Self-Assessment
A self-assessment is how you measure yourself against CMMC before a certified assessor ever does. You go through every objective in your assessment, decide whether you meet it, write down what you found, and attach the evidence that backs it up. The result is a defensible record of your current state — and the SPRS score you'd report to the DoD.
DIBFI turns that into a focused workbench: one objective at a time, with the NIST SP 800-171A assessment guidance, your evidence, and a place to record your finding all on a single screen. As you work, your score updates live so you always know where you stand.
Key concepts
The determination
For each objective you make one call: is it Met or Not met? CMMC Level 2 objectives can't be self-declared Not applicable, so the choice is deliberately two ways. When something is on its way but not fully in place, mark it Not met and flag it as partially in place — a signal that it's a candidate for a POA&M.
| Determination | Meaning |
|---|---|
| Met | The objective is fully implemented |
| Not met | The objective is not implemented |
| Partially in place | Not met, but partly there — a POA&M candidate |
The narrative
Every determination is backed by an overall comment — a short, plain-language note on what you found and why you reached that conclusion. This is the same rationale an assessor reads, and it flows into your System Security Plan, so it's worth writing clearly.
The 800-171A assessment guide
Each objective carries the official assessment guidance inline — what to determine, what to examine, whom to interview, and what to test — adapted from NIST SP 800-171A and the DoD CMMC Level 2 Assessment Guide. You never have to leave the workbench to look up what an objective actually asks for.
Objective status at a glance
The objective list shows where every objective stands so you can move through them efficiently and filter down to what's left.
| Filter | Shows |
|---|---|
| All | Every objective in the assessment |
| Not assessed | Objectives you haven't recorded a determination for yet |
| Needs attention | Objectives marked Not met |
| Complete | Objectives with any determination recorded |
Using the workbench
The workbench puts three things side by side: the objective list (left), the evidence viewer (center), and the record where you set your determination (right). You move through objectives in order — or jump to any one from the list.
Set up the assessment
Open the setup panel
Give the assessment a title, optional start and end dates, and any methodology notes describing how you're conducting it.
Record participants
List the people involved in the assessment so the record reflects who took part.
Assess an objective
Read the objective and its guidance
The workbench shows the objective text and the built-in 800-171A assessment guide — what to look for, whom to talk to, and what to test.
Review the evidence
Work through the evidence in the center viewer and select the artifacts that support this objective. You can attach the same file to other objectives it applies to without leaving the screen.
Make your determination
Choose Met or Not met. If it's partly in place, check partially in place to flag it as a POA&M candidate.
Write the narrative
Record your overall comments — what you found and why you reached this determination.
Note who assessed it and when
Set the assessor and the assessment date for the objective. These default to you and today.
Save and move on
Save and advance to the next objective. Your work saves as you go, and the score recalculates.
Track your progress
Use the objective list to filter to Not assessed and clear the backlog, or Needs attention to focus on gaps. A status dot on each row — neutral, green, or red — tells you the determination at a glance.
Permissions
Access follows the same roles as the rest of your assessment.
| Capability | Who |
|---|---|
| View the workbench, evidence, and guidance | View Every non-platform role, including Assessor (read-only) |
| Record determinations, narrative, interviews, tests, and evidence selections | Edit Org Admin, Org User, MSP Super, MSP Admin |
How it works
Extra detail on how the self-assessment behaves — product behavior, not internals.
How the score updates
Your SPRS score starts at 110 and descends as gaps are found. An objective only counts as satisfied once you've marked it Met (or it's excluded from scope); Not met, partially in place, and not-yet-assessed all count against you — exactly as real SPRS scoring requires, where a control must be affirmatively met to earn its points. A control earns its full value only when every in-scope objective under it is met. The workbench uses the same scoring engine as your dashboards, so the number you see while working matches the one you'd report.
How it relates to the full Assessments view
The workbench is the guided, objective-by-objective way to do the work. The broader Assessments view is where you create assessments, choose their scope and systems, see roll-ups by control family, and export your System Security Plan. The determinations and narratives you record in the workbench are the same records those roll-ups and exports read from — you're always working on one shared source of truth.
Scope and exclusions
Objectives that are excluded from a system's scope don't drag your score down — the workbench honors the same per-system exclusions as the rest of the platform, so the number reflects only what actually applies to your environment.
Related features
CMMC Journey
DIBFI's guided, phase-by-phase path from first scoping to certification — always showing your current phase and the single best next step.
SPRS Score
Your SPRS score is the single number that summarizes CMMC Level 2 readiness. Learn how it's calculated, why controls are weighted, and how to raise it fastest.

