---
title: "CMMC and NIST 800-171 Glossary"
description: "Plain definitions of the terms that run CMMC and NIST 800-171 work: CUI, FCI, SPRS, C3PAO, POA&M, SSP, DIBCAC, DFARS 7012, and the CUI enclave."
url: https://policycortex.com/cmmc/glossary
sealed: 2026-07-02
amended: 2026-09-03
register: cmmc/glossary
records: 3
digest: sha3:eaa3ad4e96b32e18eda1e5206a4615ad088b444ee548ca8b6af3d58c29613670
---

# Glossary: CMMC and NIST 800-171 terms, defined

Register / Glossary

The glossary defines the terms that run CMMC and NIST 800-171 work: CUI, FCI, SPRS, C3PAO, POA&M, SSP, DIBCAC, DFARS 7012, the CUI enclave, and the standard itself. Each entry is one plain definition, then the context an assessor expects you to know, and cross-references to the related terms.

10 entries · Sealed 2026-07-02 · Last amended 2026-09-03

## Terms

| Term |
|---|
| [CUI](https://policycortex.com/cmmc/glossary/cui) (Controlled Unclassified Information): CUI is government-created or -owned information that requires safeguarding under law, regulation, or government-wide policy, but is not classified. |
| [FCI](https://policycortex.com/cmmc/glossary/fci) (Federal Contract Information): FCI is information provided by or generated for the government under a contract that is not intended for public release: the trigger for CMMC Level 1. |
| [SPRS](https://policycortex.com/cmmc/glossary/sprs) (Supplier Performance Risk System): SPRS is the DoD system where contractors post their NIST 800-171 self-assessment score and, under CMMC, their certification status and affirmations. |
| [C3PAO](https://policycortex.com/cmmc/glossary/c3pao) (CMMC Third-Party Assessment Organization): A C3PAO is an organization authorized by the Cyber AB to conduct official CMMC Level 2 certification assessments. |
| [NIST SP 800-171](https://policycortex.com/cmmc/glossary/nist-800-171): NIST SP 800-171 is the federal standard of 110 security controls for protecting CUI in non-federal systems: the technical basis of CMMC Level 2. |
| [SSP](https://policycortex.com/cmmc/glossary/ssp) (System Security Plan): An SSP is the document describing how an organization implements each required security control across its in-scope environment. |
| [POA&M](https://policycortex.com/cmmc/glossary/poam) (Plan of Action and Milestones): A POA&M is a tracked plan for remediating security controls that are not yet fully implemented, with owners and target dates. |
| [DIBCAC](https://policycortex.com/cmmc/glossary/dibcac) (Defense Industrial Base Cybersecurity Assessment Center): DIBCAC is the DoD organization that conducts government-led high assessments and CMMC Level 3 assessments. |
| [DFARS 252.204-7012](https://policycortex.com/cmmc/glossary/dfars-7012): DFARS 7012 is the long-standing clause requiring contractors to safeguard covered defense information per NIST 800-171 and report cyber incidents within 72 hours. |
| [CUI Enclave](https://policycortex.com/cmmc/glossary/enclave): A CUI enclave is a segmented, hardened environment that isolates CUI so only that boundary, not the whole company, falls in CMMC scope. |

## Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

- **proof.state**: [Proof of State](https://policycortex.com/proof/state). What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- **proof.change**: [Proof of Change](https://policycortex.com/proof/change). Who or what altered the environment, under what authority, with before and after state hashes.
- **proof.agency**: [Proof of Agency](https://policycortex.com/proof/agency). What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- **architecture**: [Architecture](https://policycortex.com/architecture). How the chain is built and where it lives: inside your tenant, with no egress of evidence.

Know the terms. Then see the records behind them. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | HEAD | 343b9e774a08 | 04d8895b52d9 |
| REC 0001 | TERMS | 21e1837a080d | 343b9e774a08 |
| REC 0002 | RELATED RECORDS | eaa3ad4e96b3 | 21e1837a080d |

Head sha3:eaa3ad4e96b32e18eda1e5206a4615ad088b444ee548ca8b6af3d58c29613670. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
