> ## Content Index
> Fetch the complete content index at: https://www.cmmcoperator.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CMMC and Compliance Glossary
- URL: https://www.cmmcoperator.com/cmmc-compliance-glossary/
- Published: 2026-05-18T20:41:49.000Z
- Updated: 2026-08-18T19:22:37.000Z
- Description: Plain-English definitions of CMMC, cybersecurity, and compliance terms defense contractors need to know.
- Author: HydratedSec
- Tags: CMMC, Glossary

[Back to Resources](https://www.cmmcoperator.com/reference/)

# CMMC & Compliance Glossary

75+ terms every defense contractor should know

Showing 94 of 94 terms

[A](#glossary-a) [B](#glossary-b) [C](#glossary-c) [D](#glossary-d) [E](#glossary-e) [F](#glossary-f) [G](#glossary-g) [I](#glossary-i) [J](#glossary-j) [K](#glossary-k) [L](#glossary-l) [M](#glossary-m) [N](#glossary-n) [O](#glossary-o) [P](#glossary-p) [R](#glossary-r) [S](#glossary-s) [T](#glossary-t) [V](#glossary-v) [W](#glossary-w) [Z](#glossary-z)

## A

### Access Control

The set of policies, procedures, and technical mechanisms that govern who or what can view, use, or modify resources within an information system. Access control is the first and largest control family in NIST SP 800-171.

### Accreditation

A formal declaration by a designated authority that an information system is approved to operate under a defined set of security conditions. Accreditation signifies that residual risks have been reviewed and accepted.

### Advanced Persistent Threat (APT)

A sophisticated, well-resourced adversary - typically a nation-state or state-sponsored group - that gains and maintains long-term unauthorized access to a network. APTs pursue specific intelligence objectives rather than opportunistic exploitation.

### Assessment Objective (AO)

A granular evaluation criterion that breaks a single security control into individually testable statements. Assessors use AOs to determine whether an organization has fully met every aspect of a practice.

### ATO (Authority to Operate)

An official management decision authorizing a system to process, store, or transmit information at an accepted level of risk. An ATO is typically granted after a thorough security assessment and risk review.

### Audit Log

A chronological record that captures security-relevant events such as user logins, configuration changes, and data access attempts. Audit logs provide the evidence trail needed for forensic investigations and compliance reviews.

### Authorization Boundary

The clearly defined perimeter that encompasses all hardware, software, firmware, and network components of a system subject to a security assessment. Everything inside this boundary must meet the applicable compliance requirements.

### Awareness and Training

The security control family that requires organizations to ensure personnel understand their cybersecurity responsibilities through initial and ongoing education. Training programs must cover role-specific threats, policies, and procedures relevant to handling CUI.

## B

### Baseline Configuration

A documented, reviewed, and agreed-upon specification that describes the standard settings for an information system at a given point in time. Changes to this baseline are tracked and controlled through a formal change management process.

### Body of Evidence (BOE)

The complete collection of documentation, artifacts, and records an organization presents to prove it meets specified security requirements. A BOE typically includes policies, procedures, system security plans, scan results, and training records.

## C

### C3PAO (CMMC Third-Party Assessment Organization)

An organization authorized by the Cyber AB to conduct official CMMC assessments on behalf of the DoD. C3PAOs employ certified assessors who evaluate whether contractors satisfy the security practices required at their target CMMC level.

### CAGE Code

A five-character alphanumeric identifier assigned by the Defense Logistics Agency to entities doing business with the U.S. federal government. Contractors need a CAGE code to register in government procurement systems and participate in CMMC assessments.

### CMMC (Cybersecurity Maturity Model Certification)

A DoD-mandated framework that verifies defense contractors have implemented adequate cybersecurity practices to protect sensitive government information. CMMC defines three certification levels, each building on the requirements of the one below it.

### CMMC-AB (Cyber AB)

The independent accreditation body - now officially called the Cyber AB - responsible for training assessors, authorizing C3PAOs, and overseeing the integrity of the CMMC certification ecosystem.

### Compensating Control

An alternative safeguard that provides equivalent protection when the originally prescribed control cannot be directly implemented. Compensating controls must be documented, justified, and assessed to confirm they adequately mitigate the identified risk.

### Conditional Assessment

A CMMC assessment outcome where an organization has not fully met all required practices but has documented a credible plan to close gaps within 180 days. The organization receives a conditional certification that converts to full certification once deficiencies are resolved.

