Quick answer: Start with SPRS, CUI,CMMC, SSP, POA&M, andFCA if those keep showing up in emails from primes. Then use the freeDefensibility Check when you are ready to pressure-test a score.

Rules & programs

The frameworks and regulations that shape what contractors must do.

CMMCCybersecurity Maturity Model Certification

A DoD program that defines cybersecurity levels for contractors handling federal contract information or Controlled Unclassified Information. Levels and assessment paths have evolved; always check current rule text and your contracts.

Why it matters: Primes and solicitations may still ask about CMMC status even when certification calendars shift. Headlines about “suspension” are not the same as your clause language going away.

CMMC after Phase II suspension →

DFARSDefense Federal Acquisition Regulation Supplement

DoD-specific acquisition rules layered on top of the Federal Acquisition Regulation (FAR). Cyber-related DFARS clauses are how many safeguarding and reporting requirements show up in contracts.

Why it matters: What you signed (or will sign) usually matters more than a blog summary of CMMC news. Your contracts and flow-downs are the checklist that counts.

Is CMMC still required? →

FARFederal Acquisition Regulation

The primary set of rules governing how the U.S. federal government buys goods and services. DFARS is the DoD-specific supplement.

NIST SP 800-171NIST Special Publication 800-171

The National Institute of Standards and Technology catalog of security requirements for protecting Controlled Unclassified Information in nonfederal systems. CMMC Level 2 is closely tied to this baseline.

Why it matters: Most “do we have to secure this?” conversations for defense subcontractors still land on 800-171 practices—even when the certification path is in flux.

Rev 2 vs Rev 3 →

Rev 2 / Rev 3NIST SP 800-171 Revision 2 and Revision 3

Two editions of the 800-171 baseline. Many existing assessments still reference Rev 2; Rev 3 reorganizes and updates requirements. Your contract or assessment methodology should say which applies.

Common confusion: “Rev 3 is out” does not automatically erase work against Rev 2 for live awards. Confirm which revision you must meet today, and plan the uplift deliberately.

What to do while rules shift →

DIBDefense Industrial Base

The ecosystem of primes, subcontractors, and suppliers that design, build, and support defense systems and services—from large OEMs down to small machine shops.

Scoring & assessment

How readiness is measured, reported, and reviewed.

SPRSSupplier Performance Risk System

A DoD system where contractors report (among other things) their NIST SP 800-171 assessment score when required. In everyday contractor talk, “SPRS score” usually means that self-assessment score entry.

Why it matters: A number in SPRS is not just a procurement checkbox—someone may have to stand behind it. Optimistic scores create operational and legal risk.

How to calculate your SPRS score →

SPRS scoreNIST SP 800-171 assessment score reported in SPRS

A weighted score derived from how many 800-171 requirements are fully implemented. The common model starts at 110 and subtracts weighted values for gaps; totals can go deeply negative when many controls are unmet.

Common confusion: A “high” score is not automatically a good score. A defensible score matches reality and evidence—not the number that looks competitive in a bid.

Do I still need a SPRS score in 2026? →

Self-assessmentOrganization-performed 800-171 assessment

Your company evaluates implementation of the security requirements and stands behind the results—without a third-party certification body running the assessment for you.

Why it matters: For many small subcontractors, honest self-assessment is the live posture even when third-party certification timing moves.

Self-assessment vs C3PAO →

C3PAOCMMC Third-Party Assessment Organization

An authorized organization that can perform third-party CMMC assessments. This is different from a self-assessment your team runs and affirms.

Common confusion: Hiring tools, MSPs, or consultants is not the same as a C3PAO certification outcome. Know which path your contracts actually require.

What the suspension changed →

POA&MPlan of Action and Milestones

A living list of security gaps with owners, milestones, and target dates. Used to track remediation—not to hide permanent “we’ll get to it someday” items.

Why it matters: Hidden or eternal POA&Ms are a classic reason a score looks fine on paper and fails under review.

