CMMC Index

Have questions about CMMC? Confused by the number of acronyms and terms? This index will provide guidance and resources to dive further into CMMC.

CMMC
 
The Cybersecurity Maturity Model Certification (CMMC) is a model created by the Department of Defense (DoD) to ensure contractors are protecting confidential data from the federal government. Any organization that partners with the DoD or works within the DIB has to comply with CMMC to maintain their current contracts or bid on new ones. 
 
CUI

 

Controlled Unclassified Information (CUI) is data that is entrusted to contractors in order to carry out DIB contracts. This data is created, transmitted, or stored by contractors and must be secured. This data's security contributed to the overall security posture of the nation.

 

Read More

FCI

 

Federal Contract Information (FCI) is information that is not intended for public release and contains details on contracts.

 

Read More

NIST 800-171

 

NIST 800-171 is the framework that CMMC is founded on. It consists of 110 controls with 320 assessment objectives that contractors must adhere to in order to be considered compliant. These requirements have been in place since 2017, but CMMC required third-party audits to ensure compliance.

 

Read More

SPRS Score

 

An organizations SPRS score is a score that represents how accurately they've implemented the controls within NIST 800-171. In order to pass, a contractor must score a perfect 110.

 

Read More

Defense Industrial Base (DIB)

 

The Defense Industrial Base (DIB) is a network of organization that provides products or services to the federal government.  These services contribute to the nation's defense and require a certain level of security.

 

Read More

GRC

 

GRC stands for Governance, Risk, and Compliance. Every contractor should have a GRC that documents the actions being taken to reduce risk, remain compliance, and govern who is responsible and how controls are implemented. 

SRM

 

A Shared Responsibility Matrix (SRM) is a document that outlines the compliance relationship between a contractor and their service provider. It details whose responsibility each control belongs to, and which ones are shared.

 

Read More

RMP

 

RMP or Risk Management Program is how you organization deals with risk that is present within your IT systems. What controls do you have in place to mitigate them? Who is in charge of doing so, etc.?

ITAR

 

ITAR stands for International Traffic in Arms Regulations and is a set of regulations regarding the export and import of defense-related articles, services, and technical data.

 

Read More 

Additional Resources

Updated NIST Password Guidelines 2024
By Waits Sharpe 3 October 2024

Your password is your first (and often only) line of defense between attackers and your data....

Read More
Key Changes in the Final CMMC 2.0 Rule
By Lawrence Cruciana 16 October 2024

Officially on October 15, 2024 the wait for CMMC 2.0 is over! With the release of the Final CMMC...

Read More