Skip to main content
Category: CMMC & DIB Assessment

Defense Industrial Base Cybersecurity Assessment Center

Also known as: DIBCAC, Defense Industrial Base Cybersecurity Assessment Center, DCMA DIBCAC
Simply put

DIBCAC is a Department of Defense organization that reviews whether defense contractors are meeting the government's cybersecurity requirements. It examines a contractor's security practices, identifies weaknesses, and evaluates how well the contractor protects sensitive defense information. Its assessments help the DoD gauge the cybersecurity posture of companies in the defense supply chain.

Formal definition

The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) is a specialized unit within the Defense Contract Management Agency (DCMA) that conducts assessments of defense contractors' cybersecurity practices against applicable DFARS requirements. According to the evidence provided, DIBCAC evaluates contractors' compliance and conducts comprehensive reviews of an organization's cybersecurity infrastructure to identify weaknesses and recommend improvements. Note that the specific scope, methodologies, and the interplay between DIBCAC assessments and the CMMC program (including any role in CMMC Level 3 or Joint Surveillance/High assessments) are not detailed in the evidence packet and should be verified against current authoritative sources such as the official DCMA DIBCAC site and applicable regulations (for example, 32 CFR Part 170). Readers should also confirm current DFARS clause references and program requirements directly, as these are subject to revision.

Why it matters

For companies in the defense supply chain, DIBCAC represents the Department of Defense's own eyes on contractor cybersecurity. Rather than relying solely on contractor self-attestation, the DoD uses DIBCAC to independently evaluate whether organizations handling sensitive defense information are actually meeting applicable DFARS cybersecurity requirements. This matters because a gap between what a contractor claims and what a DIBCAC assessment finds can affect a company's standing with the department and expose weaknesses in how it protects government information.

The center's role also underscores an important distinction that compliance officers should keep in mind: assessment is not the same as authorization, and compliance is not the same as security. A DIBCAC assessment is a point-in-time review of an organization's cybersecurity infrastructure intended to identify weaknesses and recommend improvements. It does not, by itself, guarantee that a contractor's environment remains secure over time, and it should not be treated as a one-and-done exercise. Contractors are generally expected to maintain and continuously improve their security posture rather than treat a favorable assessment as a permanent status.

Because the specific scope, methodologies, and the interplay between DIBCAC assessments and the CMMC program are evolving and are not fully detailed here, readers should treat any high-stakes decision as requiring confirmation against current authoritative sources. The consequences of misjudging one's obligations, or of assuming a past assessment still reflects current requirements, can be significant for eligibility to hold or compete for defense work.

Who it's relevant to

Defense contractors and subcontractors
Companies that handle sensitive defense information and are subject to applicable DFARS cybersecurity requirements are the primary subjects of DIBCAC assessments. These organizations should understand that a DIBCAC review evaluates their actual practices, not just their stated intentions, and should confirm current requirements and clause references directly against authoritative sources.
Compliance officers and ISSMs
Those responsible for maintaining and demonstrating cybersecurity compliance in defense-facing organizations need to prepare for and respond to DIBCAC assessments. They should treat any assessment as a point-in-time evaluation that identifies weaknesses to remediate, and should maintain security posture on an ongoing basis rather than treating a past result as a permanent qualification.
Auditors and assessors
Professionals who evaluate contractor cybersecurity should understand DIBCAC's role as a DoD organization within DCMA that assesses compliance against DFARS requirements. They should distinguish DIBCAC's assessment function from other frameworks and verify the current interplay between DIBCAC and related programs against official sources.
Contract and acquisition personnel
Those managing defense contracts benefit from understanding that DIBCAC helps the DoD gauge the cybersecurity posture of supply chain participants. Because governing clauses and program requirements are subject to revision, acquisition staff should confirm current applicable requirements rather than relying on prior assumptions.

Inside DIBCAC

Organizational placement under DCMA
The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) is an organization within the Defense Contract Management Agency (DCMA), which operates under the U.S. Department of Defense. Readers should verify the current organizational structure and mission scope against official DCMA sources, as reporting relationships and responsibilities can change.
Assessment of NIST SP 800-171 implementation
DIBCAC's core function generally involves assessing defense contractors' implementation of the security requirements in NIST SP 800-171, which apply to the protection of Controlled Unclassified Information (CUI) in nonfederal systems as invoked through DFARS clause 252.204-7012 and related DFARS provisions. The specific clause references and applicable revision of NIST SP 800-171 should be confirmed against current contractual and regulatory text.
Types of assessments performed
DIBCAC conducts assessments of contractor cybersecurity posture, which in most implementations include reviews aligned to the DoD Assessment Methodology for NIST SP 800-171. Practitioners should confirm the current catalog of assessment types, their scoring approach, and their scheduling (including whether an assessment is contractor-requested or DoD-directed) against official DoD and DCMA guidance.
Role within the CMMC program
Under the Cybersecurity Maturity Model Certification (CMMC) program, DIBCAC is designated within DoD as the organization responsible for conducting CMMC Level 3 certification assessments. It is also associated with higher-level assessment activity that, depending on program rules and applicable revision, may relate to Level 2 outcomes. Because CMMC is being implemented on a phased basis and its requirements are set out in 32 CFR Part 170 and related DoD issuances, readers should verify DIBCAC's current CMMC responsibilities against those authoritative sources.
Relationship to authorization decisions
DIBCAC performs assessment functions; assessment is distinct from authorization or certification decisions and from the contractual actions that flow from an assessment result. The scope of what a DIBCAC assessment produces (for example, a score, findings, or a certification outcome under CMMC) depends on the assessment type and should be confirmed against current DoD guidance.

