---
title: "What Is DIBCAC? CMMC Definition"
description: "DIBCAC is the DoD organization that conducts government-led high assessments and CMMC Level 3 assessments."
url: https://policycortex.com/cmmc/glossary/dibcac
sealed: 2026-07-02
amended: 2026-07-13
register: cmmc/glossary/dibcac
records: 3
digest: sha3:1f969919aa40defc8772e3c32cb1a6f115c655e4421a4ec8a350f45b84705f71
---

# What is DIBCAC?

Register / Glossary

DIBCAC is the DoD organization that conducts government-led high assessments and CMMC Level 3 assessments.

Sealed 2026-07-02 · Amended 2026-07-13

DIBCAC stands for Defense Industrial Base Cybersecurity Assessment Center.

The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) performs the government-led assessments that sit above the C3PAO tier — including CMMC Level 3, which adds NIST SP 800-172 enhanced controls.

DIBCAC assessments also produce the authoritative scores that have exposed gaps between self-reported SPRS numbers and reality, as in the LOGZONE case.

The prior schedule placed the DIBCAC-assessed Phase 3 transition on November 10, 2027, but the Department suspended pending and future implementation milestones while it reviews the CMMC program.

## Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

- **proof.state**: [Proof of State](https://policycortex.com/proof/state). What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- **proof.change**: [Proof of Change](https://policycortex.com/proof/change). Who or what altered the environment, under what authority, with before and after state hashes.
- **proof.agency**: [Proof of Agency](https://policycortex.com/proof/agency). What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- **architecture**: [Architecture](https://policycortex.com/architecture). How the chain is built and where it lives: inside your tenant, with no egress of evidence.

### Related terms and reading

| Entry |
|---|
| [C3PAO: CMMC Third-Party Assessment Organization](https://policycortex.com/cmmc/glossary/c3pao): A C3PAO is an organization authorized by the Cyber AB to conduct official CMMC Level 2 certification assessments. |
| [SPRS: Supplier Performance Risk System](https://policycortex.com/cmmc/glossary/sprs): SPRS is the DoD system where contractors post their NIST 800-171 self-assessment score and, under CMMC, their certification status and affirmations. |

Know the term. Then see the record behind it. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

Dates of record

- **Sealed**: 2026-07-02
- **Last amended**: 2026-07-13
- **Record**: https://policycortex.com/cmmc/glossary/dibcac

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | HEAD | a9da3088254c | 99b4d34805f5 |
| REC 0001 | DEFINITION | 94fb9b7a44db | a9da3088254c |
| REC 0002 | RELATED RECORDS | 1f969919aa40 | 94fb9b7a44db |

Head sha3:1f969919aa40defc8772e3c32cb1a6f115c655e4421a4ec8a350f45b84705f71. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
