Readiness check
Reference / The regulatory landscape

CUI, ITAR, IL5. The vocabulary, without the fog.

The acronyms overlap and the rules cite each other. This is the map: what each term means, which clause it comes from, and how they connect. Plain definitions first — the citation is there when you need it.

A / Data types

What kind of information you hold decides everything downstream.

FCI
Federal Contract Information
Information provided by or generated for the government under a contract, not intended for public release. The lowest tier — it triggers CMMC Level 1 basic safeguarding.
CUI
Controlled Unclassified Info
Unclassified information the government requires be safeguarded or disseminated under controls. The center of gravity for DFARS 7012 and CMMC Level 2. Categories live in the NARA CUI Registry.
32 CFR Part 2002 · DoDI 5200.48
CDI
Covered Defense Information
The DFARS term for CUI (and controlled technical information) handled under a defense contract. When a contract has CDI, the 7012 clause and its safeguards attach.
ITAR data
Export-controlled (defense)
Technical data for items on the U.S. Munitions List. Access is restricted to U.S. persons and export is licensed by the State Department. The strongest driver toward US-person-controlled environments.
22 CFR 120–130 · DDTC · USML
EAR data
Export-controlled (dual-use)
Dual-use items and technology on the Commerce Control List. Controls turn on the item's classification (ECCN) and destination. Often lighter than ITAR, but still export-controlled.
15 CFR 730–774 · BIS · CCL
B / Frameworks & rules

The rules that cite each other.

DFARS 252.204-7012
The clause
Requires you to safeguard CDI per NIST 800-171, report cyber incidents within 72 hours, and use a cloud that meets FedRAMP Moderate (or equivalent). This is usually the clause in your contract.
NIST SP 800-171 Rev 2
The control set
110 security controls across 14 families for protecting CUI in non-federal systems — the technical substance behind 7012 and CMMC Level 2. Rev 3 (97 requirements, 17 families) is published, but CMMC/DoD still assess against Rev 2 under a 2024 class deviation.
CMMC
The verification program
Cybersecurity Maturity Model Certification. L1 = basic FCI safeguarding (self-assessed). L2 = the 110 controls / 320 objectives, C3PAO-assessed. L3 adds NIST 800-172 controls for the highest-risk programs.
FedRAMP
Cloud authorization
The government's cloud security program. Moderate is the 7012 baseline; High is common in GovCloud regions. Authorized on the Marketplace satisfies 7012 directly; "equivalent" puts the burden of proof on you.
GSA FedRAMP · DoD CIO memo 21 Dec 2023
32 CFR / 48 CFR
The rulemaking
32 CFR is the CMMC program rule (live Dec 2024). 48 CFR is the acquisition rule that puts CMMC into contracts (DFARS 7021; Phase 1 live 10 Nov 2025). Together they turn the model into a contract requirement.
Phase 2 paused 13 Jul 2026 — DoD policy memoranda [confirm — current status at engagement]
C / The DFARS clause family

Four clauses, not one. They travel together in your contract.

7012
Safeguard & report
Implement NIST 800-171, report incidents affecting CDI within 72 hours, and flow the requirement down to subcontractors.
DFARS 252.204-7012
7019
Post your score
Post your NIST 800-171 self-assessment score in SPRS and keep it current — within the last three years.
DFARS 252.204-7019
7020
Government verification
Give DoD the right to conduct a higher-level assessment, and maintain your posted score as a condition of award.
DFARS 252.204-7020
7021
The CMMC requirement
Hold the CMMC level the contract names — Level 1, 2, or 3 — before award. This is the clause that makes certification contractual.
DFARS 252.204-7021
D / Scoping & asset categories

Scope is the biggest lever on cost.

CMMC sorts everything that touches your environment into five categories. What lands where decides how large — and how expensive — the assessment is.

CUI Assets
Process, store, or transmit CUI. The core of the boundary.
Assessed fully
Security Protection Assets
Provide security functions to the boundary — SIEM, identity, endpoint management.
Assessed for protection
Contractor Risk-Managed Assets
Could access CUI but aren't intended to, and are managed by policy to keep them out.
Limited, if documented
Specialized Assets
OT and IoT, test equipment, government property, restricted systems.
Managed by policy
Out-of-Scope Assets
Cannot access CUI and are separated from the boundary by design.
Not assessed
Source: CMMC Assessment Scoping Guide, Level 2. A tight enclave keeps most assets out of scope.
E / DoD impact levels

The SRG impact levels, from public to classified.

IL2
Non-controlled public info
Low-sensitivity data cleared for public release. The baseline tier.
IL4
CUI
Controlled unclassified information — where most DIB workloads land.
IL5
Higher-sensitivity CUI / NSS
More sensitive CUI and unclassified National Security Systems.
IL6
Classified up to SECRET
Classified national security information. A different regime entirely.
Source: DoD Cloud Computing SRG v1r4 (Jan 2022). Most DIB CUI work sits at IL4/IL5.
F / Assessment & artifacts

Who checks the work, and what they read.

C3PAO
Certified Third-Party Assessment Organization. Authorized by the Cyber AB to conduct CMMC Level 2 assessments.
SSP
System Security Plan. Describes your boundary and how each of the 110 controls is met. The assessor's primary document.
POA&M
Plan of Action & Milestones. Documents gaps and how you'll close them. Limited under CMMC — some controls allow none.
SPRS score
Supplier Performance Risk System. Where you post your 800-171 self-assessment score, out of a maximum of 110.
Assessment objectives
The 320 discrete checks a C3PAO verifies — the 110 controls broken into their testable parts.
72-hour report
DFARS 7012 requires reporting a cyber incident affecting CDI to DoD within 72 hours of discovery.
SPRS scoring
Start at 110 and subtract weighted points for each unmet control. The score can go negative. Posted under DFARS 7019.
Cyber AB
The accreditation body that authorizes and oversees C3PAOs and CMMC practitioners.
RPO / RP
Registered Provider Organizations and Practitioners advise and prepare you. They cannot certify — that's the C3PAO.
CUI Basic vs Specified
Basic follows standard 800-171 handling. Specified carries category rules that can tighten your boundary.
Conditional vs Final
A conditional certification allows a limited POA&M. You have 180 days to close it for a final status.
G / How it fits together

From the data you hold to the assessment you pass.

STEP 01
You hold CUI / CDI
± ITAR / EAR data
STEP 02
The clause attaches
STEP 03
Controls apply
NIST 800-171 · 110 controls
STEP 04
On an authorized cloud
FedRAMP Moderate+ · IL4/5
STEP 05
Verified
CMMC L2 · C3PAO · 320 objectives

This page is a plain-language reference, not legal advice. Regulatory status current Sept 2026 and fast-moving — confirm against your contract and the current rule text. Official citations for every term are on file.

Know the vocabulary. Now map it to your contract.

A readiness check turns these terms into a plan for your specific clause and cloud.