DKDavid Koran& Associates
Home The CMMC Guide Part V · Reference and Glossary
The CMMC Guide · Part V

Reference and Glossary

The ecosystem that runs the program, the organizations and credentials a contractor will encounter, and a working glossary of the terms that recur across CMMC and this guide.

1The Governing Bodies

The CMMC ecosystem has a clear hierarchy of authority, and four bodies sit above the assessors and advisers a contractor actually meets. Knowing which one does what makes the rest of the ecosystem legible.

The Department of Defense owns the program. It exercises that ownership through the CMMC Program Management Office within the office of the Chief Information Officer, which sets policy, writes the rules, and defines what an assessment must find. Everything below it operates under authority that traces back to that office.

The Cyber AB, formerly the CMMC Accreditation Body and rebranded under its current name in 2022, is the non-governmental accreditation body that supports the program under a direct contract with the CMMC Program Management Office. It authorizes and accredits the organizations that assess and advise, maintains the official Marketplace where a contractor can verify that a provider has been vetted, and runs the Registered Practitioner programs. It operates to the international accreditation standard ISO/IEC 17011, and it is not itself part of the Department of Defense.

ISACA holds the role of the CMMC Assessor and Instructor Certification Organization, the CAICO, having fully assumed it in April 2026. It administers the training, examinations, and certifications for the individual professionals in the ecosystem, while the Cyber AB continues to run the background investigations behind those credentials. The division is worth holding onto, because it explains who issues what: the Cyber AB accredits organizations, and ISACA certifies individuals.

The Defense Industrial Base Cybersecurity Assessment Center, DIBCAC, is the government's own assessment arm, part of the Defense Contract Management Agency. It conducts the Level 3 assessments, and it assesses the C3PAOs themselves, so that the organizations authorized to certify others have first been certified by the government against the same standard they will apply.

2The Ecosystem Roles

Below the governing bodies are the organizations and individuals a contractor works with directly, and they divide along a single line that runs through the whole program: preparing for an assessment, or conducting one. The organizations come first.

OrganizationWhat it doesSide of the line
C3PAO, CMMC Third-Party Assessment OrganizationConducts Level 2 certification assessments; authorized by the Cyber AB after passing its own DIBCAC assessmentAssess
RPO, Registered Practitioner OrganizationProvides readiness and advisory services through employed Registered Practitioners, and does not conduct assessmentsAdvise
ATP, Approved Training ProviderDelivers CMMC training under the CAICONeither
APP, Approved Publishing PartnerPublishes approved CMMC training materialsNeither

The individuals hold credentials that sit on one side of the same line or the other. The advising credentials come from the Cyber AB, and the assessing credentials come from ISACA as the CAICO.

CredentialWhat it authorizesIssued by
RP, Registered PractitionerA trained adviser providing readiness and implementation guidanceCyber AB
RPA, Registered Practitioner AdvancedThe advanced Registered Practitioner designation, for deeper readiness and implementation workCyber AB
CCP, Certified CMMC ProfessionalThe foundational certification; an assessment team member and adviser, and the prerequisite to becoming an assessorISACA (CAICO)
CCA, Certified CMMC AssessorConducts Level 2 assessment work as part of a C3PAO teamISACA (CAICO)
LCCA, Lead Certified CMMC AssessorLeads a Level 2 assessment team and delivers the final determinationsISACA (CAICO)
CCI, Certified CMMC InstructorDelivers CMMC trainingISACA (CAICO)

The assessing credentials carry their own baseline. A Certified CMMC Assessor works within a C3PAO for official assessments, must hold a professional security certification at the level the government expects of a security control assessor, and, like a Certified CMMC Professional, must clear a Tier 3 background investigation that establishes eligibility rather than a security clearance.

The independence wall

The line between advising and assessing is not merely descriptive, it is a rule with teeth. A single company may hold more than one role, but it cannot both prepare a client and assess that same client for the same effort. A provider that helped an organization get ready, and the assessors that provider employs, cannot take part in that organization's certification assessment, with the separation measured in years rather than months. The logic is the same one that keeps an auditor from auditing their own work, because an assessment is worth only as much as its independence. This is why a readiness practice and an assessment organization are structurally different businesses, and why a contractor engages one party to prepare and a separate party to certify.

3The Glossary

A working glossary of the terms that recur across the program and this guide. The roles above are not repeated here; what follows is the vocabulary of the data, the documents, the scores, the assessment, and the rules.

