As the CMMC Churns
How to Survive a DIBCAC Non-Voluntary Assessment
Watch on Vimeo
Watch on Youtube
Did you get a letter emailed to you from the Defense Industrial Base Cybersecurity Assurance Center (DIBCAC) notifying your organization they intend to conduct a “High Assessment” of your DFARS Clause 252.204-7012, “Safeguarding Covered Defense Information and Cyber Incident Reporting” compliance and NIST SP 800-171, “Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations” implementation?
If so, “As the CMMC Churns” is perfect for you. This episode draws on over a dozen DIBCAC assessments/audits we have completed as Peak InfoSec. The episode explains the purpose of the DIBCAC audit, the consequences if it goes sideways, and 5 key survival rules to follow when preparing for your DIBCAC audit.
If you want to see what the DIBCAC High Assessment notification letter looks like, a redacted version is available at http://peakinfosec.com/wp-content/uploads/2026/08/DIBCAC_KTR_Notification_redacted.pdf.
Frequently Asked Questions
What is DIBCAC?
DIBCAC Is the Defense Industrial Base Cybersecurity Assessment Center, which is a part of the Defense Contract Management Agency (DCMA).
What does DIBCAC do?
DIBCAC conducts assessments or audits of organization in the Defense Industrial Base (DIB) or Defense Supply Chain.
What does DIBCAC against?
DIBCAC Assessments are to validate an organization's cybersecurity compliance to the Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, “Safeguarding Covered Defense Information and Cyber Incident Reporting,” and its implementation of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations.”
Can Peak InfoSoSec support us during our DIBCAC Assessment?
Yes. Our prior acquisition experience plus over a decade of supporting NIST SP 800-171 implementations places Peak InfoSec as one of the authoritative and go to organizations when an organization needs help with their DIBCAC assessment.
How many DIBCAC Assessments has Peak INfoSec been involved in?
Peak InfoSec has been involved in dozens of DIBCAC assessments. 100% of our clients passed their DIBCAC Assessment.
Key CMMC Organizations
- National Archives & Records Administration Controlled Unclassified Information (CUI) Homepage
- DoD CIO’s Cybersecurity Maturity Model Certification (CMMC) Home Page
- Cyber Accreditation Body (Cyber-AB)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resource Page
- Defense Industrial Base (DIB) Cybersecurity Portal
Key Regulations
Key Acquisition References
- 48 CFR § 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
- DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- DFARS Clause 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
- DFARS Clause 252.204-7021 Compliance with the Cybersecurity Maturity Model Certification Level Requirements.