Skip to content

Glossary

Compliance terms, explained plainly

Shared vocabulary makes compliance conversations shorter. These are the terms that come up most often.

Assessment objective
A discrete element of a requirement that is evaluated individually during an assessment.
C3PAO
A CMMC Third-Party Assessment Organization authorized to conduct formal CMMC assessments.
CUI
Controlled Unclassified Information — government-created or owned information requiring safeguarding under law, regulation, or government-wide policy.
Control
A safeguard or countermeasure implemented to satisfy a security or governance requirement.
DIB
The Defense Industrial Base — the organizations that supply the Department of Defense.
Evidence
Documentation or artifacts that substantiate how a requirement is satisfied.
FCI
Federal Contract Information — information provided by or generated for the government under a contract, not intended for public release.
Finding
A deficiency identified during an assessment or review.
Gap
The difference between a requirement's expectation and its current implementation.
GRC
Governance, Risk, and Compliance — the disciplines an organization uses to direct, manage risk in, and demonstrate conformance of its operations.
POA&M
Plan of Action & Milestones — a structured record of deficiencies with corrective actions, owners, and target dates.
Remediation
The work performed to resolve an identified deficiency.
Risk register
The maintained list of identified risks, with ownership, rating, treatment, and review dates.
Scope
The systems, environments, people, and facilities to which a set of requirements applies.
SPRS
The Supplier Performance Risk System, used by the Department of Defense to collect certain supplier assessment information.
SSP
System Security Plan — documentation describing a system, its boundary, and how applicable security requirements are satisfied.
Third-party risk
Risk introduced through vendors, suppliers, and other external relationships.

Ready to bring your compliance program together?

See how CyberComply can help centralize requirements, evidence, risks, remediation, documentation, and assessment readiness.