Skip to main content
Lightbridge Cloud A Lightbridge.ai company
SK Written by Sarika Krishnan with Robert LabardeeSenior Program Manager and Founder and CEO

Cloud and GovCon Glossary: Terms Defined by Lightbridge Cloud

Lightbridge Cloud maintains this glossary as a single index of the government-contracting cloud terms it defines across its guides and readiness services. Each entry gives a short, standalone definition and links to the page that covers it in depth, grouped into defense contractor compliance, data classification, government cloud environments, authorization artifacts, foreign ownership and export control, and data sovereignty and encryption.

This glossary is an index, not the deep content.

Government-contracting cloud compliance is dense with acronyms that guides tend to explain once, in passing, on the way to a bigger point. This page pulls each of those definitions into a single, groupable reference, so a reader can scan the vocabulary in one place and jump straight to the guide or service page that goes further.

Many of these terms are governed by a federal regulation or a DoD program (DFARS 252.204-7012, 32 CFR Part 117, the NIST SP 800-171 controls) and are not open to interpretation. Definitions and authorization criteria change over time. Verify any specific clause, threshold, or timeline against the official source, including acquisition.gov, the DoD CIO, NIST, the NARA CUI Registry, DCSA, and, for export controls, DDTC and BIS.

Defense contractor compliance terms, defined by Lightbridge Cloud

These terms form the ladder a defense contractor climbs from a contract clause to a verified security posture.

DFARS 252.204-7012

DFARS 252.204-7012 is the Defense Federal Acquisition Regulation Supplement clause that obligates a defense contractor to safeguard covered defense information and to report cyber incidents. It is the contractual trigger that pulls the NIST SP 800-171 control set into a contractor's obligations.

Read the full guide

NIST SP 800-171

NIST SP 800-171 is the federal standard of 110 security controls, organized into 14 families, that defines adequate protection for Controlled Unclassified Information on a non-federal system. It is the technical baseline that DFARS 252.204-7012 points to and that CMMC later verifies.

Read the full guide

CMMC (Cybersecurity Maturity Model Certification)

CMMC adds independent verification on top of the same NIST SP 800-171 baseline defense contractors already carry, with assessment levels that range from a self-assessment to a third-party review by an accredited C3PAO. It does not replace the underlying controls; it confirms them.

Read the full guide

SPRS (Supplier Performance Risk System)

SPRS is the DoD system where a contractor records the numeric score from its NIST SP 800-171 self-assessment, signaling how completely the 110 controls are implemented. Contracting officers can view the score, so it factors into eligibility for awards that carry the safeguarding clause.

Read the full guide

Data classification terms, defined by Lightbridge Cloud

These terms describe how sensitive government information is categorized and controlled without rising to a national security classification.

CUI (Controlled Unclassified Information)

CUI is government-created or government-owned information that a law, regulation, or government-wide policy requires to be safeguarded or have its dissemination controlled, without meeting the bar for national security classification. Executive Order 13556 established a single federal program for it, administered by the National Archives.

Read the full guide

CUI Basic vs CUI Specified

CUI Basic follows the CUI Program's default safeguarding and dissemination rules. CUI Specified applies when the authority behind a category prescribes its own stricter controls, and those authority-defined rules govern instead of the baseline. Reading the cited authority is what tells a handler which set of rules actually applies.

Read the full guide

Government cloud environment terms, defined by Lightbridge Cloud

These terms cover where a government workload is allowed to run and which cloud regions and authorizations apply.

DoD Impact Levels (IL2 through IL6)

DoD Impact Levels classify how sensitive a government workload is and what cloud controls it requires, running from IL2 for public and non-CUI data through IL6 for classified information up to SECRET. IL4 and IL5 cover most Controlled Unclassified Information and add dedicated boundary and tenant-separation requirements above commercial defaults.

Read the full guide

AWS GovCloud, Azure Government, and GCC High

AWS GovCloud, Azure Government, and Microsoft GCC High are isolated government cloud regions operated by vetted US persons, built to host Controlled Unclassified Information, ITAR-regulated data, and other workloads that carry elevated sovereignty and access requirements. Which one fits depends on the data category and Impact Level, not on vendor preference.

Read the full guide

FedRAMP

FedRAMP is the federal program that authorizes a cloud service offering, not an advisory firm, for sale across federal agencies. It is built on NIST SP 800-53 rather than NIST SP 800-171, and it assigns a Low, Moderate, or High baseline based on the sensitivity of the data the offering will process.

Read the full guide

Authorization and assessment artifact terms, defined by Lightbridge Cloud

These terms name the documents an assessor or authorizing official expects to see before granting a certification or authorization.

SSP (System Security Plan)

A System Security Plan documents how an organization or cloud offering implements each required security control, giving an assessor or authorizing official the evidence to evaluate before granting a certification or authorization. It underlies both CMMC assessment and FedRAMP authorization, built on the same NIST control families each program draws from.

Read the full guide

POA&M (Plan of Action and Milestones)

A Plan of Action and Milestones documents any control that is not yet fully implemented, along with the remediation steps and the timeline to close the gap. It pairs with the System Security Plan as the backbone of a defensible compliance posture, and it continues after FedRAMP authorization as part of ongoing continuous monitoring.

Read the full guide

Foreign ownership and export control terms, defined by Lightbridge Cloud

These terms govern who may own, influence, or access a cleared contractor and the controlled technical data it holds.

