Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » Generic » CMMC Assessment Scope

CMMC Assessment Scope

Determining the scope of your CMMC assessment is a need for a successful certification process. It sets the groundwork by outlining what you need to evaluate. This approach reduces the assessment’s duration and minimizes the impact of security controls on your workforce.

This is why it is essential to account for every asset, whether within or outside the scope of the assessment, that processes Controlled Unclassified Information (CUI) or is not intended for nCUI processing. Disagreements about assessment scope can lead to certification delays. 

CMMC Self-Assessment

If you’re an Organization Seeking Compliance (OSC) aiming for CMMC Level 1 or a subset of Level 2 OSCs handling non-critical national security information, you can opt for a self-assessment. This means that your organization’s CMMC lead will conduct the assessment internally.

Level 1 Self-Assessment

Level 1 assessments evaluate how the OSC safeguards Federal Contract Information (FCI) using the 17 NIST 800-171 controls that apply to Level 1. To achieve Level 1 compliance, all objectives within these 17 controls must be met.

Level 2 Self-Assessment

Level 2 OSCs must assess against NIST 800-171 (A) and meet all 110 control assessment objectives. Success at this level requires a comprehensive System Security Plan (SSP) that details how policies, procedures, and technologies align with each assessment objective.

Both Level 1 and Level 2 OSCs need to perform self-assessments annually. They must also provide an annual affirmation from a senior company official confirming compliance with all requirements. These self-assessments and affirmations must be registered in the DoD’s Supplier Performance Risk System (SPRS).

Additional reading

Honest Delve Review 2026: Features, Pricing, Pros & Cons

TL;DR Built for first-time certifications, not recurring programs: Delve is fast and intuitive for SOC 2 or ISO 27001 first-timers, but teams managing multiple frameworks or complex governance structures will hit its ceiling. Pricing isn’t published and can surprise you: All quotes are custom, and community reports suggest costs can reach $12,000/year even for sub-10-person…

Enterprise Compliance: Turning Trust into a Growth Advantage

TL,DR: Enterprise compliance brings multiple standards, regulations, and business units into one operating program. It helps large teams prove trust across geographies, departments, customer reviews, and regulatory expectations. The article covers fast-changing rules, data sprawl, capacity constraints, and unified compliance management. Enterprises today compete on trust as much as they do on product features and…

11 Best Practices for PCI DSS Compliance

TL,DR: PCI DSS is a security standard established in 2004 by Visa, Mastercard, American Express, JCB, and Discover. A single non-compliance incident can cost over $500,000 with lasting brand damage Compliance levels depend on annual transaction volume: Level 1 (over 6 million), Level 2 (1 to 6 million), Level 3 (20,000 to 1 million), and…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.