From the Field · DIBCAC Assessments

What a DIBCAC Letter Starts: The First 30 Days

A High Assessment starts from the score you already filed. Here is how the first 30 days usually run, and what matters in each.

The letter

A DIBCAC notification means the Defense Contract Management Agency intends to conduct a High Assessment of how your company implements NIST SP 800-171. The authority for it is a clause most defense contractors have already signed: DFARS 252.204-7020 requires the contractor to provide access to its facilities, systems, and personnel for a Medium or High assessment. The pause in CMMC third-party assessments did not change this clause, and it did not stop these letters.

A High Assessment is performed by government assessors using NIST SP 800-171A. Under the clause, it consists of a review of your Basic Assessment, a thorough document review, verification and demonstration that your System Security Plan describes what is actually implemented, and discussions with your staff.

That first element frames everything that follows. The assessment starts from the score you already filed.

The self-assessment in SPRS, and the SSP it was based on, are the baseline the assessors test against. When the assessment is complete, DoD posts its own summary score to SPRS, next to yours, along with the date by which you expect to reach 110. Whatever distance exists between the two numbers becomes a government record.

The first 30 days after the letter decide most of that distance. The work falls into two phases.

Days 1 to 10: the SSP goes out first

The most important thing to understand about the schedule is its order. A copy of your System Security Plan is typically due to the assessment lead within roughly two weeks of notification, well before the coordination call and long before anyone arrives on site. The assessors will study that document before they study your environment. Whatever it claims becomes the standard you are measured against.

That compresses the most consequential work into the first ten days.

Pull what you filed. Get the SPRS entry, the date it was entered, and the SSP and plan of action it was based on. In many companies the person who entered the score has moved on, or the environment has changed since. Establish exactly what was represented, and when. Expect the letter to ask you to confirm your CAGE codes and Basic Assessment information on a signed form.

Settle the boundary. Confirm which systems, locations, people, and service providers handle CUI, and draw the data flow. Most difficult assessments trace back to a boundary the company never pinned down: CUI in an email system the SSP says is out of scope, or a cloud provider no one checked.

Re-score honestly. Walk the 110 requirements against the environment as it exists today, not as the SSP describes it, using the same weighting the assessors will use.

Make the SSP describe reality before it leaves the building. Where the plan overstates, correct it. Where the environment falls short, say so and give a dated fix. A plan that honestly shows a gap is stronger than one that claims a control no one can demonstrate.

Decide who is involved. If the honest re-score is close to the filed score, this is a readiness project. If it is materially lower, it is also a question about a past representation, and that conversation belongs with counsel before the SSP is sent. Either way, name one internal owner with the authority to pull people and systems into the effort.

Days 11 to 30: build toward the milestones

After the SSP, the rest of the pre-assessment schedule usually runs on fixed intervals counted back from the assessment date. Expect a coordination call with the assessment lead roughly five weeks out, a secure file transfer for evidence a couple of weeks out, and a deadline for any additional documentation about a week before the team arrives. The assessment itself is generally on site, with some portions done virtually. Use the weeks between to prepare for each.

Come to the coordination call with answers. The call confirms scope, logistics, and who the assessors will need to speak with. Treat it as the first impression of your program. Know your boundary, your data flows, and your open plan of action items well enough to discuss them without looking them up.

Organize evidence by assessment objective. NIST SP 800-171A breaks the 110 requirements into 320 objectives, and the assessors work from those. For each objective, know what artifact, configuration, or demonstration proves it and who will show it. When the transfer request arrives, the package should already exist.

Prepare for demonstration, not presentation. A High Assessment verifies and examines. Expect to be asked to open a configuration, run a report, or walk through a process live. The people who operate the controls should rehearse showing them. Prepared answers matter less than administrators who know their own systems.

Build a plan of action you can keep. Any requirement not met on assessment day needs a realistic closure date, because that date goes into SPRS with your score. Optimistic dates that slip become their own record.

What does not help

Three reactions are common in the first weeks, and none of them improve the outcome.

  • Rewriting the SSP to read better than the environment. It widens the gap the assessment is designed to find, and it creates a new document that overstates.
  • Buying tools in a hurry. A tool deployed three weeks before an assessment rarely has the configuration history, procedures, or trained operators to demonstrate a control.
  • Treating it as an IT project. Several requirements are about people, training, physical access, and incident handling. The assessors will talk to more than the IT team.

After the assessment

The assessment closes with an out-brief from the team. The clause then gives the contractor 14 business days to provide additional information showing it meets requirements the team did not observe, or to rebut findings. Final results typically follow within about two months, and DoD posts the summary score to SPRS with your projected date for reaching 110. From that point, the score and the plan of action are the record DoD sees when it evaluates your offers and your later affirmations.

Companies that come through well tend to have one thing in common. They treated the assessment as a demonstration of what they already do every day, and they spent the first 30 days making sure that was true.

If you have received a letter

We have been through DIBCAC from your side of the table.

Our CEO led the contractor team through two DIBCAC assessments, and our President served as the contractor's Affirming Official on both. We work to the dates in your letter.

Readiness sprint

A fixed fee, with milestones tied to your DIBCAC dates. The honest re-score, boundary and data flow, SSP correction, evidence organized by assessment objective, a mock assessment, and on-site support before and during the assessment.

After the assessment

Monthly support until your plan of action items are closed and validated.

Ongoing

Continuous Compliance keeps the program current, so your annual affirmation rests on evidence rather than memory.

We can also work at the direction of your counsel.

What happens when you contact us: a response within one business day, then a 30-minute meeting to review your letter, your filed score, and your dates. The meeting is confidential and carries no obligation.

Tell us your dates

Please do not include CUI or copy text from your letter. The dates are enough to start.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

An independent firm focused exclusively on NIST 800-171 compliance for defense contractors and the DIB.

Fredericksburg, VA