---
title: Attestations
description: Freeze your compliance posture into tamper-evident, point-in-time attestation records, capture a senior official's affirmation, and keep a permanent, downloadable archive for auditors.
navigation:
  icon: i-lucide-award
---

# Attestations

The **Attestations** archive is your permanent record of what you affirmed, and when. Each attestation is a **point-in-time snapshot** of your compliance posture — your score, your findings, your systems, and your open remediation items — frozen at the moment of generation and preserved unchanged, even as the underlying data keeps moving.

CMMC and DFARS **252.204-7012** expect a **senior official to affirm** that your organization meets its security requirements. This is where that affirmation is captured and kept: a named official, a confirmed affirmation, and an immutable package an auditor can open, download, and independently verify — today or years from now.

::note
Find it in the sidebar under **Attestations** (`/dashboard/attestations`). Every role that can view evidence can browse the archive and download records; generating a new attestation is limited to organization administrators — see [Permissions](#permissions).
::

---

## Key concepts

### What an attestation is

In CMMC, an **attestation** (or **affirmation**) is a senior official's formal statement that the organization's security posture is accurate as represented. DIBFI turns that statement into a **verifiable artifact**: a sealed record that pins your posture to a specific date and can never be silently edited afterward.

### Two kinds of record

The archive holds two kinds of attestation, and they arrive by different paths.

| Kind | How it's created |
| --- | --- |
| **Self-assessment attestation** | You **generate** it on demand from a chosen assessment. It freezes your full posture and captures the affirming official. |
| **Operational attestation record** | **Generated automatically** when a recurring compliance operations task is completed, and filed into your evidence as a signed record of that review. |

### Record state

An assessment has one **current** attestation at a time. Generating a new one **supersedes** the previous record — the old one is never deleted, it's retained in full and marked as history.

| State | Meaning |
| --- | --- |
| :badge[Current]{color="success"} | The latest attestation for the assessment |
| :badge[Superseded]{color="neutral"} | Replaced by a newer attestation — kept for the audit trail |

### Integrity fingerprints

Every attestation carries three cryptographic fingerprints that make it **tamper-evident**. If anything in a record changes, the fingerprints no longer match.

| Fingerprint | What it covers |
| --- | --- |
| **Snapshot hash** | The frozen posture (score, findings, systems, POA&Ms) |
| **Package hash** | The exact bytes of the downloadable package |
| **Chain hash** | This record **plus** the one before it, linking the whole sequence |

::tip
The **chain hash** is what makes the archive tamper-evident as a *sequence*: because each record's chain hash folds in the previous record's, altering any older attestation would break every record that came after it. The first record in your history is seeded from a fixed genesis value.
::

### Overall finding (operational records)

Automatically generated operational attestations carry a plain-language verdict for the review period.

| Finding | Meaning |
| --- | --- |
| :badge[None]{color="success"} | No issues found during the review |
| :badge[Minor]{color="warning"} | Minor issues noted |
| :badge[Major]{color="error"} | Significant issues requiring attention |

---

## Using Attestations

The Attestations page lists your archive newest-first, with each record's number, score, and integrity fingerprints. Once you have two or more, a **score progression** chart shows how your posture has moved over time.

### Generate a self-assessment attestation

Generating an attestation freezes your posture and captures the affirming official in a single, sealed record.

::steps{level="4"}

#### Choose an assessment

Start a new attestation and pick the **assessment** you want to attest. DIBFI runs a **readiness check** and shows exactly what will be frozen — your score, your objective counts, and your open POA&Ms.

#### Clear any blockers

Some conditions **block** generation because they would freeze a misleading record — for example, an assessment where nothing has been assessed yet, or one with no active system in scope. Unassessed objectives that remain are allowed, but you'll see a **warning** (they count against your score).

#### Name the affirming official

Enter the **name** and **title** of the senior official making the affirmation. This is recorded on the sealed record.

#### Confirm the affirmation

Confirm the **DFARS 252.204-7012** affirmation to proceed. Generation won't continue without it.

#### Generate

DIBFI freezes the posture, assembles the package, and files the record. It becomes your **current** attestation and supersedes the previous one.