### Configuration Management

The discipline of systematically controlling changes to hardware, software, documentation, and network settings throughout their lifecycle. Effective configuration management prevents unauthorized modifications and ensures systems remain in a known, secure state.

### Continuous Monitoring

An ongoing process that maintains awareness of an organization's security posture by regularly collecting, analyzing, and reporting on threat and vulnerability data. Continuous monitoring ensures that changes in risk are detected and addressed promptly.

### Control

A specific safeguard or countermeasure - whether technical, administrative, or physical - that an organization implements to reduce risk and protect information. Controls are the building blocks of any compliance framework.

Related: Control Family, Practice, Security Control

### Control Family

A logical grouping of related security controls that address the same domain, such as access control, incident response, or media protection. Frameworks organize controls into families to simplify implementation and assessment.

Related: Control, NIST SP 800-171

### Controlled Environment

A physical or logical space where access is restricted and monitored to prevent unauthorized individuals from viewing, handling, or modifying sensitive information. Controlled environments enforce both physical and technical protections.

Related: Physical Security, Enclave

### CUI (Controlled Unclassified Information)

Government-created or government-received information that requires safeguarding per law, regulation, or policy but does not meet the threshold for classification. CUI encompasses dozens of categories including export-controlled technical data, privacy records, and procurement-sensitive information.

Related: CUI Registry, FCI, NIST SP 800-171

### CUI Registry

The official online repository maintained by the National Archives that catalogs every approved CUI category and subcategory along with its handling and dissemination requirements. Contractors reference the registry to determine which markings and protections apply to specific data.

Related: CUI

### Cybersecurity Maturity Model

A structured framework that organizes security practices into progressively rigorous levels, allowing organizations to measure and improve their cybersecurity posture incrementally. CMMC is the DoD-specific instance of this concept.

Related: CMMC

## D

### Data Loss Prevention (DLP)

Technologies and policies designed to detect and prevent unauthorized transmission or exfiltration of sensitive information. DLP solutions monitor email, web traffic, removable media, and cloud services to enforce data handling rules.

Related: CUI, Media Protection, Encryption in Transit

### Determination Statement

A declarative sentence within an assessment objective that describes a specific condition an assessor must verify. Each determination statement maps to a discrete, observable aspect of a security practice.

Related: Assessment Objective (AO), Practice

### DFARS (Defense Federal Acquisition Regulation Supplement)

A set of procurement regulations that supplement the FAR specifically for DoD contracts. DFARS clause 252.204-7012 is the primary mechanism requiring contractors to implement NIST SP 800-171 controls and report cyber incidents.

Related: FAR, CMMC, NIST SP 800-171

### DIB (Defense Industrial Base)

The worldwide network of private-sector companies and their subcontractors that design, produce, deliver, and maintain military systems, subsystems, and components for the Department of Defense. All DIB members handling CUI or FCI are subject to CMMC.

Related: CMMC, DFARS, CUI

### DIBCAC (Defense Industrial Base Cybersecurity Assessment Center)

The DoD entity responsible for conducting high-assurance cybersecurity assessments of defense contractors. DIBCAC performs the government-led assessments required for CMMC Level 3 certification.

Related: CMMC, DIB

### Dual Authorization

A security mechanism that requires two distinct, authenticated individuals to approve or execute a sensitive action, such as modifying critical system settings or accessing high-value data stores. This prevents any single person from unilaterally performing high-risk operations.

Related: Separation of Duties, Privileged User

## E

### Enclave

An isolated segment of a larger network that enforces a distinct security policy and boundary, typically to protect sensitive data at a higher assurance level than the surrounding environment. Organizations often create CUI enclaves to limit the scope of their CMMC assessment.

Related: Authorization Boundary, Scoping, System Boundary

### Encryption at Rest

The practice of converting stored data into ciphertext so that it remains unreadable without the proper decryption key. Encryption at rest protects information on disks, databases, backups, and removable media from unauthorized physical or logical access.

Related: Encryption in Transit, FIPS 140-2/140-3, Media Protection

### Encryption in Transit

The practice of protecting data as it moves across networks by applying cryptographic protocols such as TLS or IPsec. This prevents eavesdropping, interception, and tampering during transmission between systems.

Related: Encryption at Rest, FIPS 140-2/140-3

### Endpoint Detection and Response (EDR)

A category of security tools that continuously monitor endpoint devices for suspicious activity, provide real-time alerts, and enable rapid investigation and containment of threats. EDR solutions are a key detective control for CUI-processing systems.