Free Defensibility Check →

Not POA&M-able (common usage)Controls that cannot simply be parked on a POA&M under the scoring rules you are using

Under DoD’s assessment scoring methodology for 800-171, some unmet requirements affect scoring in ways teams often misunderstand. Always use the official methodology that applies to your assessment—not a blog summary.

Common confusion: Assuming every gap can be “POA&M’d away” without scoring impact is a frequent error. Verify the current rules before you mark controls.

Scoring mechanics →

Data & documents

What you protect, and the paperwork that describes how.

CUIControlled Unclassified Information

Information the government creates or possesses (or that an entity creates or possesses for the government) that requires safeguarding or dissemination controls under law, regulation, or government-wide policy—but is not classified.

Why it matters: If CUI is in your email, file shares, or shop-floor systems, 800-171-style protections are not optional theory—they are the job.

Common confusion: CUI designation is government-driven. Tools and blogs (including this site) do not “make” something CUI. When unsure, ask the prime or contracting officer.

Is your SSP CUI? →

FCIFederal Contract Information

Information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service. Related to, but not identical with, CUI.

CDICovered Defense Information

A DFARS-era term for certain unclassified controlled technical information and other information requiring protection under DoD contracts. Closely related in practice to CUI conversations for defense work.

Common confusion: Older contracts and training may say CDI while newer material says CUI. Focus on what your clauses and markings actually require.

SSPSystem Security Plan

The document that describes your system boundary, how security requirements are implemented, and who is responsible (including MSPs and cloud providers). Assessors and reviewers compare the SSP to reality and to your score marks.

Why it matters: An aspirational SSP is a liability. The plan should match how you actually operate today.

What a defensible SSP requires →

Enclave (CUI enclave)Isolated environment for handling CUI

A bounded set of systems and controls where CUI is processed, stored, or transmitted—separated from less-trusted IT so requirements can be applied consistently.

Why it matters: Small shops often over-scope (everything is “in”) or under-scope (the real CUI laptop is left out). Scope errors poison the entire assessment.

Risk, roles & operations

Who stands behind the work—and the risk language that shows up in real life.

FCAFalse Claims Act

A U.S. law that imposes liability for knowingly submitting false claims to the government. In cyber compliance discussions, the concern is representing a cybersecurity posture (including a score) that is not true.

Why it matters: This site treats signature risk as an operational problem: do not invent maturity you cannot demonstrate. We do not give legal advice—talk to counsel about your facts.

SPRS score & the False Claims Act →

Defensible scoreA SPRS / 800-171 score you can stand behind

Not an official DoD term—our plain-language label for a score built on real scope, real evidence, correct scoring math, and a story a knowledgeable person can sign without inventing maturity.

Run the free Defensibility Check →

MSPManaged Service Provider

An outside firm that runs parts of your IT (endpoints, email, servers, monitoring). In CMMC conversations, MSPs often share responsibility for controls—but your score still needs evidence of what is actually done.

Common confusion: “Our MSP handles CMMC” is incomplete. Shared-responsibility gaps show up when the SSP and evidence do not match.

MSSPManaged Security Service Provider

A provider focused on security operations (monitoring, detection, response) rather than only general IT support. Still not a substitute for your own assessment honesty.

Flow-downContract requirements passed from prime to subcontractor

Cyber and other clauses that primes push into subcontracts so the supply chain meets DoD expectations. Small shops often first “meet CMMC” because a prime required it.

Why it matters: Even if you never bid DoD primes directly, flow-downs can still put 800-171 and SPRS obligations on your plate.

CISO / vCISOChief Information Security Officer / virtual (fractional) CISO

The role accountable for security strategy and risk decisions. Smaller firms often use a fractional (vCISO) adviser instead of a full-time hire.

Educational reference only—not legal advice, not a substitute for official NIST/DoD publications, and not a certification. Always verify requirements against primary sources and your contracts.