Quick reference

Compliance Acronyms — One Page

The acronyms that appear in contracts and assessments, defined in one line each.

Intended audience
Everyone
Difficulty
Beginner
Estimated time
5 minutes
Access
Free
CMMC
NIST SP 800-171
FAR
DFARS
NIST CSF
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Correctly expand and define the acronyms most commonly used in federal contracting and cybersecurity assessments.
  • Distinguish between framework/standard acronyms (NIST CSF, NIST SP 800-171) and contracting terms (FAR, DFARS, FCI, CUI).
  • Identify which program documents (SSP, POA&M, IRP) are typically required as evidence during an assessment.

Frameworks and standards

  • NIST — National Institute of Standards and Technology, publisher of widely used security standards.
  • NIST CSF — Cybersecurity Framework: a risk-based structure of functions such as identify, protect, detect, respond, recover.
  • NIST SP 800-171 — Requirements for protecting Controlled Unclassified Information in non-federal systems.
  • NIST SP 800-53 — Broad control catalog used primarily by federal systems.
  • CIS Controls — Prioritized, prescriptive baseline of security practices.
  • ISO 27001 — International standard for an information security management system.
  • SOC 2 — Audit report on controls relevant to security, availability, and confidentiality.

Contracting terms

  • CMMC — Cybersecurity Maturity Model Certification, the Department of Defense verification program.
  • FAR — Federal Acquisition Regulation, the baseline federal contracting rules.
  • DFARS — Defense supplement to the FAR.
  • FCI — Federal Contract Information: information not for public release, generated or received under a contract.
  • CUI — Controlled Unclassified Information: unclassified information that still requires safeguarding.

Program documents

  • SSP — System Security Plan describing the system and control implementation.
  • POA&M — Plan of Action and Milestones tracking gaps and remediation.
  • IRP — Incident Response Plan.
  • AUP — Acceptable Use Policy.
  • DPA — Data Processing Agreement with a vendor.

Key takeaways

  • FCI and CUI are distinct categories of information, and the safeguarding requirements that apply depend on which category a given system or document falls under.
  • CMMC, FAR, and DFARS are related but different: FAR sets baseline federal contracting rules, DFARS adds Department of Defense-specific clauses, and CMMC is the DoD's verification program for cybersecurity requirements.
  • An SSP and a POA&M serve different purposes: the SSP describes how controls are implemented, while the POA&M tracks known gaps and their remediation timeline.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This resource is educational readiness material. ComplianceAnvil is not a certification authority, assessor, or law firm, and this content is not legal advice or a compliance assessment.

Matched on shared frameworks, topics, and program packs.

Checklist

Government Contractor Startup Checklist

What to put in place before your first federal award creates security obligations you cannot meet.

Intermediate
40 min
Free
FAR
DFARS

Published · v1.0.0 · 2026-08-01

Checklist

CMMC Readiness Checklist

Work through the preparation steps most small contractors miss before a CMMC assessment: scope, system boundary, documentation, and evidence.

Intermediate
45 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Checklist

Evidence Collection Checklist

Turn what you already do into evidence: what to capture, how to label it, and how long to keep it.

Intermediate
25 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Exercise

Identify CUI Examples

Practice separating CUI from FCI and from ordinary business information.

Advanced
15 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Checklist

NIST SP 800-171 Preparation Checklist

A plain-language preparation pass across the requirement families, focused on what a small business must produce and prove.

Advanced
60 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.