---
title: Self-Assessment
description: Work through your CMMC objectives one at a time, record a determination and narrative for each, and watch your SPRS score update live as you go.
navigation:
  icon: i-lucide-pencil-ruler
---

# Self-Assessment

A **self-assessment** is how you measure yourself against CMMC before a certified assessor ever does. You go through every objective in your assessment, decide whether you **meet** it, write down what you found, and attach the evidence that backs it up. The result is a defensible record of your current state — and the **SPRS score** you'd report to the DoD.

DIBFI turns that into a focused **workbench**: one objective at a time, with the NIST SP 800-171A assessment guidance, your evidence, and a place to record your finding all on a single screen. As you work, your score updates live so you always know where you stand.

::note
Find it in the sidebar under **Self Assessment**. If you have a single assessment, DIBFI takes you straight into its workbench; if you have more than one, you pick which assessment to work in. Everyone who can read compliance data can view the workbench; recording findings requires an editing role — see [Permissions](#permissions).
::

---

## Key concepts

### The determination

For each objective you make one call: is it **Met** or **Not met**? CMMC Level 2 objectives can't be self-declared **Not applicable**, so the choice is deliberately two ways. When something is on its way but not fully in place, mark it **Not met** and flag it as **partially in place** — a signal that it's a candidate for a POA&M.

| Determination | Meaning |
| --- | --- |
| :badge[Met]{color="success"} | The objective is fully implemented |
| :badge[Not met]{color="error"} | The objective is not implemented |
| :badge[Partially in place]{color="warning"} | Not met, but partly there — a POA&M candidate |

::tip
"Partially in place" is a checkbox that appears once you choose **Not met**. It still counts as a gap for scoring, but it marks the objective as work already underway rather than untouched.
::

### The narrative

Every determination is backed by an **overall comment** — a short, plain-language note on what you found and why you reached that conclusion. This is the same rationale an assessor reads, and it flows into your System Security Plan, so it's worth writing clearly.

### The 800-171A assessment guide

Each objective carries the official assessment guidance inline — what to **determine**, what to **examine**, whom to **interview**, and what to **test** — adapted from NIST SP 800-171A and the DoD CMMC Level 2 Assessment Guide. You never have to leave the workbench to look up what an objective actually asks for.

### Objective status at a glance

The objective list shows where every objective stands so you can move through them efficiently and filter down to what's left.

| Filter | Shows |
| --- | --- |
| **All** | Every objective in the assessment |
| **Not assessed** | Objectives you haven't recorded a determination for yet |
| **Needs attention** | Objectives marked Not met |
| **Complete** | Objectives with any determination recorded |

---

## Using the workbench

The workbench puts three things side by side: the **objective list** (left), the **evidence viewer** (center), and the **record** where you set your determination (right). You move through objectives in order — or jump to any one from the list.

### Set up the assessment

::steps{level="4"}

#### Open the setup panel

Give the assessment a **title**, optional **start and end dates**, and any **methodology notes** describing how you're conducting it.

#### Record participants

List the people involved in the assessment so the record reflects who took part.

::

### Assess an objective

::steps{level="4"}

#### Read the objective and its guidance

The workbench shows the objective text and the built-in **800-171A assessment guide** — what to look for, whom to talk to, and what to test.

#### Review the evidence

Work through the evidence in the center viewer and **select** the artifacts that support this objective. You can attach the same file to other objectives it applies to without leaving the screen.

#### Make your determination

Choose **Met** or **Not met**. If it's partly in place, check **partially in place** to flag it as a POA&M candidate.

#### Write the narrative

Record your **overall comments** — what you found and why you reached this determination.

#### Note who assessed it and when

Set the **assessor** and the **assessment date** for the objective. These default to you and today.

#### Save and move on

Save and advance to the next objective. Your work saves as you go, and the score recalculates.

::

::tip
Record **interviews** and **tests** against an objective as you perform them — who you spoke with, what you checked — so the objective's record is complete, not just a yes/no verdict.
::

### Track your progress

Use the objective list to filter to **Not assessed** and clear the backlog, or **Needs attention** to focus on gaps. A status dot on each row — neutral, green, or red — tells you the determination at a glance.

---

## Permissions

Access follows the same roles as the rest of your assessment.

| Capability | Who |
| --- | --- |
| **View** the workbench, evidence, and guidance | :badge[View]{color="neutral"} Every non-platform role, including Assessor (read-only) |
| **Record** determinations, narrative, interviews, tests, and evidence selections | :badge[Edit]{color="info"} Org Admin, Org User, MSP Super, MSP Admin |

::warning
The **Assessor** role is intentionally read-only here — an assessor reviews your self-assessment, they don't author it. When you lack the editing permission, the workbench opens in view-only mode.
::

---

## How it works

Extra detail on how the self-assessment behaves — product behavior, not internals.

### How the score updates

Your **SPRS score** starts at **110** and descends as gaps are found. An objective only counts as satisfied once you've marked it **Met** (or it's excluded from scope); **Not met**, **partially in place**, and **not-yet-assessed** all count against you — exactly as real SPRS scoring requires, where a control must be affirmatively met to earn its points. A control earns its full value only when *every* in-scope objective under it is met. The workbench uses the same scoring engine as your dashboards, so the number you see while working matches the one you'd report.

::note
Because unassessed objectives count against the score, a brand-new assessment starts well below 110 and climbs as you work through it. That's expected — the score reflects what you've *demonstrably* met, not what you *intend* to.
::

### How it relates to the full Assessments view

The workbench is the guided, objective-by-objective way to *do* the work. The broader **Assessments** view is where you create assessments, choose their scope and systems, see roll-ups by control family, and export your System Security Plan. The determinations and narratives you record in the workbench are the same records those roll-ups and exports read from — you're always working on one shared source of truth.

### Scope and exclusions

Objectives that are excluded from a system's scope don't drag your score down — the workbench honors the same per-system exclusions as the rest of the platform, so the number reflects only what actually applies to your environment.

---

## Related features

:::card-group

::card{title="Assessments" icon="i-lucide-clipboard-check" to="https://app.dibfi.com/dashboard/assessments"}
Create assessments, set scope, review roll-ups, and export your SSP.
::

::card{title="SPRS Score" icon="i-lucide-gauge" to="https://app.dibfi.com/dashboard/assessments"}
See how your determinations add up to the score you report to the DoD.
::

::card{title="POA&M" icon="i-lucide-list-checks" to="https://app.dibfi.com/dashboard/poam"}
Turn partially-in-place objectives into tracked remediation milestones.
::

:::
