---
title: Assessments
description: Track how your organization meets each CMMC practice and objective — set an implementation status and narrative for every objective, watch them roll up into practices, your SPRS score, and your open gaps.
navigation:
  icon: i-lucide-clipboard-check
---

# Assessments

An **assessment** is your organization's self-assessment against CMMC. It's the working record of how you meet each requirement — not a one-time questionnaire but a living document you build up objective by objective, revisit as your environment changes, and hand to an assessor when you're ready.

CMMC is built on **NIST SP 800-171**. A **Level 2** assessment covers all **110 practices**, and each practice breaks down into one or more **assessment objectives** — the individual, testable statements you must satisfy. There are **320 objectives** in total across the 110 Level-2 practices. You record where you stand on each one, and the platform rolls those answers up into a practice-by-practice picture, your **SPRS score**, and your list of **open gaps**.

::note
Find it in the sidebar under **Assessments** (`/dashboard/assessments`). It's visible to every role that can read compliance data; recording statuses and narratives requires an editing role — see [Permissions](#permissions).
::

---

## Key concepts

### Level 1 vs Level 2

CMMC has two self-assessable levels, and an assessment is scoped to one of them.

| Level | Scope |
| --- | --- |
| :badge[Level 1]{color="info"} | The foundational practices protecting Federal Contract Information (FCI) |
| :badge[Level 2]{color="info"} | All 110 practices protecting Controlled Unclassified Information (CUI), across the 320 objectives |

::tip
Most defense-contractor journeys target **Level 2**. Start there if you handle CUI; the Level-2 set fully contains the Level-1 practices.
::

### The requirement hierarchy

Everything in an assessment is organized as a hierarchy, from broad domains down to the single statements you actually answer.

| Level | What it is |
| --- | --- |
| **Family (domain)** | One of the **14 CMMC control families** — e.g. Access Control, Audit & Accountability, Configuration Management |
| **Practice** | A single CMMC requirement inside a family (110 of them at Level 2), identified like `AC.L2-3.1.1` |
| **Objective** | A discrete, testable statement inside a practice — the row you set a status on (320 in total) |

### Objective status

Every objective carries one status. This is the atom of the whole assessment — practices, your score, and your gaps are all derived from these.

| Status | Meaning |
| --- | --- |
| :badge[Implemented]{color="success"} | The objective is fully met |
| :badge[Partially implemented]{color="warning"} | Some, but not all, of the objective is in place — **counts as not met** |
| :badge[Not implemented]{color="error"} | The objective is not met |
| :badge[Not applicable]{color="neutral"} | The objective is out of scope for your environment, with a documented reason |
| :badge[Unassessed]{color="neutral"} | You haven't recorded a status yet — **counts as not met** |

::warning
**Partially implemented** and **unassessed** both count as **not met** for scoring and gap purposes. A half-done control earns no partial credit toward CMMC — an objective is either fully satisfied or it isn't.
::

### How objectives roll up into practices

A **practice is met only when *every* in-scope objective under it is met.** A single partial, not-implemented, or unassessed objective leaves the whole practice failing. Objectives you mark **Not applicable** (with a reason) are removed from scope and don't hold the practice back.

---

## Using an assessment

An assessment opens on an **overview** with your headline metrics, then lets you drill into each family and work through its objectives.

### Read the overview

::steps{level="4"}

#### Open the assessment

From the **Assessments** list, open the assessment you want to work in. The overview loads first.

#### Read the metrics

The overview summarizes where you stand: how many objectives are **met**, how many are **failing** (not implemented or partially implemented), and how many are **unassessed** (not yet touched). Together with your **not-applicable** count, these add up to the full objective set.

#### Check your score and gaps

The overview also surfaces your **SPRS score** and your **open gaps** — the practices that aren't fully implemented yet. Use these to decide where to focus next.

::

::note
"Failing," "met," and "unassessed" are counted at the **objective** grain on the overview. Elsewhere in the platform the same words may be counted at the **practice** grain (for example, your open-gaps list is practices, not objectives), so the totals won't always line up — they're answering slightly different questions.
::

### Work through objectives

::steps{level="4"}

#### Pick a family

Browse the requirement hierarchy and choose a control family to work on. Each family shows its practices and how many of their objectives are still open.

