Onboarding
Onboarding is the short, guided setup you complete the first time you sign in to a brand-new organization. It's where you tell DIBFI two things: which CMMC level you're pursuing, and what's in your environment — the identity providers, devices, storage, and specialized systems that touch federal information. From those answers, DIBFI builds your starting point: an initial list of systems and your first assessment, already scoped to the right level and ready to work.
Onboarding is a one-time, organization-wide setup. One person completes it on behalf of the whole organization; once it's done, everyone who joins later lands directly in the dashboard.
Key concepts
CMMC level
Onboarding first establishes the level you're assessing against. This is driven by whether your organization handles CUI (Controlled Unclassified Information) or only FCI (Federal Contract Information).
| Level | Who it's for |
|---|---|
| Level 1 | You only handle general FCI — basic safeguarding requirements |
| Level 2 | You receive, store, or process CUI — the fuller NIST SP 800-171 baseline |
System categories
You describe your environment one category at a time. Each category asks about the systems that actually touch FCI or CUI — not every tool your company uses.
| Category | What it covers |
|---|---|
| Identity & Collaboration | How users sign in and collaborate — e.g. Microsoft 365, Google Workspace, on-prem Active Directory |
| User Access | Where users work from — laptops and desktops, virtual desktops, jump hosts, mobile devices |
| Data Storage | Where FCI or CUI lives — SharePoint/OneDrive, file servers, other cloud storage |
| Specialized / OT | Purpose-built systems — manufacturing/OT, ERP, lab systems, and other specialized platforms |
Environment boundary
Finally, you tell DIBFI how your regulated systems relate to the rest of your business. This sets expectations for your scope.
| Boundary | Meaning |
|---|---|
| Separate | Your FCI/CUI systems sit on their own network or enclave, isolated from everyday business systems |
| Mixed | Your FCI/CUI systems share a network with the rest of the business — email, accounting, HR, and so on |
| Not sure | You're not certain how things are set up yet — that's fine, you can refine it as you go |
What onboarding produces
When you finish, DIBFI turns your answers into a working starting point.
Using onboarding
The setup runs as a short wizard with a progress bar across the top. You move forward with Next, and you can step Back at any point to change an answer before you finish.
Get oriented
The welcome step introduces what you're about to do. Onboarding also confirms your CMMC level based on your DoD work and whether you handle CUI — handling CUI points you to Level 2, FCI-only to Level 1.
Add your identity & collaboration systems
Select the platforms users authenticate and collaborate through when working with FCI or CUI — for example Microsoft 365 or Google Workspace. Leave out sign-in tools that never touch regulated data.
Add where users work from
Choose the endpoint types used to access, process, or store FCI or CUI — company laptops and desktops, virtual desktops, jump hosts, and the like.
Add where data is stored
Select the storage locations that actually hold FCI or CUI — SharePoint/OneDrive, file servers, or other cloud storage. Skip shares that hold only internal, non-regulated content.
Add specialized or operational systems
Include any purpose-built systems — manufacturing/OT, ERP, or lab systems — that directly handle regulated data.
Set your environment boundary
Tell DIBFI whether your regulated systems are separate from the rest of the business, mixed in with it, or you're not sure yet.
Review and finish
The summary lists the systems you selected and the assessment that will be created. Confirm to complete onboarding — DIBFI builds your systems and first assessment and takes you into the platform.
Permissions
Onboarding is completed by the person who sets up the organization — typically an owner or administrator. It runs once, at the organization level, so a single completed setup applies to everyone.
| Capability | Who |
|---|---|
| Complete onboarding for a new organization | The organization owner or administrator setting it up |
| Skip onboarding (already done) | Everyone who joins after setup is complete |
How it works
A little more on how onboarding behaves — product behavior, not internals.
It runs once, for the whole organization
Onboarding is tied to your organization, not to individual users. The first person through the wizard sets things up for everyone; once it's marked complete, DIBFI stops showing it and sends everyone straight to the dashboard.
Your answers become real objects
Each system you select becomes a manageable system in your dashboard, and DIBFI creates your first assessment at your chosen level with those systems linked to it. The assessment is seeded with the full objective set for your level, so your scope is populated and ready — you're not starting from an empty page.
Your level sets your scope
Choosing Level 1 scopes your assessment to the Level 1 requirements; Level 2 loads the fuller NIST SP 800-171 objective set. This is why the level question matters early: it determines how much you'll be assessed against and how your SPRS score is calculated.
It's safe to re-enter
Onboarding is designed to be forgiving. If setup is somehow started again, DIBFI recognizes systems and an assessment that already exist and won't create duplicates — you keep the environment you already built.
What to do next
With onboarding complete, you land in the dashboard with systems and a first assessment in place. From here you can invite your team, begin implementing and scoring controls, collect evidence, and follow DIBFI's guided journey toward certification.
Related features
Overview
Set up your organization, invite your team, and understand roles and permissions.
Organization Settings
Manage your organization's identity, the legal and personnel details that appear in your System Security Plan, connected integrations, and the security controls that govern AI assistant access.

