1. CM means those devices are for Cloud-Managed infrastructure, or Aruba Central. If you only want home use, I would avoid this model, because it is designed for users that already have an Aruba Central account.
2. You definitely want an IAP (Instant AP), because those can be used without a separate hardware controller, and converted to controller-based if necessary. The regular AP CANNOT be converted to work without a controller. Stick with the IAP variant and you will not go wrong. If you are in the US, look for IAP-305-US. If you are outside of the US, I would look for the IAP-305-RW.
3. FIPS/TAA hardware are manufactured in Either US or Singapore and have tamper-resistant labels on them.
I hope that answers some of your questions.