Skip to content

Glossary

This glossary explains every abbreviation the platform uses. If a term is missing, ask and it will be added.

  • CMMC, Cybersecurity Maturity Model Certification. A U.S. Department of Defense program that grades how well a company protects certain unclassified information. Levels 1, 2, and 3 set increasing security requirements. The platform helps you self-assess and prepare; the certification itself (Level 2+) is issued by a C3PAO, never by this platform.
  • FedRAMP, Federal Risk and Authorization Management Program. The U.S. government’s process for approving cloud services that handle federal data. “FedRAMP authorized” means a specific government agency (or the FedRAMP program office) approved a specific service after a security assessment.
  • FedRAMP 20x, the 2025+ modernization of FedRAMP. Classes A, B, and C certifications are available now; Class D is in a pilot phase.
  • SPRS, Supplier Performance Risk System. The DoD system where contractors report their own NIST SP 800-171 assessment scores. You compute the score in the platform; you submit it yourself.
  • NIST SP 800-171, a National Institute of Standards and Technology publication listing 110 security requirements for protecting CUI.
  • NIST SP 800-53, the larger control catalog (hundreds of controls) that FedRAMP baselines draw from.
  • FAR, Federal Acquisition Regulation. The main rulebook for federal buying. Citations look like “FAR 52.204-21”.
  • DFARS, Defense Federal Acquisition Regulation Supplement. The DoD-specific add-on to the FAR. Citations look like “DFARS 252.204-7012”.
  • SOC 2, a commercial (non-government) audit standard for how a company protects customer data. Not a government certification.
  • ISO 27001, an international information-security management standard. Also commercial, not government-issued.
  • FIPS 140-2 / 140-3, federal standards for cryptographic modules. “FIPS-validated encryption” means the encryption passed government testing.
  • CUI, Controlled Unclassified Information. Information the government says must be safeguarded but is not classified. Handled under 32 CFR Part 2002 and DFARS 252.204-7012.
  • CDI, Covered Defense Information. CUI in the defense context that triggers DFARS 252.204-7012 obligations.
  • FCI, Federal Contract Information. Information provided by or generated for the government under a contract, not intended for public release.
  • PII, Personally Identifiable Information. Data that can identify a person (name plus other details).
  • ITAR, International Traffic in Arms Regulations. Export rules for defense articles and data. The platform screens for ITAR relevance but does not handle ITAR-controlled data.
  • FOUO, For Official Use Only. An older marking; mostly replaced by CUI.
  • OSCAL, Open Security Controls Assessment Language. A machine-readable format (XML/JSON/YAML) from NIST for security documents. Think of it as “the same information as your security paperwork, but structured so a computer can check it.” The platform exports OSCAL files.
  • SSP, System Security Plan. The document describing a system and how it meets each security control. The core FedRAMP artifact.
  • POA&M, Plan of Action and Milestones. The list of security gaps with planned fixes and dates.
  • SAP, Security Assessment Plan. What the assessor will test.
  • SAR, Security Assessment Report. What the assessor found.
  • ATO, Authority to Operate. The agency decision that a system may run with federal data. Granted by an agency, not by a vendor.
  • 3PAO, Third Party Assessment Organization. A FedRAMP-recognized independent assessor.
  • C3PAO, CMMC Third Party Assessment Organization. The CMMC equivalent for Level 2 assessments.
  • DIBCAC, Defense Industrial Base Cybersecurity Assessment Center. DoD’s own assessment arm for high-assurance reviews.
  • ConMon, Continuous Monitoring. The ongoing checks after authorization.
  • RFP, Request for Proposal. The document asking companies to propose how they’d do the work and for how much.
  • SOW, Statement of Work. Describes what work is to be done.
  • PWS, Performance Work Statement. Describes the required results (outcomes) rather than how to do the work.
  • IGCE, Independent Government Cost Estimate. The government’s internal cost estimate for a requirement.
  • IDIQ, Indefinite Delivery, Indefinite Quantity. A contract vehicle where the government orders as needed over time.
  • GWAC, Governmentwide Acquisition Contract. An IDIQ usable by many agencies.
  • MAS, Multiple Award Schedule (GSA Schedules).
  • UEI, Unique Entity Identifier. The government’s ID for your company (replaced DUNS).
  • CAGE code, Commercial and Government Entity code. A 5-character DoD identifier for your company/facility.
  • NAICS, North American Industry Classification System. Codes that classify industries; contracts specify one.
  • PSC, Product Service Code. Classifies what a contract buys (products/services).
  • SAM.gov, System for Award Management. The federal portal where contracts are posted and where you register to do business.
  • USASpending, the federal spending data site.
  • FPDS, Federal Procurement Data System. Historical award records.
  • Set-aside, a contract reserved for a category of business (small business, veteran-owned, etc.).
  • Teaming, joining with another company to pursue a contract together.
  • AES-256-GCM, an encryption standard. AES is the algorithm, 256 is the key length, GCM is the mode that also detects tampering.
  • At rest / in transit, “at rest” means stored (in a database or on disk); “in transit” means moving across a network. Both should be encrypted.
  • Pass-through, this platform’s core posture: it prepares documents and computes scores for YOU, and YOU review, sign, and submit them to the government. The platform never signs or submits on your behalf and never claims certifications it doesn’t hold.
  • Tenant isolation, each customer’s data is scoped to their own account, so one customer can never see or change another’s records.
  • Atomic claim verification, every factual claim in generated proposal text is checked against its cited source; claims that don’t hold up are flagged or regenerated before a section is marked ready.
  • Immutable audit trail, every important action is recorded in an append-only log that can’t be edited after the fact.