---
title: DIBFI Documentation
description: Guides and reference for DIBFI — the platform that takes defense contractors from first scoping to CMMC certification and keeps them compliant afterward.
navigation:
  icon: i-lucide-book-open
---

# DIBFI Documentation

**DIBFI** is a compliance platform for defense contractors pursuing and maintaining **CMMC** (Cybersecurity Maturity Model Certification). It guides you through a structured journey — scope your environment, implement and document controls, gather evidence, score yourself against **SPRS**, manage risk and remediation, and stay compliant with recurring operations — all in one place. Managed Service Providers (MSPs) can run the same journey across many client organizations under their own branding.

::note
New here? Start with **Getting Started** to set up your organization, then follow the **CMMC Journey** — DIBFI's guided, phase-by-phase path to certification.
::

## Explore by area

:::card-group

::card{title="Getting Started" icon="i-lucide-rocket" to="/00-getting-started/onboarding"}
Set up your organization, invite your team, and understand roles and permissions.
::

::card{title="Assessment & Scoring" icon="i-lucide-clipboard-check" to="/01-assessment-and-scoring/assessments"}
Run CMMC assessments, track objectives, follow the guided journey, and watch your SPRS score.
::

::card{title="Evidence & Documents" icon="i-lucide-folder-lock" to="/02-evidence-and-documents/evidence-locker"}
Collect evidence, build policies, and generate your System Security Plan.
::

::card{title="Operations & Risk" icon="i-lucide-shield-alert" to="/03-operations-and-risk/risk-management"}
Manage risk, run recurring compliance tasks, and track remediation with POA&Ms.
::

::card{title="Billing & MSP" icon="i-lucide-credit-card" to="/04-billing-and-msp/billing-and-subscriptions"}
Manage your plan, and — for partners — run compliance across multiple clients.
::

::card{title="Integrations & AI" icon="i-lucide-bot" to="/05-integrations-and-ai/ai-connector"}
Connect Microsoft 365 and give an approved AI assistant read-only access to your data.
::

:::

## What you can do in DIBFI

:::card-group

::card{title="Know where you stand" icon="i-lucide-gauge"}
A live SPRS score, open gaps, and readiness — always up to date as you work.
::

::card{title="Prove it" icon="i-lucide-file-check"}
Evidence, policies, and a complete System Security Plan an assessor can review.
::

::card{title="Stay compliant" icon="i-lucide-calendar-check"}
Recurring compliance tasks and periodic risk reviews keep you audit-ready between assessments.
::

::card{title="Close the gaps" icon="i-lucide-list-checks"}
Track every weakness to remediation with risks and POA&Ms.
::

:::

::tip
Looking for a specific term? See the **Glossary** in the Reference section — it explains CMMC, SPRS, POA&M, SSP, CUI, and the other acronyms you'll meet along the way.
::