Information and data

TermMeaning
FCI, Federal Contract InformationInformation provided by or generated for the government under a contract and not intended for public release, excluding public and simple transactional information. Handling it triggers Level 1.
CUI, Controlled Unclassified InformationInformation that a law, regulation, or governmentwide policy requires to be safeguarded, the sensitive category that triggers Level 2. Organized by the National Archives program and catalogued in the CUI Registry.
CUI Basic and CUI SpecifiedBasic follows the uniform baseline handling; Specified carries additional handling rules from the authority that created it. Both are CUI for CMMC.
CTI, Controlled Technical InformationTechnical data with a military or space application that is subject to controls, a common form of CUI on a manufacturing floor, safeguarded under DFARS 252.204-7012.
DIB, Defense Industrial BaseThe network of contractors and subcontractors that support the Department of Defense.

Documents and records

TermMeaning
SSP, System Security PlanThe document describing the assessment scope and how each applicable requirement is met, by whom, and with what. Required and not deferrable.
POA&M, Plan of Action and MilestonesThe companion document recording requirements not yet met and the plan to close them, limited by rule in what it may carry.
CRM, Customer Responsibility MatrixThe document dividing security responsibilities between a contractor and an external or cloud service provider.
AffirmationThe annual attestation of continuous compliance entered in SPRS, signed by a designated Affirming Official.

Scores, statuses, and systems

TermMeaning
SPRS, Supplier Performance Risk SystemThe DoD system where assessment scores and affirmations are posted and where a contracting officer verifies status before award.
eMASS, Enterprise Mission Assurance Support ServiceThe DoD system, in its CMMC instantiation, where certification assessment results are recorded.
CMMC StatusThe result of an assessment: Conditional, a passing score with permitted open items and a 180-day clock, or Final, a clean result valid three years with annual affirmation.
Conditional CMMC Status DateThe date results are posted, which starts the 180-day closeout clock.
CMMC UIDThe unique identifier assigned to each assessment in SPRS, tied to a specific contractor information system.
CAGE CodeThe Commercial and Government Entity code identifying a contractor facility, to which an assessment is tied.

Assessment terms

TermMeaning
Assessment ScopeThe set of assets that are within an assessment and the category into which each falls.
Asset categoriesCUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets, described in Core Concepts.
Assessment ObjectiveA determination statement from NIST SP 800-171A; a requirement is MET only when all of its objectives are met.
MET, NOT MET, Not ApplicableThe three possible findings for a requirement in an assessment.
Adequacy and SufficiencyThe two standards for evidence: the right kind of evidence, and enough of it across the full scope.
EnclaveA small, deliberately separated environment built to hold CUI and nothing else, used to shrink the assessment scope.
OSA and OSCOrganization Seeking Assessment, for any assessment, and Organization Seeking Certification, for a C3PAO certification specifically.
CAP, CMMC Assessment ProcessThe Cyber AB's procedural playbook for Level 2 certification assessments, described in The Assessment.
CoPC, Code of Professional ConductThe ethics and conflict-of-interest rules binding the ecosystem's organizations and professionals.
FedRAMP ModerateThe federal cloud authorization baseline a cloud service handling CUI must meet, or match through a documented equivalency.

Regulations and standards

CitationMeaning
32 CFR Part 170The CMMC Program rule, covering the levels, assessments, scoring, plan of action rules, and phase-in.
48 CFR, with DFARS 252.204-7021 and 252.204-7025The acquisition rule and clauses that place CMMC into contracts, described in Foundations.
DFARS 252.204-7012The longstanding safeguarding and cyber incident reporting clause requiring NIST SP 800-171.
FAR 52.204-21, renumbered FAR 52.240-93The basic safeguarding requirements for FCI, and the source of Level 1.
NIST SP 800-171 Rev 2The 110 requirements underlying Level 2, to which CMMC is pinned.
NIST SP 800-171AThe assessment objectives and the examine, interview, and test methods.
NIST SP 800-172The enhanced requirements, a subset of which is added at Level 3.

From the vocabulary to the work

Knowing the terms is the start; applying them to a specific environment, with its own scope, evidence, and gaps, is onsite readiness work. That is the practice behind this guide.

Start CMMC Readiness or call 802-335-2662

4Sources

  1. The Cyber AB, ecosystem roles and the official CMMC Marketplace. cyberab.org
  2. ISACA, in its role as the CMMC Assessor and Instructor Certification Organization (CAICO), for the individual credentials. isaca.org
  3. 32 CFR Part 170, CMMC Program, including the definitions at 32 CFR 170.4. ecfr.gov
  4. NIST SP 800-171 Rev 2 and NIST SP 800-171A, the requirements and the assessment objectives. csrc.nist.gov
← Part IV
The Assessment
The CMMC Guide →
Return to the guide index
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Part V: Reference and Glossary · Edition 2026.1 · Last reviewed July 12, 2026