Cubelet AI

CMMC Glossary

Key terms and acronyms for CMMC compliance professionals, assessors, and defense contractors.

C3PAO CMMC Third-Party Assessment Organization

An authorized organization accredited by the Cyber AB to conduct CMMC Level 2 and Level 3 assessments.

CCA Certified CMMC Assessor

An individual certified to conduct CMMC assessments as part of a C3PAO assessment team.

CMMC Cybersecurity Maturity Model Certification

A DoD framework requiring defense contractors to demonstrate cybersecurity practices at specific maturity levels to protect sensitive information.

CUI Controlled Unclassified Information

Information that requires safeguarding or dissemination controls per government regulations but is not classified. CMMC Level 2 protects CUI.

Cyber AB CMMC Accreditation Body

The organization responsible for accrediting C3PAOs and certifying CMMC assessors. Formerly known as CMMC-AB.

DIB Defense Industrial Base

The network of companies that provide products and services to the Department of Defense. All DIB organizations handling CUI need CMMC certification.

FCI Federal Contract Information

Information provided by or generated for the government under contract, not intended for public release. Protected at CMMC Level 1.

FIPS 140-2 Federal Information Processing Standard 140-2

A U.S. government standard for cryptographic modules. CMMC requires FIPS-validated encryption for CUI protection.

MCP Model Context Protocol

A standard protocol that allows AI assistants (Claude, ChatGPT) to use specialized tools. Cubelet simulators run as MCP servers for in-the-flow-of-work training.

NIST 800-171 NIST Special Publication 800-171

The NIST standard defining 110 security requirements for protecting CUI in non-federal systems. CMMC Level 2 is based on NIST 800-171.

OSC Organization Seeking Certification

A defense contractor or subcontractor undergoing a CMMC assessment to achieve certification.

POA&M Plan of Action and Milestones

A document identifying security weaknesses, planned remediation actions, and target completion dates. Limited POA&Ms are allowed under CMMC.

SSP System Security Plan

A document describing how an organization implements security controls for its information systems. Required evidence for CMMC assessments.

SPRS Supplier Performance Risk System

A DoD system where contractors submit self-assessment scores. CMMC Level 1 self-assessments are recorded in SPRS.

Put these terms into practice

The CMMC Simulator covers all 110 practices across 14 domains with AI-guided coaching.

Try CMMC Simulator