# DoD (Department of Defense) | Secureframe

> The DoD components that affect defense contractor cybersecurity: DoD CIO, USD(A&S), DCMA, DIBCAC, DC3, and DCSA. Who does what in the CMMC and DFARS ecosystem.

canonical: https://secureframe.com/glossary/department-of-defense

The Department of Defense is the federal agency responsible for U.S. military operations. For contractors, the DoD is the counterparty on contracts, the author of DFARS, the owner of CMMC, and the operator of SPRS. Cybersecurity oversight sits across several DoD components: the DoD CIO sets policy, DIBCAC (under DCMA) conducts assessments, the CMMC PMO manages the certification program, and DC3 handles incident response coordination.

### DoD Components That Touch Contractor Cybersecurity

- **DoD CIO**: Sets cybersecurity policy, issues implementation guidance, coordinates with OMB on DoD-specific policy direction.
- **USD(A&S):** Under Secretary of Defense for Acquisition and Sustainment. Houses the CMMC Program Management Office.
- **DCMA:** Defense Contract Management Agency. Administers contracts post-award. Houses DIBCAC.
- **DIBCAC:** Defense Industrial Base Cybersecurity Assessment Center. Conducts Medium and High NIST 800-171 assessments.
- **DC3:** DoD Cyber Crime Center. Receives DIBNet incident reports and coordinates response.
- **DCSA:** Defense Counterintelligence and Security Agency. Handles industrial security and facility clearances.

### How Contractors Interact with DoD

The contracting officer is your primary DoD touchpoint on any given contract. The CO issues the award, administers modifications, receives cyber incident reports, and has authority over compliance disputes. Beyond the CO, your SPRS score is visible to contracting officers across DoD. A DIBCAC assessment is scheduled by DCMA. A CMMC certification is issued by the Cyber AB based on a C3PAO assessment, not by DoD directly.

### DoD Cybersecurity Priorities in Practice

- **Protect CUI in the Defense Industrial Base via DFARS 252.204-70**12 and CMMC.
- **Strengthen cyber supply chain risk management per **NIST SP 800-161.
- **Enforce accountability for cybersecurity misrepresentation through the Civil C**yber-Fraud Initiative.
- **Integrate zero trust architecture per the DoD Zero Trust Strate**gy (November 2022).
