The federal vocabulary, decoded.
30 terms a technology company hits in its first year of federal — compliance programs, registrations, contract vehicles, set-asides. Every entry says what the term is, what it costs you to ignore, and which of the 12 Federal Readiness Score categories it feeds.
02 — BROWSE
#
- 3PAO
An accredited independent firm that tests whether a cloud service actually implements the security controls it claims, producing the evidence an authorizing official relies on.
Compliance Posture Also called Third Party Assessment Organization, FedRAMP Recognized assessor
- 8(a) Business Development Program
A nine-year Small Business Administration program for socially and economically disadvantaged small firms, carrying set-aside and limited sole-source contracting authority.
Certifications & Set-Asides Also called 8(a), SBA Business Development Program
A
- ATO
A federal official's formal, signed decision that a system may operate with government data, accepting the residual security risk on the agency's behalf.
Compliance Posture Also called Authority to Operate, Authorization to Operate
- Authorization Boundary
The explicit line around everything a security authorization covers — the components, services, and data flows an assessor will test and an official will accept risk on.
Product Architecture Also called System boundary, Accreditation boundary
B
- BPA
A standing arrangement with pre-agreed terms that lets an agency place repeat orders for recurring needs without negotiating each one.
Contract Vehicle Strategy Also called Blanket Purchase Agreement
C
- CAGE Code
A five-character code identifying a specific legal entity at a specific physical location, used across federal contracting, logistics, and security systems.
Registration & Identity Also called Commercial and Government Entity Code, NCAGE
- CIO-SP4
The fourth-generation NITAAC government-wide acquisition contract for information technology services, and one of the most heavily contested federal procurements of recent years.
Organizational Capability Also called Chief Information Officer Solutions and Partners 4, NITAAC CIO-SP4
- CMMC
The Department of War program that verifies whether a defense contractor has actually implemented required cybersecurity safeguards before it can be awarded applicable work.
Compliance Posture Also called Cybersecurity Maturity Model Certification
- CMMC Level 2
The CMMC tier for contractors handling Controlled Unclassified Information, assessed against the NIST SP 800-171 requirement set by self-assessment or by an authorized third-party assessor.
Compliance Posture Also called CMMC L2
- CUI
Unclassified government information that still requires safeguarding or dissemination controls under law, regulation, or government-wide policy.
Product Architecture Also called Controlled Unclassified Information
D
- DFARS 252.204-7012
The defense contract clause that requires contractors to implement NIST SP 800-171 on systems holding covered defense information and to report cyber incidents within 72 hours.
Compliance Posture Also called Safeguarding Covered Defense Information and Cyber Incident Reporting, the 7012 clause
F
- FedRAMP
The government-wide program that standardizes how cloud products are security-assessed, authorized, and continuously monitored for federal use.
Compliance Posture Also called Federal Risk and Authorization Management Program
- FedRAMP 20x
The modernized FedRAMP authorization path that replaces narrative security packages with machine-readable evidence and a class-based certification model.
Compliance Posture Also called 20x, FedRAMP Consolidated Rules
- FedRAMP Moderate
The FedRAMP impact level for systems where a breach would cause serious adverse effect, and the level most federal SaaS purchases actually require.
Compliance Posture Also called Moderate baseline, FedRAMP Class C
G
- GSA Schedule
A long-term government-wide contract with pre-negotiated terms and pricing that lets any federal agency buy from a company without running a full open competition.
Contract Vehicle Strategy Also called Federal Supply Schedule, GSA contract
- GWAC
A task-order contract for information technology established by one agency and made available for the whole federal government to buy through.
Contract Vehicle Strategy Also called Government-Wide Acquisition Contract
I
- IDIQ
A contract that sets terms, a guaranteed minimum, and a ceiling without committing the government to a specific quantity, with actual work ordered later.
Contract Vehicle Strategy Also called Indefinite Delivery Indefinite Quantity
M
- MAS
The single consolidated GSA schedule program, organized into large categories and Special Item Numbers, that replaced the government's separate legacy schedules.
Contract Vehicle Strategy Also called Multiple Award Schedule, Consolidated Schedule
N
- NAICS
The six-digit industry classification system federal buyers use to categorize what they are buying, and the basis for deciding whether a company counts as small.
Market Fit & TAM Also called North American Industry Classification System, NAICS code
- NIST SP 800-171
The federal standard specifying how a private organization must protect Controlled Unclassified Information on its own systems, and the requirement set CMMC assessments are built on.
Compliance Posture Also called SP 800-171, Protecting CUI in Nonfederal Systems
O
- OASIS+
GSA's family of multiple-award contracts for professional services, organized into domains and separate small-business tracks, with periodic on-ramps for new holders.
Contract Vehicle Strategy Also called One Acquisition Solution for Integrated Services Plus
P
- PSC
The four-character code on a federal award describing what the government bought, as distinct from the industry code describing who sold it.
Market Fit & TAM Also called Product Service Code, Federal Supply Classification
S
- SAM.gov
The government's single registration system for entities that want federal awards, and the authoritative public record of who a contractor is.
Registration & Identity Also called System for Award Management
- SBIR
A federal program that funds small-business research and development in phases, and creates a sole-source path to production contracts for the resulting technology.
Past Performance Also called Small Business Innovation Research, SBIR/STTR
- SDVOSB
A small business at least 51 percent owned and controlled by one or more service-disabled veterans, now requiring formal government certification rather than self-certification.
Certifications & Set-Asides Also called Service-Disabled Veteran-Owned Small Business, VOSB
- Set-Aside
A procurement reserved for competition among a defined class of businesses, so that firms outside that class cannot compete for it at all.
Certifications & Set-Asides Also called Small business set-aside, Reserved procurement
- SEWP
A NASA-managed government-wide acquisition contract that agencies use to buy information technology products and product-based solutions quickly.
Channel & Partnership Readiness Also called Solutions for Enterprise-Wide Procurement
- SPRS
The government-only Department of War system that holds supplier risk and performance data, including the cybersecurity assessment scores defense contractors are required to post.
Past Performance Also called Supplier Performance Risk System
T
- Task Order
An individual order for work placed against an existing indefinite-delivery contract, where the actual money and the actual performance happen.
Past Performance Also called Delivery Order
U
- UEI
The twelve-character identifier the government assigns to a registered entity, used across every federal award, payment, and reporting system.
Registration & Identity Also called Unique Entity ID, Unique Entity Identifier
03 — WHY THIS GLOSSARY
Most federal glossaries stop at the definition. Every entry here ends with the same question a buyer actually has: what does this change about my readiness? That answer names a specific scored category, and it links to the open methodology where that category is described — so a definition turns into a next step instead of trivia.
Terms are reviewed on a rolling basis and each entry carries the date it was last reviewed. Where a rule has a live date attached, the entry says the date and where the government published it.