Common questions

Answers to the questions practitioners most commonly ask about DIBCAC.

Is DIBCAC outside the CMMC program, or does it play a role in CMMC assessments?
DIBCAC is not outside the CMMC program. The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), part of the Defense Contract Management Agency (DCMA), is designated within the DoD CMMC framework as the organization responsible for conducting CMMC Level 3 assessments. It also conducts higher-assurance government-led assessments that, under applicable DoD guidance, may relate to Level 2 outcomes. Readers should verify the current scope of DIBCAC's CMMC role against 32 CFR Part 170 and official DCMA/DIBCAC sources, since CMMC is being implemented in phases and details may change across revisions.
Does DIBCAC only perform voluntary or self-selected assessments?
No. DIBCAC conducts government-led assessments of defense contractors and subcontractors, and it schedules assessments as part of DoD oversight rather than solely at a contractor's election. In addition to its assessment activity supporting NIST SP 800-171 implementation verification, DIBCAC performs CMMC Level 3 assessments and leads higher-assurance government-led assessments. The specific triggers, prioritization, and selection criteria for a given assessment are governed by current DoD policy and contract terms, which a reader should confirm against authoritative sources for their situation.
How does a contractor prepare for a DIBCAC-led assessment?
Preparation generally centers on demonstrating implementation of the applicable security requirements, commonly NIST SP 800-171 for CUI protection under DFARS clause 252.204-7012, supported by a System Security Plan (SSP) and, where gaps exist, a Plan of Action and Milestones (POA&M). Contractors typically assemble evidence, artifacts, and documentation showing each requirement is implemented as described. Because assessment scope, evidence expectations, and any CMMC-specific requirements depend on the assessment type and the current revision of governing guidance, contractors should confirm the exact requirements applicable to their assessment against official DoD and DIBCAC sources.
What is the difference between a DIBCAC assessment and a contractor self-assessment?
A self-assessment is performed by the contractor against the applicable requirements and, for NIST SP 800-171, may be reported through the mechanism specified by DoD guidance. A DIBCAC-led assessment is a government-conducted review that provides independent verification rather than self-attestation, and it generally carries greater assurance weight in DoD oversight. It is important not to equate a self-assessment score with an independent assessment outcome. The precise reporting, scoring methodology, and how each is used should be verified against current DoD guidance.
Does a DIBCAC assessment result satisfy CMMC requirements automatically?
Not automatically for all levels. The relationship between a given DIBCAC assessment and CMMC requirements depends on the assessment type and the applicable CMMC level. DIBCAC conducts CMMC Level 3 assessments and leads certain higher-assurance government-led assessments that, under DoD guidance, may relate to Level 2 outcomes. Whether a particular result satisfies a specific CMMC requirement should be confirmed against 32 CFR Part 170 and current CMMC program guidance, as terms and mappings continue to be implemented in phases.
How should a contractor handle findings or gaps identified during a DIBCAC assessment?
Identified gaps are generally documented and remediated through a Plan of Action and Milestones (POA&M) or equivalent remediation tracking, subject to any limits on which requirements may be addressed via POA&M under the applicable framework. Not all requirements are eligible for deferral, and the acceptability and timelines for remediation depend on the governing guidance and contract terms. Contractors should confirm which findings must be fully implemented versus which may be remediated over time against the current authoritative requirements applicable to their assessment.

Common misconceptions

DIBCAC is outside the CMMC program and only assesses NIST SP 800-171 scores.
In addition to NIST SP 800-171 assessment activity, DIBCAC is designated within DoD to conduct CMMC Level 3 certification assessments and is associated with higher-level assessment activity that may relate to Level 2 outcomes under the phased CMMC program. Because CMMC requirements and DIBCAC's precise responsibilities are being implemented in phases under 32 CFR Part 170, the reader should verify current roles against official DoD and DCMA sources.
A DIBCAC assessment or a favorable score is a permanent statement of compliance.
Assessment results reflect a point-in-time evaluation against the applicable requirements and revision. Cybersecurity obligations for CUI are ongoing, and a score or certification outcome does not eliminate continuous responsibilities. Practitioners should treat any result as time-sensitive and subject to change as requirements, systems, and applicable revisions evolve.
Assessment by DIBCAC is the same as authorization or certification, and a passing result satisfies all DoD cybersecurity requirements.
Assessment is distinct from authorization and certification decisions and from the contractual actions that follow. A given DIBCAC assessment addresses specific requirements (for example, NIST SP 800-171 or a particular CMMC level) and does not automatically satisfy other, separately governed requirements. Readers should confirm what a specific assessment covers and what obligations remain.

Best practices

Confirm which requirement set applies to your contract (for example, NIST SP 800-171 via DFARS 252.204-7012 versus a specific CMMC level under 32 CFR Part 170) and the applicable revision before preparing for any DIBCAC assessment.
Verify DIBCAC's current assessment types, scope, and scheduling directly against official DCMA and DoD sources rather than relying on prior-cycle assumptions, since roles and processes are being implemented on a phased basis.
Treat any DIBCAC assessment result as point-in-time and maintain ongoing cybersecurity practices, recognizing that a score or certification outcome does not create a permanent state of compliance.
Distinguish between assessment activity and the authorization, certification, and contractual actions that may follow, and confirm what a specific assessment does and does not cover.
Do not assume that satisfying one requirement set (such as a NIST SP 800-171 score) automatically satisfies separately governed CMMC or other DoD requirements; validate each obligation independently.
Consult current official DoD, DCMA, and CMMC program text for clause numbers, effective dates, and level-specific criteria before making compliance or contractual decisions.