FOCI (Foreign Ownership, Control, or Influence)

FOCI describes the condition where a foreign interest holds enough ownership of, or sway over, a cleared US contractor that it could compromise classified or export-controlled work. The Defense Counterintelligence and Security Agency reviews and, where possible, mitigates FOCI under 32 CFR Part 117.

Read the full guide

Deemed export

A deemed export is the release of controlled technical data or source code to a foreign person located inside the United States, treated under both ITAR and the EAR as an export to that person's country of nationality. Granting system access or sharing a screen can trigger one without anything crossing a border.

Read the full guide

ITAR vs EAR

ITAR, administered by the State Department, governs defense articles and technical data on the United States Munitions List. The EAR, administered by Commerce, governs dual-use items on the Commerce Control List. Jurisdiction follows the item, and misclassifying which regime applies is the root of most export-control violations.

Read the full guide

Data sovereignty and encryption terms, defined by Lightbridge Cloud

These terms distinguish where data physically sits from who can be legally compelled to produce it, and the key-custody models that close the gap.

Data residency vs data sovereignty

Data residency is where data physically sits: the country or region storing and processing it. Data sovereignty is whose law governs that data and who can be lawfully compelled to disclose it. Data can reside in one country yet still be reachable under another country's law, typically through legal authority over the provider or over whoever holds the encryption keys.

Read the full guide

CLOUD Act

The US Clarifying Lawful Overseas Use of Data Act addresses how US legal process can reach data held by a service provider subject to US jurisdiction, regardless of where that data is physically stored. It is the main reason region pinning alone does not guarantee sovereignty, and why customer-held encryption keys are a common response.

Read the full guide

BYOK (Bring Your Own Key)

BYOK is a customer-managed key model where the customer generates or supplies key material and imports it into the provider's key management service, which still operates the keys day to day. It gives the customer provenance and rotation control, but the keys live inside the provider boundary, so the provider retains the technical ability to decrypt.

Read the full guide

HYOK (Hold Your Own Key)

HYOK, also called an external key store, keeps key material inside a customer-controlled hardware security module that never leaves that boundary. The provider must call out to the external store for every cryptographic operation, so it cannot decrypt data without the customer, at the cost of an added availability dependency.

Read the full guide

Note: several definitions above summarize a federal regulation, DoD program, or agency practice for readability. Where a definition and its underlying source could differ in edge cases, the source governs; consult the linked guide and qualified counsel before relying on any figure for a bid, an assessment, or a contract deliverable.

This glossary is independent, general educational information published by Lightbridge Cloud. It is not legal, audit, or accounting advice. Lightbridge Cloud is not FedRAMP authorized or CMMC certified, is not a C3PAO or 3PAO, and does not adjudicate FOCI or export-control determinations.

Cloud and GovCon glossary: frequently asked questions, answered by Lightbridge Cloud

What is a GovCon cloud glossary?
A GovCon cloud glossary is a reference list of the terms used across government-contracting cloud compliance, from the contract clauses and control standards that create an obligation to the environments, artifacts, and ownership rules that satisfy it. This glossary from Lightbridge Cloud indexes the terms it defines across its guides and readiness services, with a short definition and a link to the full page for each one.
What is the difference between DFARS, NIST SP 800-171, SPRS, and CMMC?
DFARS 252.204-7012 is the contract clause that creates the safeguarding obligation. NIST SP 800-171 is the 110-control standard that clause points to. SPRS is where a contractor records the self-assessment score measuring how completely those controls are implemented. CMMC adds independent verification on top of the same baseline, ranging from a self-assessment to a third-party assessment depending on the level required.
What is the difference between an SSP and a POA&M?
A System Security Plan (SSP) documents how each required control is actually implemented across an environment. A Plan of Action and Milestones (POA&M) documents any control that is not yet fully implemented, along with the remediation steps and timeline to close it. An assessor or authorizing official expects both: the SSP shows the current state, the POA&M shows the path to full compliance.
What is the difference between DoD Impact Levels and FedRAMP baselines?
DoD Impact Levels (IL2 through IL6) classify Department of Defense workloads and map them to a required cloud environment, from public data in IL2 to classified data up to SECRET in IL6. FedRAMP baselines (Low, Moderate, High) authorize a cloud service offering for federal agencies generally, built on NIST SP 800-53 rather than the NIST SP 800-171 controls behind the Impact Level framework. A cloud offering serving DoD workloads often has to satisfy both.
How does FOCI relate to ITAR and EAR?
FOCI, reviewed under 32 CFR Part 117, concerns whether a foreign interest's ownership or influence over a cleared US contractor could compromise access to classified information. ITAR and the EAR are a separate regime governing the export and transfer of controlled technology and technical data, including deemed exports to foreign persons inside the United States. A contractor under FOCI mitigation usually also has to manage deemed-export and technology-control obligations at the same time.
Where can I read the full definition behind a glossary term?
Every entry in this glossary links to the full Lightbridge Cloud guide or readiness service that covers the term in depth. This page is the index; the linked pages go to depth.

From vocabulary to a defensible readiness plan.

When the terms are settled and the real question is which environment and which artifacts your program needs, Lightbridge Cloud runs vendor-neutral GovCon readiness advisory, with no vendor kickbacks and no reseller quotas.