#### Open a practice

Expand a practice to see its objectives — the individual statements you'll assess. Each objective shows the exact NIST wording so you know precisely what's being asked.

#### Set each objective's status

For every objective, choose **Implemented**, **Partially implemented**, **Not implemented**, or **Not applicable**. This is the single most important action in an assessment — it drives every downstream number.

#### Write the narrative

Record **how** you meet the objective — the plain-language explanation an assessor reads to understand your implementation. A good narrative describes what's in place, not just that a box is checked.

#### Record a reason for anything not applicable

If an objective doesn't apply to your environment, mark it **Not applicable** and document **why**. The reason is retained as evidence of a complete, defensible assessment.

::

::tip
Attach **evidence** to objectives as you go — the artifacts that back up each narrative. Working an objective and its evidence together saves you a second pass before an assessment.
::

---

## Permissions

Access follows the compliance-data permissions in the role matrix.

| Capability | Who |
| --- | --- |
| View assessments, the overview, and objective statuses | Every non-platform role, including Assessor |
| Set objective statuses, write narratives, mark not-applicable | Org Admin, Org User, MSP Super, MSP Admin |

Assessors have **read-only** access — they can review your entire assessment, its narratives, and its evidence, but they can't change a status or a score.

::warning
The number of assessments you can create is governed by your subscription plan. Foundation includes **1** assessment, Professional includes **3**, and Enterprise is **unlimited**. When you reach your plan's limit, creating another assessment prompts an upgrade.
::

---

## How it works

Extra detail on how the assessment behaves — product behavior, not internals.

### What an objective holds

Each objective is a single record inside a practice.

:::field-group
::field{name="Objective statement"}
The exact NIST SP 800-171 wording of the testable requirement.
::
::field{name="Practice & family"}
The practice it belongs to (e.g. `AC.L2-3.1.1`) and its CMMC control family.
::
::field{name="Status"}
Implemented, Partially implemented, Not implemented, Not applicable, or (by default) Unassessed.
::
::field{name="Narrative"}
Your plain-language explanation of how the objective is met.
::
::field{name="Not-applicable reason"}
The documented justification recorded when an objective is marked Not applicable.
::
::field{name="Evidence"}
The artifacts linked to the objective as proof of implementation.
::
:::

### How the score is calculated

Your **SPRS score** starts at **110** and subtracts a weight for every in-scope practice that isn't fully met. Practices carry different weights depending on how important the underlying control is, so not every gap costs the same. Because a practice is met only when **all** of its in-scope objectives are met, an unassessed or partially implemented objective quietly holds its whole practice — and its weight — against your score until you close it.

::note
Objectives you mark **Not applicable** are excluded from the math entirely — they neither earn nor deduct points. That's why documenting scope decisions matters: it keeps your score reflecting only what genuinely applies to you.
::

### What "open gaps" means

Your **open gaps** are the **practices** that aren't fully implemented yet — including practices where you simply haven't assessed the objectives. Clearing a gap means bringing **every** in-scope objective under that practice to **Implemented** (or **Not applicable** with a reason). Watching your open-gaps count fall is the most direct measure of assessment progress.

### AI assistant access

When the [AI Connector](https://app.dibfi.com/dashboard/org-settings) is enabled, assistants can **read** (never change) your assessment data — your objective statuses, practice rollups, SPRS score, and open gaps — so you can ask questions about your posture in plain language. Access follows the same permissions as the app: an assistant only ever sees what the connected user's role is allowed to see.

---

## Related features

:::card-group

::card{title="Evidence" icon="i-lucide-paperclip" to="https://app.dibfi.com/dashboard/systems"}
Attach the artifacts that prove each objective is implemented.
::

::card{title="POA&M" icon="i-lucide-list-checks" to="https://app.dibfi.com/dashboard/poam"}
Track the remediation of open gaps as milestones.
::

::card{title="AI Connector" icon="i-lucide-bot"}
Read your assessment statuses, score, and gaps through an AI assistant.
::

:::
