Compliance & Security Glossary
Which compliance framework do we actually need?
It depends on who is asking and what they require.
-
A Defense prime flowing down contract requirements will include CMMC.
-
A commercial enterprise conducting vendor due diligence will usually ask for SOC 2.
-
An international partner or competitive RFP may specify ISO 27001.
-
A federal civilian agency buying your cloud product will require FedRAMP.
Each has different requirements and assessors, but the underlying controls overlap. The order in which you pursue them can significantly affect the total cost. Below are some of the common acronyms and terms to know.
Frameworks and Standards
SOC 2 — An attestation report issued by a licensed CPA firm that evaluates how well an organization’s controls meet the AICPA Trust Services Criteria. It is the security report most commonly requested in commercial B2B sales.
SOC 1 — An attestation focused on controls over financial reporting rather than security. Customers may request one when your service affects their financial statements, as with payroll or payment processing.
SOC 3 — A public, general-use summary of a SOC 2 report. Unlike a full SOC 2 report, it can be published and used as a marketing or customer-assurance document.
Trust Services Criteria (TSC) — The five categories a SOC 2 report may cover: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is mandatory. The other four are optional, and adding them increases the scope and cost of the examination.
ISO/IEC 27001 — The international standard for information security management systems. An accredited certification body certifies an organization on a three-year cycle, with surveillance audits each year. The current version is ISO/IEC 27001:2022.
ISMS (Information Security Management System) — The documented management system at the center of ISO 27001. It covers scope, policies, risk methodology, objectives, internal audits, and management reviews. ISO 27001 certifies the management system, not simply a list of controls.
Annex A — The control catalog in ISO 27001:2022. It contains 93 controls across four themes: organizational, people, physical, and technological. The Statement of Applicability explains which controls apply.
Statement of Applicability (SoA) — The ISO 27001 document that records which Annex A controls apply, how they are implemented, and why any controls have been excluded. Auditors usually review it early in the process.
ISO/IEC 27701 — A privacy extension to ISO 27001 for organizations that process personal data. It is often pursued alongside GDPR compliance work.
ISO/IEC 42001 — The management-system standard for artificial intelligence. It is appearing more often in vendor requirements for organizations that deploy AI features in regulated environments.
NIST Cybersecurity Framework (CSF) — A voluntary, outcome-based framework organized around six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Organizations often use it to structure their security programs and report risk to leadership rather than to obtain a certification.
NIST SP 800-53 — The broad security and privacy control catalog for federal information systems. Many other federal control sets are derived from it.
NIST SP 800-171 — The 110 security requirements for protecting Controlled Unclassified Information in nonfederal systems. Revision 2 remains the operative baseline for CMMC assessments. Defense has indicated that it intends to move to Revision 3 through rulemaking, so contractors should monitor the transition rather than assume either version is permanent.
NIST SP 800-172 — Enhanced requirements added to NIST SP 800-171 for systems that must defend against advanced persistent threats. It applies to the highest-priority defense programs.
NIST SP 800-37 / Risk Management Framework (RMF) — The federal process for categorizing systems, selecting and implementing controls, assessing those controls, authorizing operation, and monitoring the system. It is the standard route to an ATO.
FISMA — The federal law requiring agencies, and contractors operating systems on their behalf, to maintain information security programs. It provides the statutory basis for many RMF and ATO requirements.
FedRAMP — The standardized program for authorizing cloud services for federal government use at Low, Moderate, or High impact levels. It is required for most cloud products sold to federal civilian agencies.
FedRAMP 20x — FedRAMP’s modernization program, intended to accelerate authorizations through automation and continuous validation rather than relying primarily on point-in-time document reviews. Phase 2 pilots are underway, and the requirements are still developing.
GovRAMP — The state, local, and education counterpart to FedRAMP. It was known as StateRAMP before its 2025 rebrand. State procurement documents cite it increasingly, and the program recognizes some FedRAMP work.
CJIS Security Policy — FBI requirements for systems that handle criminal justice information. The policy applies to law enforcement agencies and the vendors that serve them.
