CMMC Level 1 · GlossarySEC / DEF16
CMMC Level 1 · Reference
CMMC Level 1 Glossary
The terms you meet in a Level 1 self-assessment, defined in plain English and tied to their source.
Terms
- FCIFederal Contract Information
- CUIControlled Unclassified Information
- TermSelf-Assessment
- TermAffirmation
- TermAffirming Official
- SPRSSupplier Performance Risk System
- C3PAOCertified Third-Party Assessment Organization
- TermDetermination
- TermAssessment Objective
- TermSecurity Requirement
- POA&MPlan of Action and Milestones
- SSPSystem Security Plan
- TermCMMC Scope
- TermSpecialized Assets
- MFAMulti-Factor Authentication
- COTSCommercial Off-the-Shelf
How This Reference Is Maintained
Every requirement and objective here is taken directly from the primary sources: FAR 52.204-21, NIST SP 800-171A, and 32 CFR Part 170. Identifiers, official text, and assessment procedures are reproduced from those authorities and pinned to a specific published version, then checked against the DoD CMMC Assessment Guide for Level 1. Each page shows the framework version, its effective date, and when the content was last verified. When a source changes, the affected pages are re-verified before they are updated.
