sha3:1f969919aa40defc8772e3c32cb1a6f115c655e4421a4ec8a350f45b84705f71Intacta9da3088254c72f22d5c317aaa55f52aa8c4118b0d7bf017262e0255645d7d55prev:99b4d34805f5RegisterGlossary
What is DIBCAC?
DIBCAC is the DoD organization that conducts government-led high assessments and CMMC Level 3 assessments.
94fb9b7a44dbb3ce802a788481d0fd804a03f0eb379080fb2e285f6882591b97prev:a9da3088254cDIBCAC stands for Defense Industrial Base Cybersecurity Assessment Center.
The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) performs the government-led assessments that sit above the C3PAO tier — including CMMC Level 3, which adds NIST SP 800-172 enhanced controls.
DIBCAC assessments also produce the authoritative scores that have exposed gaps between self-reported SPRS numbers and reality, as in the LOGZONE case.
The prior schedule placed the DIBCAC-assessed Phase 3 transition on November 10, 2027, but the Department suspended pending and future implementation milestones while it reviews the CMMC program.
1f969919aa40defc8772e3c32cb1a6f115c655e4421a4ec8a350f45b84705f71prev:94fb9b7a44dbRelated records
Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.
- proof.state
- Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- proof.change
- Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
- proof.agency
- Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- architecture
- Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.
Related terms and reading
Know the term. Then see the record behind it.
- Sealed
- Last amended