DIB
Defense Industrial Base
The companies that design, make, repair or supply anything for the Department of Defense, from primes down to the machine shop three tiers below them. If a DoD contract or subcontract touches your work, you are in it.
CMMC terms
The words your contract, your prime and your assessor will use, each explained in a sentence or two. No sales pitch in any of them.
Most of CMMC is a handful of acronyms used over and over. Once they are clear, the rest of the program reads like a checklist rather than a code.
DIB
Defense Industrial Base
The companies that design, make, repair or supply anything for the Department of Defense, from primes down to the machine shop three tiers below them. If a DoD contract or subcontract touches your work, you are in it.
CMMC
Cybersecurity Maturity Model Certification
The DoD program, written into regulation at 32 CFR Part 170, that checks whether a contractor actually protects the information it is given. It has three levels, and your contract says which one applies.
Level 1
CMMC Level 1, Foundational
For companies that handle Federal Contract Information but no CUI. It covers the 15 basic safeguarding requirements in FAR 52.204-21, self-assessed every year, with an annual affirmation.
Level 2
CMMC Level 2, Advanced
For companies that handle CUI. It covers the 110 requirements in NIST SP 800-171 Rev 2. Your contract decides whether you self-assess or need a certification assessment, every three years either way, with an affirmation every year.
Level 3
CMMC Level 3, Expert
For a small number of the most sensitive programs. Level 2 plus enhanced requirements from NIST SP 800-172, assessed by the government's own assessors, DIBCAC.
CUI
Controlled Unclassified Information
Information the government requires you to protect even though it is not classified. For most suppliers that means drawings, specifications and technical data marked CUI. Handling it is what puts you at Level 2.
FCI
Federal Contract Information
Information about a government contract that is not meant for the public, such as order details or delivery schedules. Handling FCI without CUI is Level 1.
800-171
NIST SP 800-171
The 110 security requirements, grouped into 14 families, that Level 2 is built on. Access control, incident response, media protection and the rest.
800-171A
NIST SP 800-171A
The companion document that breaks the 110 requirements into 320 assessment objectives. It is what an assessor actually checks, one objective at a time.
SSP
System Security Plan
The document that says, requirement by requirement, how your business meets NIST SP 800-171, where CUI lives, and who is responsible. Without one in place, a score cannot be posted.
POA&M
Plan of Action and Milestones
The list of requirements you do not yet meet, what closing each one takes, and who owns it.
SPRS
Supplier Performance Risk System
The DoD system where you post your NIST SP 800-171 score and your CMMC status. Contracting officers check it before award. Scores run from 110 down to minus 203.
AO
Affirming Official
The senior person at your company who confirms in SPRS that you meet the requirements, at each assessment and every year after. It is a signed statement to the government, which is why the score behind it has to be honest.
C3PAO
CMMC Third-Party Assessment Organization
A firm authorized by the Cyber AB to perform Level 2 certification assessments. Capital Cyber is not a C3PAO. On 13 July 2026 the requirement for a C3PAO certification as a condition of award was suspended, pending a review.
Cyber AB
The Cyber AB
The accreditation body for the CMMC ecosystem. It runs the marketplace where you can look up authorized assessors and registered consultants.
DIBCAC
Defense Industrial Base Cybersecurity Assessment Center
The DoD's own assessors. They perform Level 3 assessments and can assess Level 2 contractors.
7012
DFARS 252.204-7012
The contract clause that requires you to protect covered defense information using NIST SP 800-171, report cyber incidents within 72 hours, and pass the clause down to subcontractors who will handle that information. It applies today, whatever the status of CMMC.
7019
DFARS 252.204-7019
The clause that requires a current NIST SP 800-171 assessment score to be posted in SPRS before you can be considered for award.
7020
DFARS 252.204-7020
The clause that lets DoD assess your NIST SP 800-171 implementation and requires you to pass the same requirement to your subcontractors.
7021
DFARS 252.204-7021
The clause where the contracting officer writes in the CMMC level your contract requires.
52.204-21
FAR 52.204-21
The civilian clause behind Level 1: 15 basic safeguarding requirements for any contractor system that holds Federal Contract Information.
FedRAMP
FedRAMP Moderate
The federal cloud authorization baseline. Under DFARS 7012, a cloud service that stores your covered defense information has to meet FedRAMP Moderate or its equivalent.
Enclave
CUI enclave
A defined part of your environment where CUI is handled, kept separate so the rest of the business stays out of scope. A smaller boundary is less to secure and less to evidence.
Scoping
Assessment scope
Deciding which people, systems and places are in your assessment and which are not. Most assessment problems start here.
Flow-down
Flow-down
The obligation to pass the same security clauses to any subcontractor who will handle the information. If you are a prime, you have to know which suppliers touch CUI. If you are a sub, expect your prime to ask.
That is what a 30-minute call is for. Bring your contract and we will read the clauses with you.
What happens in 30 minutes
A CMMC Level 2 gap assessment scores all 110 requirements against your environment and calculates your SPRS score.
Cyber Grants Alliance, a nonprofit, awards in-kind cybersecurity grants. It provides the gap assessment itself, not cash. It costs you nothing, and you are under no obligation to buy anything afterward, from us or from anyone.