← All Articles
Strategic

What Ten Weeks Before a DIBCAC Assessment Taught Me

A DIBCAC High assessment checks what you said against what you do. Notes on the weeks after the letter, from the contractor side of two of them.

KE
Brian Stack
September 27, 2026
7 min read

I have been on the contractor side of two DIBCAC assessments. We asked for the first one. The second arrived by letter, about ten weeks before the assessment team did. That matches what I have seen since: letters tend to arrive ten to eleven weeks out. That is enough time to prepare well, and not enough to spend the first few weeks deciding where to start.

The second one taught me more. Nothing major had changed in the environment between the two, and I expected preparation to confirm what we already had. It did not. It turned up more drift than I expected, and it took real work to bring the documentation and the day-to-day practice back into line before the team arrived.

This is what I would tell a contractor who has just opened that letter.

What DIBCAC is actually assessing

The letter rests on DFARS 252.204-7020, which requires contractors to give the Government access to their facilities, systems and personnel for a Medium or High assessment. A Medium assessment is a review of your documents: your self-assessment, your System Security Plan, and how you say each requirement is met. A High assessment adds verification. Assessors examine artifacts, interview the people who do the work and watch controls operate, working through the 320 assessment objectives in NIST SP 800-171A.

The comparison that matters is between the score you posted in SPRS and what the team can verify. LOGZONE posted a 110 in October 2021. A DIBCAC assessment in February 2024 scored it at -170. In June 2026 the company agreed to pay $507,144 to resolve False Claims Act allegations. The gap between the posted score and the verified one is what turned an assessment into a case.

The pause on the CMMC Phase 2 C3PAO requirement, announced July 13, 2026, does not change any of this. That requirement is paused. DIBCAC's access under 7020 was never tied to it.

The phases below assume about eleven weeks. If your letter gives you less, compress the middle, not the first week.

Week one: read it, own it, freeze the record

Read the whole letter, then read it again with whoever will own the response.

Name one owner. Someone who can pull people off other work.

Tell leadership and your Affirming Official in the first days. They should hear it from you early, not late.

Talk to counsel early. Whether counsel should direct any part of the preparation is their call, not yours or mine.

Freeze the record. Save the SSP, POA&M, policies and SPRS entry as they stood the day the letter arrived. From then on, every change gets a date and a reason. A clean record of what you changed and when holds up better than a document that looks like it was always right.

Weeks two to four: rescore against evidence

Go objective by objective, and score only what you can show. Not what the policy says, not what the admin remembers setting up. Pull the artifact, find the person who performs the control, and check that the two agree.

This is where I was surprised. There had been no wholesale changes to the environment, so I expected a handful of findings. The list was longer. None of it came from a big decision. It came from software updates, minor system changes and personnel turnover: the ordinary changes that never prompt anyone to say "we need to update the documentation." Each one was small. Together they meant the documentation had fallen behind how things were actually done, and some tasks were being done one way by one person and a little differently by another.

A single software update can change a configuration default, what gets logged and who holds access. That is three controls, and nothing about the update tells you so.

Weeks five to ten: fix what is real, document what is not

Sort the findings into three groups.

The practice is right and the document is wrong. Update the document to match reality, date it, and note what changed.

The document is right and the practice is inconsistent. Fix the practice, train the people involved, and keep evidence that it now runs the same way every time.

Neither is there yet. Fix it if you can in the time you have. If you cannot, it goes on the POA&M with a realistic date, and your score reflects it.

Resist the pull to make everything look finished. A POA&M item with a realistic date is a stronger position than a control described as implemented that cannot be demonstrated.

Prepare people for interviews by making sure they can describe what they do in their own words. Recited policy does not survive a follow-up question.

The last week

Stage evidence where it can be found quickly, confirm who will attend each session, and name one person to track requests as they come in. Then stop changing things. A change made the night before is a change nobody has practiced.

After the assessment

If you believe the team missed evidence or misread a control, the DoD Assessment Methodology gives you 14 business days to submit a rebuttal with supporting documentation. Use it for evidence, not argument.

The result is recorded in SPRS, along with the date you expect to close open items and reach 110. Those dates are now on the record. Close them when you said you would.

What the letter actually tests

Looking back, the drift was predictable. We managed changes as IT work, not as compliance events. Nobody asked, with each update or departure, which controls it touched and which documents now had to change. That is the part I would do differently, and it is why continuous compliance is central to how we work at Stehrling now.

Your environment is never static. Small changes ripple and affect multiple controls. If you do not track them as they happen, your documented state drifts away from the reality of your security posture, and you find out how far only when someone asks you to prove it.

A DIBCAC letter does not test whether you were compliant once. It tests whether what you wrote down is still true.

Brian Stack led a defense contractor's team through two DIBCAC assessments. He is CEO of Stehrling.

Want to know where your organization stands?

Take our 3-minute Readiness Check and get an instant gap summary based on your environment.

Start Readiness Check →

An independent firm building NIST 800-171 compliance programs and AI governance for defense contractors and the DIB.

Fredericksburg, VA