Full engagement
Full consultation
Discuss your complete cloud and security strategy with the principal consultant. For comprehensive transformations and multi-quarter engagements.
Glossary
A practical reference for key CMMC terms, DoD compliance language, and defense-contractor security concepts.
35 terms across 6 categories
Jump to a topic
Terms
Department of Defense framework that verifies implementation of cybersecurity controls and processes across the Defense Industrial Base.
Network of DoD contractors, subcontractors, and suppliers responsible for providing products and services to support military operations.
Sensitive government information that requires protection but is not classified. Handling CUI requires CMMC Level 2 or higher.
Information provided to contractors by or on behalf of the government that requires basic protection (CMMC Level 1).
Authorized organizations that conduct CMMC assessments and certifications for defense contractors.
Individual certified to conduct CMMC assessments at specific levels. Must be employed by a C3PAO.
Individual certified to assist organizations in preparing for CMMC assessments and implementing required practices.
Terms
Entry level requiring 17 basic cybersecurity practices to protect Federal Contract Information (FCI).
Intermediate level requiring 110 practices aligned with NIST SP 800-171 to protect Controlled Unclassified Information (CUI).
Advanced level requiring 110+ practices with additional requirements for advanced persistent threats (APTs).
Terms
Organization evaluates its own compliance with CMMC requirements. Required for Level 1 and some Level 2 contracts.
Independent evaluation by certified C3PAO. Required for most Level 2 and all Level 3 certifications.
Terms
NIST Special Publication providing guidelines for protecting CUI in non-federal systems. Foundation for CMMC Level 2.
Enhanced security requirements for protecting CUI, forms basis for additional CMMC Level 3 requirements.
DoD procurement regulations that include cybersecurity requirements for contractors handling CUI.
Terms
CMMC domain focused on limiting system access to authorized users, processes, and devices.
CMMC domain focused on identifying, documenting, and managing organizational assets including systems and data.
CMMC domain focused on creating, protecting, and retaining audit logs to enable monitoring and investigation.
CMMC domain focused on establishing and maintaining system configurations and controlling changes.
CMMC domain focused on verifying identities of users, processes, and devices accessing systems.
CMMC domain focused on establishing processes to detect, analyze, contain, and respond to security incidents.
CMMC domain focused on performing periodic and timely maintenance on systems and controlling maintenance activities.
CMMC domain focused on protecting digital and non-digital media containing CUI during transport and storage.
CMMC domain focused on ensuring individuals accessing systems are trustworthy and meet security requirements.
CMMC domain focused on limiting physical access to systems, equipment, and operating environments.
CMMC domain focused on restoring systems and data after disruptions while maintaining security controls.
CMMC domain focused on identifying, assessing, and responding to organizational risk from cybersecurity threats.
CMMC domain focused on developing plans to assess security controls and remediate deficiencies.
CMMC domain focused on identifying cybersecurity events and understanding their potential impact.
CMMC domain focused on monitoring, controlling, and protecting communications and system boundaries.
CMMC domain focused on identifying, reporting, and correcting system flaws and malicious code.
Terms
Document identifying specific actions to correct deficiencies and reduce security risks with timeline and resources.
Document describing security controls in place or planned for system and how controls meet security requirements.
DoD database where contractors submit self-assessments of NIST SP 800-171 compliance scores.
CMMC program costs that may be reimbursable under government contracts, including assessment and remediation expenses.
Work with CCP-certified advisors to translate CMMC requirements into a practical readiness roadmap for your environment.
Next step
Choose how you'd like to begin your engagement with Pilotcore.
Full engagement
Discuss your complete cloud and security strategy with the principal consultant. For comprehensive transformations and multi-quarter engagements.
Recommended start
Test the engagement with a focused 1-4 week scope. See real results, on a fixed timeline, before committing to anything larger.