Defense-acquisition, contracting, and compliance terms every defense-tech founder should know — DARPA, SBIR, CMMC, ITAR, and more. 16 terms defined.
CFIUS
The U.S. interagency committee that reviews foreign investment in American companies for national-security risk.
Also: Committee on Foreign Investment in the United States
CMMC
The Department of Defense's framework for verifying that a contractor's IT systems protect sensitive government data.
Also: Cybersecurity Maturity Model Certification · CMMC compliance · CMMC certification · CMMC 2.0
CPARS
The U.S. government's official database of contractor performance report cards, used to award future contracts.
Also: Contractor Performance Assessment Reporting System
DARPA
The U.S. Department of Defense's high-risk, high-reward research agency, created in 1958 to prevent technological surprise.
Also: Defense Advanced Research Projects Agency
Defense Base Act (DBA)
A federal law that requires workers' compensation-type coverage for employees working outside the U.S. on U.S. government contracts.
Also: DBA · Defense Base Act insurance · DBA workers compensation
DFARS 252.204-7012
The DoD contract clause that requires defense contractors to safeguard sensitive information and report cyber incidents within 72 hours.
Also: DFARS 7012 · Safeguarding Covered Defense Information and Cyber Incident Reporting
DoD Impact Levels (IL)
The Department of Defense's system for classifying how sensitive cloud-hosted government information is, ranging from IL2 (low-sensitivity unclassified) up to IL6 (classified up to and including SECRET).
Also: dod impact levels · impact level 5 · IL5 · IL4 · dod il4 · dod cloud impact levels
EAR
The U.S. export-control rules for "dual-use" and less-sensitive military items — the commercial-side counterpart to ITAR.
Also: Export Administration Regulations · EAR compliance
FedRAMP
The U.S. government's standardized security-authorization program for cloud products and services sold to federal agencies.
Also: Federal Risk and Authorization Management Program · FedRAMP levels · FedRAMP impact levels · FedRAMP Low · FedRAMP Moderate · FedRAMP High · FedRAMP authorization levels
GSA Schedule
Long-term, government-wide contracts GSA pre-negotiates with vendors so agencies can buy at set prices without a full bid.
Also: Multiple Award Schedule · MAS · Federal Supply Schedule
IDIQ Contract
A flexible federal contract vehicle for an indefinite quantity of supplies or services within stated limits over a fixed period.
Also: Indefinite-Delivery, Indefinite-Quantity contract
ITAR
The U.S. export-control rulebook governing defense-related technology, hardware, and technical data on the U.S. Munitions List.
Also: International Traffic in Arms Regulations · ITAR compliance
NDAA
The annual U.S. law that sets defense policy and authorizes Department of Defense spending levels.
Also: National Defense Authorization Act
NIST SP 800-171
The NIST standard that defines how to protect Controlled Unclassified Information on non-government systems — the control baseline behind DFARS 7012 and CMMC.
Also: NIST 800-171 · NIST Special Publication 800-171
SBIR
A U.S. program that gives small businesses non-dilutive federal R&D funding — no equity or IP taken — to mature new technology.
Also: Small Business Innovation Research · SBIR grant · SBIR program
Section 889
A federal law banning the government from buying or using certain Chinese-made telecom and surveillance equipment — and from contracting with companies that use it.
Also: Section 889 NDAA · covered telecommunications prohibition
Definitions are educational and may be modified by your specific policy language, endorsements, and state rules. For regulatory guidance, refer to the California Department of Insurance or the NAIC.