# DIBCAC (Defense Industrial Base Cybersecurity Assessment Center) | Secureframe

> DIBCAC under DCMA, how Basic/Medium/High assessments differ, how scores get recorded in SPRS, and what to have ready when DIBCAC shows up.

canonical: https://secureframe.com/glossary/dibcac

DIBCAC is part of the Defense Contract Management Agency (DCMA). It runs the Medium and High NIST SP 800-171 assessments defined in DFARS 252.204-7020. DIBCAC can show up for a few reasons: your contract picked you, you are a prime supporting a major program, or you passed DIBCAC's trigger criteria. Assessment results land in SPRS and contracting officers can see them.

### Where DIBCAC Sits

DIBCAC operates under DCMA, the Defense Contract Management Agency. DCMA administers active DoD contracts and manages contractor performance, so placing the cybersecurity assessment function there puts it alongside existing oversight mechanisms.

### The Three Assessment Types

- **Basic:** Self-assessment. You score yourself using the DoD Assessment Methodology and submit to SPRS. This is the minimum under DFARS 252.204-7019.
- **Medium:** DIBCAC reviews your SSP, supporting policies, and interviews staff. No on-site technical verification.
- **High:** DIBCAC comes on-site and verifies that controls actually work as documented. This is the most detailed.

### What Triggers a DIBCAC Assessment

DIBCAC assessments are not random. Triggers include the contracting activity requesting one, being selected for the DoD's risk-based sampling, DIB-CS program involvement, or a cyber incident that warrants a post-incident review. Expect at least 30 days of advance notice for a scheduled assessment.

### DIBCAC vs C3PAO

C3PAOs assess against CMMC and issue certifications. DIBCAC assesses against DFARS 7012 and produces SPRS scores. They measure largely the same controls but under different authorities. DIBCAC can also assess Level 3 under CMMC 2.0, which C3PAOs cannot.

### How to Prepare

- **SSP **current and readable. An assessor who cannot follow your SSP will struggle to give you credit.
- **POA&M realisti**c. If every item says 'Q4 2026,' that raises questions. Dates should match your actual remediation capacity.
- **Evidence organized by requi**rement number. 3.1.1, 3.1.2, 3.1.3... one folder per requirement with the artifacts inside.
- **Staff briefed**. Whoever owns identity management should be able to explain how MFA is enforced for privileged accounts without reading from a script.
- **Network diagrams accurate**. The diagram the assessor receives should match what is actually in the environment.