HIPAA — The U.S. law governing protected health information, including the administrative, physical, and technical safeguards in the Security Rule. The Office for Civil Rights enforces HIPAA. There is no official “HIPAA certified” credential.
HITRUST CSF — A prescriptive, certifiable framework that combines requirements from HIPAA, NIST, ISO, and other sources. It is common in healthcare, where customers often want a formal credential that HIPAA itself does not provide.
PCI DSS — The payment-card industry’s security standard for organizations that store, process, or transmit cardholder data. The card brands impose it through contracts rather than legislation.
CIS Controls — A prioritized set of practical defensive actions organized into implementation groups. Organizations often use the controls as a starting point before adopting a formal framework.
CMMC — The Department of Defense certification program for contractors that handle FCI and CUI. It is covered in detail in our CMMC Glossary Guide.
Federal Contracting & Regulatory
FAR (Federal Acquisition Regulation) — The primary rulebook for federal government purchasing. FAR clauses appear directly in government contracts.
DFARS — The Department of War supplement to the FAR. It contains Defense-specific acquisition and cybersecurity clauses.
FAR 52.204-21 — The basic safeguarding clause containing 15 requirements for systems that hold Federal Contract Information. It is the baseline requirement for nearly every federal contractor.
DFARS 252.204-7012 — Requires contractors to implement NIST SP 800-171, use cloud services that meet FedRAMP Moderate equivalency, and report covered cyber incidents to DoD within 72 hours.
DFARS 252.204-7019 / -7020 — The clauses requiring contractors to maintain a current NIST SP 800-171 self-assessment score in SPRS. They also give DoD the right to conduct higher-level assessments.
DFARS 252.204-7021 — The CMMC clause. Under the 48 CFR final rule effective November 10, 2025, it may appear in solicitations and make the specified CMMC level a condition of award.
DFARS 252.204-7025 — A newer clause addressing the identification and handling of covered information in defense contracts. Contractors should monitor it as the acquisition rules develop.
CUI (Controlled Unclassified Information) — Government-created or government-owned information that requires safeguarding under law or policy but is not classified. Handling CUI triggers many of the requirements described on this page.
FCI (Federal Contract Information) — Information provided by or generated for the government under a contract that is not intended for public release. It carries fewer requirements than CUI, but it still must be protected.
CDI (Covered Defense Information) — The term used in DFARS 252.204-7012 for the unclassified controlled technical and export-controlled information protected by the clause.
ITAR — Export-control regulations governing defense articles, services, and technical data. ITAR’s citizenship and access restrictions influence many enclave designs.
EAR — Export-control regulations covering dual-use commercial items and technology. EAR may apply alongside ITAR or in its place.
Flowdown — The transfer of contract requirements from a prime contractor to its subcontractors. Many small businesses first encounter compliance requirements through flowdowns.
Prime contractor / Subcontractor — The prime contractor holds the government contract directly. Subcontractors perform part of the work for the prime. Contract requirements travel down this chain.
SPRS (Supplier Performance Risk System) — The Defense system in which contractors post assessment scores and contracting officers check compliance status before award.
SAM.gov — The federal registration system that contractors must maintain to remain eligible for awards.
UEI (Unique Entity Identifier) — The government-issued identifier for entities registered in SAM.gov. It replaced the DUNS number.
CAGE Code — A five-character identifier assigned to facilities that do business with the federal government.
NAICS Code — An industry classification code used in procurement to categorize a business’s activities and determine set-aside eligibility.
ATO (Authorization to Operate) — A formal decision by a federal official to accept the risk of operating a system. It is the outcome of the RMF process and is normally valid for a limited period.
Impact Levels (IL2–IL6) — Defense cloud classifications based on data sensitivity. IL2 covers public and low-sensitivity data, IL4 covers CUI, IL5 covers higher-sensitivity CUI and national security systems, and IL6 covers classified information up to SECRET.
Let's Talk
1. Team Review
Our sales team reviews your submission within 1 business day.
2. Discovery Call
We schedule a 30-minute call to understand your specific situation.
3. Proposals
We provide proposals from the relevant C3PAO partners for your needs.
4. You Decide
No pressure. Compare proposals and choose what's right for you.