The UpCISO help centre
Clear answers for your
security programme.
Understand the terminology, prepare your evidence, and turn the next decision into a practical step.
18 guides
C3PAO
What is a C3PAO? Preparing for a CMMC assessment
A CMMC Third-Party Assessment Organization conducts independent CMMC assessments. UpCISO helps you prepare; it does not issue a certification.
Read guideSPRS
What is SPRS? Understanding your assessment score
The Supplier Performance Risk System is the government system holding assessment information. An UpCISO score is a preparation calculation, not a submission to SPRS.
Read guideSSP
What is an SSP? Building a System Security Plan
A System Security Plan describes the system boundary and how security requirements are implemented. Generating a draft does not prove the controls work.
Read guidePOA&M
What is a POA&M? Planning security remediation
A Plan of Action and Milestones records remediation work, owners and dates. Only specific unresolved requirements can support a conditional CMMC status.
Read guideCUI
What is CUI? Identifying and protecting government information
Controlled Unclassified Information is unclassified information subject to government safeguarding or dissemination controls. A document mentioning CUI is not necessarily CUI itself.
Read guideFCI
What is FCI? Federal Contract Information explained
Federal Contract Information is nonpublic information provided by or created for the government under a contract, with specified exclusions.
Read guideCMMC Level 1
CMMC Level 1: scope and self-assessment basics
CMMC Level 1 addresses basic protection of Federal Contract Information through self-assessment. Your contract determines the required level.
Read guideCMMC Level 2
CMMC Level 2: scope, evidence and assessment preparation
CMMC Level 2 addresses protection of CUI. The required self-assessment or third-party assessment route depends on the contract.
Read guideUnconfirmed
Security assessment findings: reported versus confirmed
A questionnaire answer records what you report. Confirmation records an assessor’s review against evidence; it is separate from saving an answer or approving a document.
Read guideNot applicable
When is a security requirement not applicable?
Use Not applicable only when a requirement or question genuinely does not apply, and record a reason. It is not a way to postpone unfinished work.
Read guideESP
What is an ESP? External Service Providers and CMMC scope
An External Service Provider supplies services your organisation relies on. Record the actual service, information handled and customer responsibilities.
Read guideCSP
What is a CSP? Cloud Service Providers and shared responsibility
A Cloud Service Provider supplies a cloud service. Assess the specific offering and your configuration, not just the provider’s brand.
Read guideFedRAMP
FedRAMP and CMMC: checking your cloud provider
FedRAMP provides a federal cloud security assessment framework. A provider’s status does not prove your own environment meets CMMC requirements.
Read guideEvidence
What counts as security assessment evidence?
Evidence supports a specific assessment conclusion. A file name, product name or policy draft alone does not show a control is operating.
Read guideConditional status
Conditional CMMC status: score thresholds and closeout deadlines
Conditional CMMC status has restricted eligibility and an official closeout deadline. A programme target or an 80% score threshold does not grant or extend that status.
Read guideTarget completion date
How to set a security programme target completion date
Your target completion date is a planning goal for the programme. Use it to organise roadmap work; it does not change contractual or official assessment deadlines.
Read guideIn progress
How to track security work in progress
In progress means work has started but is not yet complete. An estimated completion date supports planning and does not turn the answer into a met or confirmed finding.
Read guideReview cadence
How to plan recurring security reviews
Review cadence is how often you commit to checking controls, policies or providers. A review against one date differs from showing operation throughout a period.
Read guide