Related: Continuous Monitoring, Incident Response Plan

### External Service Provider (ESP)

A third-party entity that provides IT services - such as cloud hosting, managed security, or help desk support - to an organization handling CUI. ESPs that process, store, or transmit CUI on behalf of a contractor fall within the contractor's CMMC assessment scope.

Related: Managed Service Provider (MSP), FedRAMP, Shared Services

## F

### FAR (Federal Acquisition Regulation)

The primary body of rules governing how the U.S. federal government purchases goods and services. FAR clause 52.204-21 establishes the 15 basic safeguarding requirements that form the foundation for CMMC Level 1\. The FAR overhaul model text renumbers this clause 52.240-93, but the renumbering is not codified and 32 CFR 170.14(c)(2) still cites 52.204-21.

Related: DFARS, FCI, CMMC

### FCI (Federal Contract Information)

Information generated or provided under a government contract that is not intended for public release. FCI is less sensitive than CUI but still requires baseline protection under FAR 52.204-21 and CMMC Level 1.

Related: CUI, FAR, CMMC

### Federal Information Processing Standards (FIPS)

A series of standards issued by NIST for use by federal agencies and their contractors. FIPS publications cover topics from encryption module validation (FIPS 140) to secure hashing algorithms, and compliance with applicable FIPS is mandatory for systems handling CUI.

Related: FIPS 140-2/140-3, NIST

### FedRAMP (Federal Risk and Authorization Management Program)

A government-wide program that standardizes the security assessment, authorization, and continuous monitoring of cloud products and services used by federal agencies. Defense contractors often rely on FedRAMP-authorized cloud solutions to inherit security controls.

Related: GCC High, External Service Provider (ESP)

### FIPS 140-2/140-3

Federal standards that specify the security requirements for cryptographic modules used to protect sensitive information. CMMC and NIST 800-171 require that encryption implementations use FIPS-validated modules to ensure they meet a verified level of cryptographic strength.

Related: Encryption at Rest, Encryption in Transit

### FISMA (Federal Information Security Modernization Act)

A U.S. law that mandates federal agencies and their contractors develop, document, and implement information security programs. FISMA drives the continuous-monitoring and risk-management requirements that underpin many DoD cybersecurity frameworks.

Related: NIST, Risk Assessment

## G

### Gap Analysis

A systematic comparison of an organization's current security posture against the requirements of a target framework to identify deficiencies. Gap analysis results directly inform remediation planning, resource allocation, and timeline estimates.

Related: Remediation, POA&M, Self-Assessment

### GCC High

A Microsoft Azure and Microsoft 365 cloud environment designed to meet DoD and ITAR requirements for handling CUI. GCC High is hosted in U.S.-only datacenters by screened personnel and carries FedRAMP High authorization.

Related: FedRAMP, CUI, Controlled Environment

## I

### Identification and Authentication

The security control family focused on verifying the identity of users, devices, and processes before granting them access to information systems. Strong identification and authentication form the foundation of all access control decisions.

Related: MFA, Access Control, Privileged User

### Incident Response Plan

A documented set of procedures that describes how an organization detects, contains, eradicates, and recovers from cybersecurity incidents. DFARS 252.204-7012 requires contractors to report qualifying cyber incidents to the DoD within 72 hours.

Related: DFARS, Audit Log, DIBCAC

### Information System

A discrete set of interconnected resources - including hardware, software, data, and personnel - organized to collect, process, store, transmit, or dispose of information. Defining information system boundaries is a prerequisite for any compliance assessment.

Related: System Boundary, Authorization Boundary

### Inherited Control

A security control whose implementation is provided by an external system, service, or infrastructure rather than by the organization itself. Cloud customers, for example, inherit physical security controls from their cloud provider.

Related: FedRAMP, External Service Provider (ESP), Shared Services

### Interconnection Security Agreement (ISA)

A formal document that establishes the technical and security requirements for connecting two separately owned information systems. An ISA defines the data flows, security controls, and responsibilities of each party for the shared connection.

Related: System Boundary, External Service Provider (ESP)

## J

### Joint Surveillance Voluntary Assessment (JSVA)

An early-adoption assessment program that allowed defense contractors to undergo a joint DIBCAC and C3PAO evaluation ahead of the CMMC rule's full implementation. JSVAs helped refine assessment procedures and gave participating organizations a head start on certification.

