FAQ
Plain-English answers to common compliance, security, and industrial control terms.
Compliance & Security Standards
CMMC Level 1 (Cybersecurity Maturity Model Certification – Foundational)
Basic cybersecurity practices required for organizations handling Federal Contract Information (FCI), focusing on essential cyber hygiene.
CMMC Level 2 (Cybersecurity Maturity Model Certification – Advanced)
Advanced cybersecurity requirements for organizations handling Controlled Unclassified Information (CUI), aligned with NIST 800-171 security controls.
Common compliance requirements in government environments
Common compliance requirements in government environments include:
- CJIS (Criminal Justice Information Services) – Security requirements established by the FBI to protect sensitive criminal justice and law enforcement information.
- CMMC (Cybersecurity Maturity Model Certification) – A Department of Defense certification program that verifies a contractor's cybersecurity practices and compliance readiness.
- CUI (Controlled Unclassified Information) - CMMC Level 2 – Protects sensitive government information that requires stronger security controls but is not classified.
- DFARS (Defense Federal Acquisition Regulation Supplement) – Cybersecurity requirements for companies working with the U.S. Department of Defense and handling sensitive government data.
- FCI (Federal Contract Information) - CMMC Level 1 – Protects federal contract information that is not intended for public release through basic cybersecurity practices and access controls.
- FedRAMP – A U.S. government security standard that ensures cloud services meet strict requirements for data protection, risk management, and security controls.
- HIPAA (Health Insurance Portability and Accountability Act) – Federal regulations that protect patient health information and require safeguards for healthcare data privacy and security.
- ITAR (International Traffic in Arms Regulations) – Regulations that govern the handling, storage, and sharing of defense-related and export-controlled information.
- NIST 800-171 – A cybersecurity framework that defines how organizations must protect Controlled Unclassified Information (CUI).
- PCI DSS (Payment Card Industry Data Security Standard) – A security standard that helps businesses protect credit card and payment information from unauthorized access and fraud.
DFARS (Defense Federal Acquisition Regulation Supplement)
DFARS is a set of cybersecurity and contracting requirements issued by the U.S. Department of Defense (DoD) for companies that do business with the DoD. If a company stores, processes, or transmits Controlled Unclassified Information (CUI) for the DoD, it must comply with DFARS cybersecurity requirements.
GRC (Governance, Risk & Compliance)
A structured approach to managing organizational policies, risks, regulatory requirements, and compliance activities.
HIPAA Compliance (Health Insurance Portability and Accountability Act)
HIPAA is a U.S. law that protects sensitive patient health information.
ISO 27001 (Information Security Management Standard)
The international standard for information security management, ensuring sensitive data is protected through documented security controls and risk management.
Microsoft 365 Government
Microsoft 365 Government is a special version of Microsoft 365 designed for:
- U.S. Federal agencies
- State and local governments
- Tribal governments
- Government contractors handling regulated government data
PCI Compliance (Payment Card Industry Data Security Standard – PCI DSS)
PCI DSS is a security standard for organizations that process, store, or transmit credit card data.
SOC 2 (System and Organization Controls 2)
An independent audit framework that verifies an organization has controls in place to protect customer data, covering security, availability, and privacy.
SPRS Scoring – Measures implementation of NIST 800-171 controls and helps demonstrate readiness for CMMC Level 2 certification and DoD contracts.
The SPRS score is a numeric score that measures how well an organization complies with the 110 security controls in NIST 800-171.
Contractors handling CUI are generally required to submit their assessment results into the Department of Defense's SPRS database. Organizations start at 110 and lose points for each unmet security requirement.
- Perfect Score: 110
- Typical Starting Score: Can be negative if many required controls are missing
- Minimum Possible Score: −203
Common Requirements Affecting SPRS Scores
- Multi-Factor Authentication (MFA)
- Access Control
- Security Awareness Training
- Audit Logging
- Incident Response
- Vulnerability Management
- Encryption
- Backup and Recovery
- Risk Assessments
Industrial Control Systems (OT)
DCS (Distributed Control System)
A DCS is designed for large continuous industrial processes where many controllers work together.
PLC (Programmable Logic Controller)
A PLC is an industrial computer that directly controls equipment.
SCADA (Supervisory Control and Data Acquisition)
SCADA is software that monitors and controls industrial processes.
Discovery Meeting for Compliance Evaluation
Compliance Scoping Meeting
- Determine which CMMC Level (1 or 2) your organization is preparing for
- Identify whether Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) exists within the organization
- Define the compliance boundary
- Assess the effort required to achieve and maintain the appropriate compliance level
Possible Outcome
- CMMC Level 1 or Level 2?
- FCI or CUI?
- Other organizational, industrial, or informational compliances
- In-scope users?
- In-scope servers and applications?
- Existing controls already in place?
- Gap assessment needed?
- Estimated remediation effort?
CMMC Level 1 or Level 2
Defense industrial base and support programs with references to Department of Defense approvals and defense manufacturing.
- Industrial Control Systems (OT): PLC, SCADA, DCS
- Communication and Cloud: FedRAMP, Microsoft 365 Government
- Information Security and Governance: ISO 27001, SOC 2, GRC
- Other: PCI or HIPAA
1. Do You Handle FCI or CUI?
Do you receive, process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) from the DoD or prime contractors?
- FCI requires CMMC Level 1.
- CUI requires CMMC Level 2 and compliance with NIST 800-171.
2. Understand Defense Contracts
- Are you a direct DoD contractor or a subcontractor?
- What contract numbers do you currently have?
- Has any customer requested NIST 800-171 compliance?
- Has any customer required SPRS scoring?
- Have you seen DFARS clauses in your contracts?
Key clauses include:
- DFARS 252.204-7012
- DFARS 252.204-7019
- DFARS 252.204-7020
- DFARS 252.204-7021
3. Compliance Boundary
- Number of users
- Number of servers
- Microsoft 365 licensing
- Engineering systems
- File shares
- ERP/MRP systems
- CAD systems
- Manufacturing systems
- Remote access methods
- Vendors with access
Which systems contain or touch DoD-related information?
4. Review Existing Security Controls
- MFA enabled?
- Endpoint protection?
- Server patching?
- Backup and disaster recovery?
- Email security?
- Security awareness training?
- Vulnerability management?
- Log retention?
- Incident response procedures?
