Cybersecurity Maturity Model Certification (CMMC) Assessment Process Vocabulary

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/31

flashcard set

Earn XP

Description and Tags

Vocabulary terms and definitions from the Cybersecurity Maturity Model Certification (CMMC) Assessment Process (CAP) version 5.6.1 transcript.

Last updated 6:32 AM on 5/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

32 Terms

1
New cards

CMMC

Cybersecurity Maturity Model Certification; the Department of Defense’s (DoD) unifying standard for the implementation of cybersecurity measures within the Defense Industrial Base (DIB).

2
New cards

CAP

CMMC Assessment Process; the CMMC doctrine providing the overarching procedures and guidance for C3PAOs conducting official CMMC Assessments.

3
New cards

The Cyber AB

Cybersecurity Maturity Model Certification Accreditation Body, Inc.; the entity responsible for administering the CMMC Marketplace and the CMMC Assessment Process.

4
New cards

CCP

Certified CMMC Professional; a trained individual eligible for roles in the CMMC Assessment ecosystem.

5
New cards

CCA

Certified CMMC Assessor; a certified individual who conducts CMMC Assessments and manages Assessment Teams.

6
New cards

OSC

Organization Seeking Certification; the DIB company, university, or legal entity pursuing CMMC Certification by contracting with a C3PAO.

7
New cards

OSC Assessment Official

The most senior representative of an OSC who has decision-making authority and is directly responsible for leading the OSC’s engagement in the Assessment; must be an employee of the organization.

8
New cards

OSC Point of Contact (OSC POC)

The individual within the OSC who provides daily coordination and liaison support; could be an employee, contractor, consultant, or Registered Practitioner (RP).

9
New cards

C3PAO

CMMC Third-Party Assessment Organization; an independent conformity-Assessment body authorized to conduct CMMC Assessments and issue certifications.

10
New cards

Lead Assessor

The CMMC Certified Assessor (CCA) who oversees and manages a dedicated CMMC Assessment Team for an OSC Assessment.

11
New cards

CQAP

CMMC Quality Assurance Professional; the formally trained individual responsible for ensuring Assessment documentation completeness, accuracy, and procedural integrity.

12
New cards

Assessment framing

The practice of identifying the size, scale, date, time, place, manner, resources, and level-of-effort associated with a prospective CMMC Assessment.

13
New cards

CMMC Assessment Scope

The official and technical term for the boundaries within an organization’s networked environment that contain all the assets to be assessed.

14
New cards

HQ Organization

The legal entity that will be delivering services or products under a DoD contract; can be the OSC itself or designate a Host Unit as the OSC.

15
New cards

Host Unit

The specific people, procedures, and technology within an HQ Organization that are applied to a DoD contract and considered the OSC for Assessment purposes.

16
New cards

Enclave

A set of system resources operating within the same security domain that share a single, common, and continuous security perimeter.

17
New cards

Supporting Organizations

External entities (people, procedures, and technology) that support the Host Unit; their assets may be in scope, but they do not receive a certificate during the OSC's Assessment.

18
New cards

CAGE code

Commercial and Government Entity code; a mandatory identifier issued by the Department of Defense for organizations undergoing Assessment.

19
New cards

UEI

Unique Entity Identifier; a number issued by GSA's SAM.gov system required for the organization's corporate structure.

20
New cards

Adequacy

The criteria used to determine if a given artifact or response demonstrates the performance of a CMMC practice; answers the question: "Does the Assessment Team have the right Evidence?"

21
New cards

Sufficiency

The criteria needed to verify that the CMMC domain and practice coverage is enough to rate against each practice based on scope; answers the question: "Does the Assessment Team have enough of the right Evidence?"

22
New cards

MET

A finding where the contractor successfully meets the practice and conforms to all objectives.

23
New cards

NOT MET

A finding where the contractor does not conform fully to all of the objectives of a practice.

24
New cards

NOT APPLICABLE (N/A)

A finding indicating a practice does not apply to the assessment, such as publicly accessible systems requirements when none exist.

25
New cards

Examine method

The process of reviewing, inspecting, observing, or analyzing Assessment objects such as specifications, mechanisms, or activities to obtain Evidence.

26
New cards

Interview method

The process of holding discussions with individuals or groups to facilitate understanding or achieve clarification of practice implementation.

27
New cards

Test method

The process of exercising Assessment objects under specified conditions to compare actual behavior with expected behavior.

28
New cards

CMMC eMASS

The official repository system and application into which authorized C3PAO representatives must upload Assessment Packages and Pre-Assessment Forms.

29
New cards

Limited Practice Deficiency Correction

An accommodation allowing OSCs to resolve minor documentation or implementation discrepancies within a restricted timeframe (usually 5 business days) to achieve a "MET" score.

30
New cards

POA&M

Plan of Action and Milestones; a time-bound document (maximum 180 days) used to identify and monitor corrective efforts for security weaknesses.

31
New cards

CMMC Level 2 Conditional Certification

A certification status requiring at least 80% (88/110) of practices to be "MET" and all remaining items to be on a valid, authorized POA&M.

32
New cards

JSON

JavaScript Object Notation; the specific data format required for structuring Pre-Assessment information for export into CMMC eMASS.