, assessed by the government's own assessors, DIBCAC.

The information

2 TERMS

CUI

Controlled Unclassified Information

Information the government requires you to protect even though it is not classified. For most suppliers that means drawings, specifications and technical data marked CUI. Handling it is what puts you at Level 2.

FCI

Federal Contract Information

Information about a government contract that is not meant for the public, such as order details or delivery schedules. Handling FCI without CUI is Level 1.

The standard and the documents

5 TERMS

800-171

NIST SP 800-171

The 110 security requirements, grouped into 14 families, that Level 2 is built on. Access control, incident response, media protection and the rest.

800-171A

NIST SP 800-171A

The companion document that breaks the 110 requirements into 320 assessment objectives. It is what an assessor actually checks, one objective at a time.

SSP

System Security Plan

The document that says, requirement by requirement, how your business meets NIST SP 800-171, where CUI lives, and who is responsible. Without one in place, a score cannot be posted.

POA&M

Plan of Action and Milestones

The list of requirements you do not yet meet, what closing each one takes, and who owns it.

SPRS

Supplier Performance Risk System

The DoD system where you post your NIST SP 800-171 score and your CMMC status. Contracting officers check it before award. Scores run from 110 down to minus 203.

The people and the bodies

4 TERMS

AO

Affirming Official

The senior person at your company who confirms in SPRS that you meet the requirements, at each assessment and every year after. It is a signed statement to the government, which is why the score behind it has to be honest.

C3PAO

CMMC Third-Party Assessment Organization

A firm authorized by the Cyber AB to perform Level 2 certification assessments. Capital Cyber is not a C3PAO. On 13 July 2026 the requirement for a C3PAO certification as a condition of award was suspended, pending a review.

Cyber AB

The Cyber AB

The accreditation body for the CMMC ecosystem. It runs the marketplace where you can look up authorized assessors and registered consultants.

DIBCAC

Defense Industrial Base Cybersecurity Assessment Center

The DoD's own assessors. They perform Level 3 assessments and can assess Level 2 contractors.

The contract clauses

5 TERMS

7012

DFARS 252.204-7012

The contract clause that requires you to protect covered defense information using NIST SP 800-171, report cyber incidents within 72 hours, and pass the clause down to subcontractors who will handle that information. It applies today, whatever the status of CMMC.

7019

DFARS 252.204-7019

The clause that requires a current NIST SP 800-171 assessment score to be posted in SPRS before you can be considered for award.

7020

DFARS 252.204-7020

The clause that lets DoD assess your NIST SP 800-171 implementation and requires you to pass the same requirement to your subcontractors.

7021

DFARS 252.204-7021

The clause where the contracting officer writes in the CMMC level your contract requires.

52.204-21

FAR 52.204-21

The civilian clause behind Level 1: 15 basic safeguarding requirements for any contractor system that holds Federal Contract Information.

The environment

4 TERMS

FedRAMP

FedRAMP Moderate

The federal cloud authorization baseline. Under DFARS 7012, a cloud service that stores your covered defense information has to meet FedRAMP Moderate or its equivalent.

Enclave

CUI enclave

A defined part of your environment where CUI is handled, kept separate so the rest of the business stays out of scope. A smaller boundary is less to secure and less to evidence.

Scoping

Assessment scope

Deciding which people, systems and places are in your assessment and which are not. Most assessment problems start here.

Flow-down

Flow-down

The obligation to pass the same security clauses to any subcontractor who will handle the information. If you are a prime, you have to know which suppliers touch CUI. If you are a sub, expect your prime to ask.

Still not sure which of these apply to you?

BOOK A CALL

That is what a 30-minute call is for. Bring your contract and we will read the clauses with you.

What happens in 30 minutes

  1. We read your contract's CMMC and DFARS clauses with you.
  2. We confirm which level applies and how it will be assessed.
  3. We tell you the first step, whether or not it involves us. No slides.

Know the words. Now know where you stand.

A CMMC Level 2 gap assessment scores all 110 requirements against your environment and calculates your SPRS score.

See the gap assessment

Defense supplier under 25 people? Start with the grant.

Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the gap assessment itself, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.

Apply for a CGA grant