CMMC Partner Assurance Network (CPAN) Glossary

Advisory

Deliver strategic CMMC advisory services, including gap assessments, SSP/POA&M development, remediation roadmaps, and hands-on implementation support to help organizations prepare for audits and sustain compliance.

CMMC Third-Party Assessment Organizations (C3PAOs)

Conduct official CMMC assessments, including mock assessments, readiness reviews, and formal certification determinations in accordance with DoD and Cyber Accreditation Body requirements.

Legal & Compliance Advisors

Provide legal guidance on DFARS, CUI handling, contractual obligations, incident response, and regulatory compliance to ensure organizations meet CMMC requirements while managing legal and contractual risk.

Insurance Providers & Risk Advisors

Offer cyber insurance, professional liability coverage, and risk assessments aligned with CMMC controls, helping organizations reduce financial exposure and meet insurer and DoD expectations.

Managed Service Providers (MSPs)

Design, implement, and manage compliant IT infrastructure, networks, and security controls that support ongoing CMMC requirements across environments.

Managed Security Service Providers (MSSPs)

Deliver continuous security monitoring, incident detection and response, log management, and SOC services aligned with CMMC control requirements.

Cloud Service Providers (CSPs)

Provide secure, FedRAMP-authorized or CMMC-aligned cloud environments for hosting CUI and supporting Moderate/High security requirements.

Cybersecurity Tool Vendors

Supply CMMC-relevant security technologies such as endpoint protection, SIEM, vulnerability management, identity and access management, encryption, penetration testing, and data protection tools.

Continuous Monitoring /GRC Platforms

Enable automated control tracking, evidence collection, risk management, reporting, and audit readiness through CMMC-aligned GRC and continuous compliance platforms.

System Integrators (SIs)

Architect, integrate, and deploy secure IT and cybersecurity solutions that align with CMMC requirements across on-premises, hybrid, and cloud environments.

Authorized Training Providers (ATPs)

Deliver official CMMC curriculum and certification training for practitioners, assessors, and organizational staff as authorized by the CMMC ecosystem.

Cybersecurity Training Vendors

Provide role-based security awareness, technical training, and workforce education to support CMMC.

Workforce Alignment

CMMC cybersecurity-ready workforce aligned to your organizational needs

End-to-End Solution

Offer integrated, turnkey CMMC compliance solutions spanning advisory, technology, implementation, monitoring, training, and assessment readiness.

Data Centers

Provide secure, compliant hosting environments capable of supporting CMMC requirements for sensitive data, including CUI storage and processing.