CMMC vocabulary is easier when terms are grouped by function: information types, documents, assessment actors, system and status identifiers, and external providers. When the CMMC rule defines a term, use the program definition rather than an informal industry shortcut.
For a small defense contractor, the useful test is whether the organization can show how the requirement applies inside the defined FCI/CUI boundary, who operates it, and what current evidence proves it is working.
The rule in plain English
Core document and status terms include SSP (System Security Plan), POA&M (Plan of Action and Milestones), SPRS (Supplier Performance Risk System), CMMC UID, Conditional CMMC Status, and Final CMMC Status.
Core actor terms include OSA/OSC for organizations seeking assessment or certification status, C3PAO for an authorized third-party assessment organization, DIBCAC for government assessment functions, and RP/RPO for consultative ecosystem roles.
Core CMMC acronyms and what they mean
Use these as working definitions, then follow the cited primary source when a contract or assessment decision turns on the exact wording.
- CMMC — Cybersecurity Maturity Model Certification, the DoD program for verifying protection of FCI and CUI in contractor information systems.
- FCI — Federal Contract Information, nonpublic information provided by or generated for the Government under a contract, subject to FAR basic safeguarding.
- CUI — Controlled Unclassified Information, information requiring safeguarding or dissemination controls under law, regulation, or government-wide policy.
- CDI — Covered Defense Information, the DFARS 252.204-7012 term used in covered defense-information and covered-contractor-system obligations.
- SSP — System Security Plan, the document describing the system boundary, environment, and how applicable security requirements are implemented.
- POA&M — Plan of Action and Milestones, a managed record of deficiencies and planned corrective actions; CMMC restricts what may be deferred for conditional status.
- SPRS — Supplier Performance Risk System, the DoD system used for relevant supplier cybersecurity assessment and CMMC status information.
- C3PAO — CMMC Third-Party Assessment Organization authorized to conduct CMMC certification assessments.
- DIBCAC — Defense Industrial Base Cybersecurity Assessment Center, the DoD organization that performs specified government-led cybersecurity assessments.
- OSA / OSC — Organization Seeking Assessment / Organization Seeking Certification, program terms for entities entering the applicable CMMC assessment path.
- RP / RPO — Registered Practitioner / Registered Practitioner Organization, consultative ecosystem roles; they are not C3PAOs merely by holding those designations.
- ESP — External Service Provider, an outside provider whose services can affect the assessed environment depending on what it processes, stores, transmits, or protects.
- CMMC UID — the unique identifier used to distinguish a CMMC-scoped information system in the program.
How to implement it without overbuilding
Maintain a site-wide glossary linked from technical articles so individual guides can stay focused. Add the source and program-specific meaning when a familiar acronym has a different generic use elsewhere.
For internal contractor use, add company-specific mappings such as who acts as system owner, affirming official, incident lead, or evidence owner.
What evidence to keep
Keep definitions tied to 32 CFR, DFARS, NIST, NARA, and Cyber AB sources where applicable.
Version definitions that changed across CMMC iterations so old slide decks and policies do not silently drive current work.
Where teams get into trouble
The common problem is using 'certified,' 'assessed,' 'compliant,' and 'self-assessed' interchangeably. Another is labeling every external IT company an ESP without documenting its actual role.
Small-contractor walkthrough
A new compliance lead encounters SSP, POA&M, SPRS, C3PAO, DIBCAC, OSA, OSC, ESP, RP, CUI, FCI, and CDI in one meeting. The glossary should distinguish documents, status terms, actors, providers, and information types instead of offering one-line definitions without context.
For readiness, choose a normal business example rather than a perfect demonstration environment.
Reference content should answer the definition or comparison quickly, then show the contracting consequence. Readers usually need to know not only what a term means but what decision changes because of it.
Keep definitions anchored to the CMMC rule, acquisition clauses, NIST, or the CUI Registry. Date-stamp program-status details that can change independently of the underlying definition.
- Use program definitions.
- Group acronyms by function.
- Link each term to a source.
- Separate formal status words.
Group acronyms by function
Information terms explain what is protected: FCI is Federal Contract Information; CUI is Controlled Unclassified Information; CDI is Covered Defense Information under DFARS 252.204-7012; CTI is Controlled Technical Information. Scope/system terms explain where protections apply: SSP is System Security Plan; ESP is External Service Provider; SPA is Security Protection Asset; SPD is Security Protection Data; CMMC UID identifies an assessment/status record for a contractor information system.
Assessment actors explain who does what: OSA is Organization Seeking Assessment; OSC is Organization Seeking Certification; C3PAO is Certified Third-Party Assessment Organization; DIBCAC is the Defense Industrial Base Cybersecurity Assessment Center. RP/RPO are advisory ecosystem labels and should not be described as certification assessors.
Status acronyms need dates and context
SPRS is the Supplier Performance Risk System. POA&M is Plan of Action and Milestones. A CMMC status may be Conditional or Final depending on the assessment path and permissible POA&M. When using acronyms in a contract file, record the level, assessment type, CMMC UID, status date, affirmation date, and closeout deadline where relevant.
Do not mix a NIST SP 800-171 DoD Assessment score with a CMMC certificate or status. Both can appear in related acquisition workflows, but they come from different assessment mechanisms. Use the exact label shown by the authoritative record.
Add 'do not confuse with' notes to the glossary
CUI is not classified information. CDI is not generic company-confidential data. A C3PAO is not a generic consultant. A POA&M is not permission to defer any requirement. FedRAMP is not CMMC. Rev. 3 being newer at NIST does not automatically mean it replaced the current DFARS contractual baseline.
Version the glossary and keep source links. When a prime questionnaire introduces an unfamiliar acronym, map it to an official or contract source before adding it to the reference page.
Before assessment week
- ✓Use program definitions.
- ✓Group acronyms by function.
- ✓Link each term to a source.
- ✓Separate formal status words.
- ✓Retire obsolete terminology.
- ✓Add company-specific role mappings.
Common questions
What is an SSP?
A System Security Plan describes system boundaries, environment, how security requirements are implemented, and connections or relationships with other systems as required by NIST SP 800-171.
What is a POA&M?
A Plan of Action and Milestones records planned actions to correct deficiencies; CMMC limits what may be deferred for conditional status.
What is SPRS?
The Supplier Performance Risk System is used by DoD for relevant supplier performance and cybersecurity assessment or status information.
What is a C3PAO?
A CMMC Third-Party Assessment Organization authorized to conduct CMMC certification assessments using qualified assessment personnel.
Is an SPRS score the same as a CMMC certificate?
No. Use the exact assessment/status label from the authoritative record; NIST DoD assessment scores and CMMC status are distinct.
Official sources used for this guide
Open the primary source before making a contract-specific decision. Regulations and program implementation can change.