Related: DIBCAC, C3PAO, CMMC

## K

### Key Management

The set of policies and procedures governing the creation, distribution, storage, rotation, and destruction of cryptographic keys. Proper key management is essential to ensuring that encrypted data remains protected throughout its lifecycle.

Related: Encryption at Rest, FIPS 140-2/140-3

## L

### Least Privilege

A security principle that grants users, processes, and systems only the minimum access rights necessary to perform their assigned tasks. Enforcing least privilege limits the blast radius of compromised accounts and reduces insider-threat risk.

Related: Role-Based Access Control (RBAC), Privileged User, Separation of Duties

## M

### Managed Service Provider (MSP)

A company that remotely manages a customer's IT infrastructure, security tools, or end-user systems on an ongoing basis. When an MSP handles CUI-bearing systems, it becomes an external service provider within the customer's CMMC assessment scope.

Related: External Service Provider (ESP), Shared Services

### Marking

The process of applying the appropriate designators, headers, footers, and portion markings to documents and media that contain CUI. Correct marking ensures that anyone who handles the material understands its sensitivity and required protections.

Related: CUI, CUI Registry, Media Protection

### Media Protection

The controls and procedures that safeguard physical and digital storage media - such as USB drives, hard disks, backup tapes, and printed documents - throughout their lifecycle from creation to destruction. NIST 800-171 includes specific requirements for media sanitization and disposal.

Related: Encryption at Rest, Physical Security

### MFA (Multi-Factor Authentication)

An authentication method that requires users to present two or more distinct credential types - something they know, something they have, or something they are - before gaining access. MFA significantly reduces the risk of credential-based attacks.

Related: Two-Factor Authentication, Privileged User

## N

### Network Segmentation

The practice of dividing a network into isolated zones to limit the lateral movement of threats and contain potential breaches. Segmenting CUI-processing systems from general-purpose networks reduces the assessment scope and strengthens protection.

Related: Enclave, System Boundary, Scoping

### NIST (National Institute of Standards and Technology)

A non-regulatory agency within the U.S. Department of Commerce that develops standards, guidelines, and best practices for information security. NIST publications form the technical foundation for CMMC and most federal cybersecurity requirements.

Related: NIST SP 800-171, NIST SP 800-172, FISMA

### NIST SP 800-171

A special publication specifying 110 security requirements for protecting CUI in non-federal systems and organizations. It is the core technical standard behind CMMC Level 2 and the DFARS 252.204-7012 compliance obligation.

Related: NIST SP 800-171A, CMMC, CUI, DFARS

### NIST SP 800-171A

The companion assessment guide to SP 800-171 that provides 320 detailed assessment objectives and examination procedures for evaluating an organization's implementation of each security requirement. Assessors use 800-171A to structure their evidence review.

Related: NIST SP 800-171, Assessment Objective (AO), Body of Evidence (BOE)

### NIST SP 800-172

An enhanced security publication that adds 35 supplemental requirements beyond SP 800-171, designed to counter advanced persistent threats targeting critical programs. CMMC Level 3 draws its 24 additional practices from this document.

Related: NIST SP 800-171, APT, CMMC

## O

### ODP (Organization-Defined Parameter)

A placeholder within a security requirement that the implementing organization must fill with a specific, context-appropriate value - such as a time period, frequency, or list of roles. ODPs allow frameworks to remain flexible while requiring organizations to make deliberate implementation decisions.

Related: Control, Practice

### OSC (Organization Seeking Certification)

A defense contractor or subcontractor that is pursuing a CMMC assessment to demonstrate compliance with the required cybersecurity practices. The OSC is responsible for preparing its environment, evidence, and personnel for the assessment.

Related: C3PAO, CMMC, Body of Evidence (BOE)

### Other Than Satisfied

An assessment finding indicating that an organization has not adequately met one or more determination statements within a security practice. Any practice scored as "other than satisfied" counts against the organization's overall CMMC assessment result.

Related: Determination Statement, POA&M, SPRS

## P

### Penetration Testing

A controlled, authorized attempt to exploit vulnerabilities in a system, network, or application to evaluate its security defenses. Pen tests simulate real-world attack techniques to uncover weaknesses that automated scanning alone may miss.

Related: Vulnerability Scanning, Risk Assessment

### Personnel Security

The controls that screen individuals before granting them access to sensitive information and systems, and that manage access throughout and after their employment. Personnel security includes background checks, access agreements, and timely termination of access upon departure.

