Terms people mix up
Three terms decide what you owe, four pairs get swapped in nearly every first conversation, and the rest is the working vocabulary of an assessment.
FCI, CUI, CDI
- FCI
- Federal contract information. Information provided by or generated for the government under a contract, not intended for public release, and not CUI. Covered by FAR 52.204-21 and CMMC Level 1.
- CUI
- Controlled unclassified information. Government-designated and, in theory, marked. Covered by DFARS 252.204-7012 and CMMC Level 2, which means all 110 requirements of NIST SP 800-171 Rev. 2.
- CDI
- Covered defense information. The DFARS 252.204-7012 term for the CUI that clause protects. Includes controlled technical information and export-controlled data.
Not sure which one you are holding? Work it through.
Pairs that get confused
- Adequate security vs. compliant
- The clause asks for adequate security. The standard defines what that means. You can be adequate with open items in a POA&M, but only for the requirements the rules allow to be deferred.
- SPRS score vs. certification
- A score is a number you post. A certification is an assessment someone else performs. Level 2 contracts increasingly need the second.
- Scope vs. company
- The assessment covers the systems that handle CUI, not necessarily everything you own. A tight boundary is the single largest lever on cost.
- ESP vs. cloud service
- External service providers handling CUI on your behalf inherit obligations. A cloud service holding CUI generally needs FedRAMP Moderate equivalency.
Working vocabulary
- SSP
- System security plan. The document that describes your boundary, your environment, and how each of the 110 requirements is met. Requirement 3.12.4 asks for it, and an assessment cannot proceed without it.
- POA&M
- Plan of action and milestones. The dated list of requirements you have not yet met and how you will close them. Only some requirements may sit on a POA&M at assessment time.
- SPRS
- Supplier Performance Risk System. The DoD system where you post your 800-171 self-assessment score and where senior officials affirm it.
- C3PAO
- CMMC Third-Party Assessment Organization. An accredited assessor that conducts Level 2 certification assessments.
- DIBCAC
- Defense Industrial Base Cybersecurity Assessment Center. The DoD organization that conducts Level 3 assessments and some higher-confidence Level 2 assessments.
- ODP
- Organization-defined parameter. A blank inside a Rev. 3 requirement, such as a time period or frequency, that the organization fills in and an assessor checks. Rev. 2 has none.
- Assessment objective
- One determination statement from NIST SP 800-171A. Each requirement breaks into several; an assessor decides each one separately, and a requirement is met only when all of its objectives are.