The CMMC Glossary
Plain-English definitions for every acronym, regulation, and concept in the CMMC ecosystem — written for defense contractors, not lawyers. Bookmark this page; we update it as the rules change.
Frameworks & Rules
CMMC Ecosystem
Documents & Artifacts
Control Families
- Control Families
- Access Control (AC) Family
- Awareness and Training (AT) Family
- Audit and Accountability (AU) Family
- Configuration Management (CM) Family
- Identification and Authentication (IA) Family
- Incident Response (IR) Family
- Maintenance (MA) Family
- Media Protection (MP) Family
- Physical Protection (PE) Family
- Personnel Security (PS) Family
- Risk Assessment (RA) Family
- Security Assessment (CA) Family
- System and Communications Protection (SC) Family
- System and Information Integrity (SI) Family
- Supply Chain Risk Management (SR) Family
Specific Requirements
Key Concepts
- 180-Day Rule
- Conditional Certification
- Final Certification
- Three-Year Recertification
- Annual Affirmation
- FIPS / FIPS 140-2 / FIPS 140-3
- CMVP
- False Claims Act
- Assessment Objective
- Evidence
- Flow-Down Clause
- Self-Assessment
- Prioritized Acquisition
- Least Privilege
- Least Functionality
- Separation of Duties
- Continuous Monitoring
- Tabletop Exercise
- Policy vs Procedure
- CUI Spillage
- Annual Self-Assessment
- Interim Safeguards
- Closure Evidence
- Control Inheritance
- False Affirmation
- SPRS Score
- Compliance vs Certification
- Compensating Control
- Residual Risk
- Risk Acceptance
- Contingency Plan
- Security Incident
- Breach Notification
Technical Terms
- SIEM
- EDR
- MDR
- MFA
- Hardening
- CIS Benchmarks
- DISA STIGs
- Vulnerability Scan
- Penetration Test
- Remote Access
- VPN
- Antivirus / Anti-malware
- Firewall
- Session Lock
- Media Sanitization
- Visitor Log
- Patch Management
- Data Backup
- Access Control List
- Advanced Encryption Standard
- Demilitarized Zone
- Domain Name System
- Encryption
- Intrusion Detection / Prevention System
- Network Access Control
- Phishing
- Ransomware
- Zero Trust Architecture
- Bring Your Own Device
- Data at Rest
- Data in Transit
- Insider Threat
- Social Engineering
- Service Account
- Privileged Access
- Change Management
- Configuration Baseline
- Audit Trail
- Clean Desk Policy
- Public Key Infrastructure
Regulations & Clauses
Data Categories
Scoping & Boundary
Tired of looking things up?
CMMCDocs is a working platform that gets you assessment-ready in 60 days. Spin up a free demo workspace pre-loaded with sample data — no signup, no sales call.
Get my demo account
CMMCDocs.com