Related: Access Control, Least Privilege

### Physical Security

The measures designed to prevent unauthorized physical access to facilities, equipment, and information. Physical security includes building access controls, visitor logs, surveillance cameras, locked server rooms, and secure disposal procedures.

Related: Controlled Environment, Media Protection

### POA&M (Plan of Action and Milestones)

A structured document that identifies known security weaknesses, specifies the corrective actions planned, assigns responsible parties, and sets target completion dates. Under CMMC, limited POA&Ms may be permitted for certain practices, but some controls prohibit POA&M usage entirely.

Related: Remediation, Conditional Assessment, Gap Analysis

### Practice

The CMMC-specific term for a security requirement that an organization must implement at a given maturity level. Each practice traces back to a requirement in NIST SP 800-171 (Level 2) or NIST SP 800-172 (Level 3).

Related: Control, Assessment Objective (AO), CMMC

### Privileged User

An individual who has been granted elevated system access - such as administrator, root, or database owner rights - beyond what a standard user requires. Privileged accounts demand additional monitoring, MFA, and access restrictions because their compromise poses outsized risk.

Related: Least Privilege, Role-Based Access Control (RBAC), MFA

## R

### RBAC (Role-Based Access Control)

An access management approach that assigns permissions to defined organizational roles rather than to individual users. Users inherit the access rights of the roles they are assigned, simplifying administration and enforcing consistent security policies.

Related: Least Privilege, Separation of Duties

### Recovery

The phase of incident response and business continuity that restores information systems and data to a known-good state after a disruption or security incident. Recovery planning includes backup strategies, restoration procedures, and recovery time objectives.

Related: Incident Response Plan, Baseline Configuration

### Registered Practitioner (RP)

An individual authorized by the Cyber AB to provide CMMC consulting and readiness guidance to organizations seeking certification. RPs may advise but cannot conduct official assessments.

Related: RPA, CMMC-AB (Cyber AB)

### Remediation

The process of correcting identified security deficiencies by implementing missing controls, fixing misconfigurations, or updating policies and procedures. Effective remediation addresses root causes rather than symptoms.

Related: POA&M, Gap Analysis

### Risk Assessment

A systematic process for identifying threats to an organization, analyzing the likelihood and potential impact of each threat, and prioritizing risk responses. Regular risk assessments ensure that security investments target the most significant vulnerabilities.

Related: Gap Analysis, Vulnerability Scanning, Threat Intelligence

### RPA (Registered Provider Organization)

A company authorized by the Cyber AB to deliver CMMC preparation services, readiness assessments, and implementation support. RPAs employ Registered Practitioners and operate under a code of professional conduct.

Related: Registered Practitioner (RP), CMMC-AB (Cyber AB)

## S

### Scoping

The process of identifying which systems, networks, personnel, and facilities are in scope for a compliance assessment based on where CUI or FCI is processed, stored, or transmitted. Accurate scoping prevents both over-investment in unnecessary controls and dangerous gaps in coverage.

Related: Authorization Boundary, System Boundary, Enclave

### Security Assessment Boundary

The formally documented perimeter that defines everything subject to evaluation during a CMMC or other security assessment. It encompasses all technology assets, physical locations, and third-party services that handle in-scope data.

Related: Authorization Boundary, Scoping

### Security Control

A management, operational, or technical safeguard prescribed by a framework to protect the confidentiality, integrity, and availability of information. Security controls may be preventive, detective, corrective, or compensating in nature.

Related: Control, Control Family

### Self-Assessment

An internal evaluation where an organization measures its own compliance against a framework's requirements without involving a third-party assessor. CMMC Level 1 and Level 2 (for select contract types) permit self-assessment, but the results must be submitted to SPRS.

Related: SPRS, C3PAO, Body of Evidence (BOE)

### Separation of Duties

A security principle that divides critical functions among different individuals so that no single person can independently complete a high-risk process. This reduces the potential for fraud, error, and insider threats.

Related: Dual Authorization, Least Privilege, RBAC

### Shared Services

IT services - such as email, directory services, or endpoint management - that are provided centrally and consumed by multiple systems or business units. In a CMMC context, shared services that touch CUI pull the providing infrastructure into the assessment scope.