::

::note
The score in an attestation is computed with the **same method** you see live on your dashboard and workbench — a frozen attestation can never diverge from the number you saw when you generated it.
::

### Download a record

Open any record to see its full frozen posture and integrity fingerprints, then download its **package** — a complete, self-contained set of documents (score summary, methodology, assessment record, score worksheet, POA&M list, evidence summary, asset scope, and a DFARS 7012 checklist). The package is immutable and remains downloadable for the life of the record.

::tip
Every download link is generated fresh and expires quickly, so records stay private to people who are signed in and authorized — but the archive itself keeps the package available indefinitely.
::

### Review an operational attestation

When a recurring compliance operations task is completed, DIBFI **automatically generates** a formal attestation record for that review — with the task, period, systems reviewed, findings, the reviewer's signature, and an overall finding — and files it into your evidence. You don't generate these by hand; you review them where your evidence lives.

---

## Permissions

Access is governed by two permissions in the role matrix.

| Capability | Permission |
| --- | --- |
| Browse the archive, open a record, download a package | :badge[VIEW_EVIDENCE]{color="neutral"} |
| Generate a new self-assessment attestation and record the affirmation | :badge[MANAGE_ORG]{color="info"} |

`VIEW_EVIDENCE` is held by **every** role, including Assessor — an external assessor can open and download any attestation but cannot create one. `MANAGE_ORG` is held by **Org Admin** and **MSP Super** (and Platform Admin) — so generating an attestation, like affirming on behalf of the organization, is reserved for administrators.

::warning
Attestations are **records, not drafts** — there is no edit. Once generated, a record's posture, affirmation, and fingerprints are fixed. To reflect new work, you generate a **new** attestation, which supersedes the old one without ever altering it.
::

---

## How it works

Extra detail on what an attestation stores and how it behaves — product behavior, not internals.

### What a snapshot freezes

Each self-assessment attestation captures a complete, self-contained picture of your posture at generation time.

:::field-group
::field{name="Organization & assessment"}
Your organization's name and the assessment being attested, with its level and dates.
::
::field{name="Score" type="0–110"}
The SPRS-style score, frozen — computed exactly as it appears live.
::
::field{name="Objective posture"}
Counts of objectives met, partially met, not met, not applicable, and not yet assessed.
::
::field{name="Systems in scope"}
The active systems and their environment type at the time of attestation.
::
::field{name="Open POA&Ms"}
The remediation items still open, with their references and target dates.
::
::field{name="Evidence coverage"}
How many distinct evidence artifacts back the assessment, and how many objectives they cover.
::
::field{name="Participants"}
Who took part in the assessment, with their roles and dates.
::
::field{name="Affirmation"}
The affirming official's name and title, and the moment the affirmation was recorded.
::
:::

### Why records never change

An attestation is written **once** and read back **verbatim** — the record you open is the frozen snapshot, not a fresh query against live data. That's deliberate: an affirmation has to stay truthful about the day it was made, even after your systems, findings, and POA&Ms have all moved on. Editing a live record after the fact would defeat the entire point of an attestation, so DIBFI doesn't allow it.

### The tamper-evident chain

Records are linked in a **hash chain**, in order. Each record's chain fingerprint is derived from its own frozen posture **and** the fingerprint of the record before it. Anyone with the package can re-compute the fingerprints and confirm nothing was altered — and because the chain is sequential, tampering with an older record would visibly break every record that followed. The very first record is seeded from a fixed genesis marker.

### CMMC artifact hashing (enterprise)

On enterprise plans, an attestation package can also include a **CMMC artifact hash** — a single fingerprint over your assessment artifacts, suitable for entry in the government's eMASS system. The package includes the material a reviewer needs to reproduce that hash independently.

---

## Related features

:::card-group

::card{title="Evidence Locker" icon="i-lucide-folder-lock" to="https://app.dibfi.com/dashboard/systems"}
Where the artifacts an attestation references — and automatic operational records — live.
::

::card{title="Compliance Ops" icon="i-lucide-calendar-check" to="https://app.dibfi.com/dashboard/compliance-ops"}
Complete recurring reviews that automatically generate operational attestation records.
::

::card{title="POA&M" icon="i-lucide-list-checks" to="https://app.dibfi.com/dashboard/poam"}
The open remediation items an attestation freezes alongside your score.
::

:::
