Attestations

Freeze your compliance posture into tamper-evident, point-in-time attestation records, capture a senior official's affirmation, and keep a permanent, downloadable archive for auditors.

The Attestations archive is your permanent record of what you affirmed, and when. Each attestation is a point-in-time snapshot of your compliance posture — your score, your findings, your systems, and your open remediation items — frozen at the moment of generation and preserved unchanged, even as the underlying data keeps moving.

CMMC and DFARS 252.204-7012 expect a senior official to affirm that your organization meets its security requirements. This is where that affirmation is captured and kept: a named official, a confirmed affirmation, and an immutable package an auditor can open, download, and independently verify — today or years from now.

Find it in the sidebar under Attestations (/dashboard/attestations). Every role that can view evidence can browse the archive and download records; generating a new attestation is limited to organization administrators — see Permissions.

Key concepts

What an attestation is

In CMMC, an attestation (or affirmation) is a senior official's formal statement that the organization's security posture is accurate as represented. DIBFI turns that statement into a verifiable artifact: a sealed record that pins your posture to a specific date and can never be silently edited afterward.

Two kinds of record

The archive holds two kinds of attestation, and they arrive by different paths.

KindHow it's created
Self-assessment attestationYou generate it on demand from a chosen assessment. It freezes your full posture and captures the affirming official.
Operational attestation recordGenerated automatically when a recurring compliance operations task is completed, and filed into your evidence as a signed record of that review.

Record state

An assessment has one current attestation at a time. Generating a new one supersedes the previous record — the old one is never deleted, it's retained in full and marked as history.

StateMeaning
CurrentThe latest attestation for the assessment
SupersededReplaced by a newer attestation — kept for the audit trail

Integrity fingerprints

Every attestation carries three cryptographic fingerprints that make it tamper-evident. If anything in a record changes, the fingerprints no longer match.

FingerprintWhat it covers
Snapshot hashThe frozen posture (score, findings, systems, POA&Ms)
Package hashThe exact bytes of the downloadable package
Chain hashThis record plus the one before it, linking the whole sequence
The chain hash is what makes the archive tamper-evident as a sequence: because each record's chain hash folds in the previous record's, altering any older attestation would break every record that came after it. The first record in your history is seeded from a fixed genesis value.

Overall finding (operational records)

Automatically generated operational attestations carry a plain-language verdict for the review period.

FindingMeaning
NoneNo issues found during the review
MinorMinor issues noted
MajorSignificant issues requiring attention

Using Attestations

The Attestations page lists your archive newest-first, with each record's number, score, and integrity fingerprints. Once you have two or more, a score progression chart shows how your posture has moved over time.

Generate a self-assessment attestation

Generating an attestation freezes your posture and captures the affirming official in a single, sealed record.

Choose an assessment

Start a new attestation and pick the assessment you want to attest. DIBFI runs a readiness check and shows exactly what will be frozen — your score, your objective counts, and your open POA&Ms.

Clear any blockers

Some conditions block generation because they would freeze a misleading record — for example, an assessment where nothing has been assessed yet, or one with no active system in scope. Unassessed objectives that remain are allowed, but you'll see a warning (they count against your score).

Name the affirming official

Enter the name and title of the senior official making the affirmation. This is recorded on the sealed record.

Confirm the affirmation

Confirm the DFARS 252.204-7012 affirmation to proceed. Generation won't continue without it.

Generate

DIBFI freezes the posture, assembles the package, and files the record. It becomes your current attestation and supersedes the previous one.

The score in an attestation is computed with the same method you see live on your dashboard and workbench — a frozen attestation can never diverge from the number you saw when you generated it.

Download a record

Open any record to see its full frozen posture and integrity fingerprints, then download its package — a complete, self-contained set of documents (score summary, methodology, assessment record, score worksheet, POA&M list, evidence summary, asset scope, and a DFARS 7012 checklist). The package is immutable and remains downloadable for the life of the record.

Every download link is generated fresh and expires quickly, so records stay private to people who are signed in and authorized — but the archive itself keeps the package available indefinitely.

Review an operational attestation

When a recurring compliance operations task is completed, DIBFI automatically generates a formal attestation record for that review — with the task, period, systems reviewed, findings, the reviewer's signature, and an overall finding — and files it into your evidence. You don't generate these by hand; you review them where your evidence lives.


Permissions

Access is governed by two permissions in the role matrix.

CapabilityPermission
Browse the archive, open a record, download a packageVIEW_EVIDENCE
Generate a new self-assessment attestation and record the affirmationMANAGE_ORG

VIEW_EVIDENCE is held by every role, including Assessor — an external assessor can open and download any attestation but cannot create one. MANAGE_ORG is held by Org Admin and MSP Super (and Platform Admin) — so generating an attestation, like affirming on behalf of the organization, is reserved for administrators.

Attestations are records, not drafts — there is no edit. Once generated, a record's posture, affirmation, and fingerprints are fixed. To reflect new work, you generate a new attestation, which supersedes the old one without ever altering it.

How it works

Extra detail on what an attestation stores and how it behaves — product behavior, not internals.

What a snapshot freezes

Each self-assessment attestation captures a complete, self-contained picture of your posture at generation time.

Organization & assessment
Your organization's name and the assessment being attested, with its level and dates.
Score
0–110
The SPRS-style score, frozen — computed exactly as it appears live.
Objective posture
Counts of objectives met, partially met, not met, not applicable, and not yet assessed.
Systems in scope
The active systems and their environment type at the time of attestation.
Open POA&Ms
The remediation items still open, with their references and target dates.
Evidence coverage
How many distinct evidence artifacts back the assessment, and how many objectives they cover.
Participants
Who took part in the assessment, with their roles and dates.
Affirmation
The affirming official's name and title, and the moment the affirmation was recorded.

Why records never change

An attestation is written once and read back verbatim — the record you open is the frozen snapshot, not a fresh query against live data. That's deliberate: an affirmation has to stay truthful about the day it was made, even after your systems, findings, and POA&Ms have all moved on. Editing a live record after the fact would defeat the entire point of an attestation, so DIBFI doesn't allow it.

The tamper-evident chain

Records are linked in a hash chain, in order. Each record's chain fingerprint is derived from its own frozen posture and the fingerprint of the record before it. Anyone with the package can re-compute the fingerprints and confirm nothing was altered — and because the chain is sequential, tampering with an older record would visibly break every record that followed. The very first record is seeded from a fixed genesis marker.

CMMC artifact hashing (enterprise)

On enterprise plans, an attestation package can also include a CMMC artifact hash — a single fingerprint over your assessment artifacts, suitable for entry in the government's eMASS system. The package includes the material a reviewer needs to reproduce that hash independently.


Evidence Locker

Where the artifacts an attestation references — and automatic operational records — live.

Compliance Ops

Complete recurring reviews that automatically generate operational attestation records.

POA&M

The open remediation items an attestation freezes alongside your score.