Related: External Service Provider (ESP), Managed Service Provider (MSP)

### Split Tunnel VPN

A VPN configuration that routes only designated traffic through the encrypted corporate tunnel while allowing other traffic to go directly to the internet. Split tunneling can reduce latency but may create uncontrolled data paths that complicate CUI protection.

Related: Encryption in Transit, Controlled Environment

### SPRS (Supplier Performance Risk System)

A DoD web application where contractors submit their self-assessed compliance scores based on NIST SP 800-171\. Contracting officers and program managers reference SPRS scores when evaluating contractor cybersecurity risk during source selection.

Related: Self-Assessment, NIST SP 800-171, Other Than Satisfied

### SSP (System Security Plan)

A comprehensive document that describes how an organization implements each required security control within its information system. The SSP covers the system boundary, data flows, roles and responsibilities, and the specific technical and procedural safeguards in place.

Related: Body of Evidence (BOE), Authorization Boundary, Control

### Supply Chain Risk Management

The set of activities for identifying, assessing, and mitigating risks arising from the products, services, and components provided by external suppliers. CMMC Level 3 and NIST SP 800-172 place particular emphasis on supply chain security for critical defense programs.

Related: DIB, External Service Provider (ESP), NIST SP 800-172

### System and Communications Protection

A NIST SP 800-171 control family that addresses requirements for monitoring, controlling, and protecting data at system boundaries and during transmission. Controls in this family cover encryption, session management, and network architecture.

Related: Encryption in Transit, Network Segmentation, Control Family

### System and Information Integrity

A control family focused on identifying, reporting, and correcting information system flaws in a timely manner. Requirements include vulnerability scanning, malicious code protection, security alert monitoring, and system integrity verification.

Related: Vulnerability Scanning, Continuous Monitoring, Control Family

### System Boundary

The logical and physical border that separates one information system from another and from external networks. A well-defined system boundary is critical for scoping a compliance assessment and ensuring all in-scope components are evaluated.

Related: Authorization Boundary, Scoping, Enclave

## T

### Threat Intelligence

Analyzed information about current and emerging cyber threats - including adversary tactics, techniques, and procedures - that organizations use to proactively strengthen their defenses. Threat intel feeds can be automated, community-shared, or classified.

Related: APT, Risk Assessment, Vulnerability Scanning

### Two-Factor Authentication

A subset of multi-factor authentication that requires exactly two different credential types to verify a user's identity. Common combinations include a password plus a one-time code from a hardware token or authenticator app.

Related: MFA

## V

### Virtual Desktop Infrastructure (VDI)

A technology that hosts desktop environments on centralized servers and streams them to endpoint devices. VDI can simplify CUI protection by keeping sensitive data in a controlled datacenter rather than on distributed laptops and workstations.

Related: Enclave, Controlled Environment, GCC High

### Vulnerability Scanning

The automated process of probing systems, networks, and applications for known security weaknesses using signature-based tools. Regular vulnerability scans help organizations identify and remediate exploitable flaws before adversaries can leverage them.

Related: Penetration Testing, Risk Assessment, Remediation

## W

### Whitelist (Allowlist)

A security technique that permits only explicitly approved software, network addresses, or users while blocking everything not on the approved list. Allowlisting is a strong preventive control against unauthorized software execution and network connections.

Related: Access Control, Configuration Management

## Z

### Zero Trust Architecture

A security model that assumes no implicit trust for any user, device, or network segment - even those inside the corporate perimeter. Every access request is continuously verified based on identity, device health, and context before granting the minimum required privileges.

CMMC Operator publishes documentation templates and planning resources for informational purposes only. Planning estimates are based on self-reported inputs and do not constitute a compliance determination, certification, or legal opinion.

## Ready to assess your CMMC readiness?

CMMC Operator helps defense contractors score their compliance posture across CMMC, NIST 800-171, and more - in minutes, not months.

[Get Started Free](https://cmmcoperator.com/cmmc-readiness-score?ref=cmmcoperator.com)

## Turn this guide into a readiness plan

Start with the free tools: the [Mac scope classifier](https://www.cmmcoperator.com/mac-cmmc-scope-classifier/) and the [POA&M eligibility checker](https://www.cmmcoperator.com/cmmc-poam-eligibility-checker/) turn control status into a prioritized plan. Do not enter CUI, FCI, credentials, or system evidence into any web tool.

[Run the free CMMC readiness check](https://cmmcoperator.com/cmmc-readiness-score?ref=cmmcoperator.com)