DIBFI Documentation

Guides and reference for DIBFI — the platform that takes defense contractors from first scoping to CMMC certification and keeps them compliant afterward.

DIBFI is a compliance platform for defense contractors pursuing and maintaining CMMC (Cybersecurity Maturity Model Certification). It guides you through a structured journey — scope your environment, implement and document controls, gather evidence, score yourself against SPRS, manage risk and remediation, and stay compliant with recurring operations — all in one place. Managed Service Providers (MSPs) can run the same journey across many client organizations under their own branding.

New here? Start with Getting Started to set up your organization, then follow the CMMC Journey — DIBFI's guided, phase-by-phase path to certification.

Explore by area

Getting Started

Set up your organization, invite your team, and understand roles and permissions.

Assessment & Scoring

Run CMMC assessments, track objectives, follow the guided journey, and watch your SPRS score.

Evidence & Documents

Collect evidence, build policies, and generate your System Security Plan.

Operations & Risk

Manage risk, run recurring compliance tasks, and track remediation with POA&Ms.

Billing & MSP

Manage your plan, and — for partners — run compliance across multiple clients.

Integrations & AI

Connect Microsoft 365 and give an approved AI assistant read-only access to your data.

What you can do in DIBFI

Know where you stand

A live SPRS score, open gaps, and readiness — always up to date as you work.

Prove it

Evidence, policies, and a complete System Security Plan an assessor can review.

Stay compliant

Recurring compliance tasks and periodic risk reviews keep you audit-ready between assessments.

Close the gaps

Track every weakness to remediation with risks and POA&Ms.

Looking for a specific term? See the Glossary in the Reference section — it explains CMMC, SPRS, POA&M, SSP, CUI, and the other acronyms you'll meet along the way.