to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

Terms people mix up

Three terms decide what you owe, four pairs get swapped in nearly every first conversation, and the rest is the working vocabulary of an assessment.

FCI, CUI, CDI

FCI
Federal contract information. Information provided by or generated for the government under a contract, not intended for public release, and not CUI. Covered by FAR 52.204-21 and CMMC Level 1.
CUI
Controlled unclassified information. Government-designated and, in theory, marked. Covered by DFARS 252.204-7012 and CMMC Level 2, which means all 110 requirements of NIST SP 800-171 Rev. 2.
CDI
Covered defense information. The DFARS 252.204-7012 term for the CUI that clause protects. Includes controlled technical information and export-controlled data.

Not sure which one you are holding? Work it through.

Pairs that get confused

Adequate security vs. compliant
The clause asks for adequate security. The standard defines what that means. You can be adequate with open items in a POA&M, but only for the requirements the rules allow to be deferred.
SPRS score vs. certification
A score is a number you post. A certification is an assessment someone else performs. Level 2 contracts increasingly need the second.
Scope vs. company
The assessment covers the systems that handle CUI, not necessarily everything you own. A tight boundary is the single largest lever on cost.
ESP vs. cloud service
External service providers handling CUI on your behalf inherit obligations. A cloud service holding CUI generally needs FedRAMP Moderate equivalency.

Working vocabulary

SSP
System security plan. The document that describes your boundary, your environment, and how each of the 110 requirements is met. Requirement 3.12.4 asks for it, and an assessment cannot proceed without it.
POA&M
Plan of action and milestones. The dated list of requirements you have not yet met and how you will close them. Only some requirements may sit on a POA&M at assessment time.
SPRS
Supplier Performance Risk System. The DoD system where you post your 800-171 self-assessment score and where senior officials affirm it.
C3PAO
CMMC Third-Party Assessment Organization. An accredited assessor that conducts Level 2 certification assessments.
DIBCAC
Defense Industrial Base Cybersecurity Assessment Center. The DoD organization that conducts Level 3 assessments and some higher-confidence Level 2 assessments.
ODP
Organization-defined parameter. A blank inside a Rev. 3 requirement, such as a time period or frequency, that the organization fills in and an assessor checks. Rev. 2 has none.
Assessment objective
One determination statement from NIST SP 800-171A. Each requirement breaks into several; an assessor decides each one separately, and a requirement is met only when all of its objectives are.