# DIBFI Documentation > Documentation for DIBFI, a compliance platform that takes defense contractors from first scoping through CMMC certification and keeps them compliant afterward. ## Documentation Sets - [DIBFI Documentation (complete)](https://docs.dibfi.com/llms-full.txt) ## Getting Started - [Getting Started](https://docs.dibfi.com/raw/00-getting-started.md): Set up your organization, invite your team, and understand roles and permissions. - [Onboarding](https://docs.dibfi.com/raw/00-getting-started/onboarding.md): Set up a new organization the first time you sign in — choose your CMMC level, tell us what's in your environment, and get an initial set of systems and a first assessment scoped and ready to work. - [Organization Settings](https://docs.dibfi.com/raw/00-getting-started/organization-settings.md): Manage your organization's identity, the legal and personnel details that appear in your System Security Plan, connected integrations, and the security controls that govern AI assistant access. - [Roles & Permissions](https://docs.dibfi.com/raw/00-getting-started/roles-and-permissions.md): The roles in DIBFI and exactly what each one can see and do — for direct organizations, assessors, and MSP partners. ## Assessment & Scoring - [Assessments](https://docs.dibfi.com/raw/01-assessment-and-scoring/assessments.md): Track how your organization meets each CMMC practice and objective — set an implementation status and narrative for every objective, watch them roll up into practices, your SPRS score, and your open gaps. - [CMMC Journey](https://docs.dibfi.com/raw/01-assessment-and-scoring/cmmc-journey.md): DIBFI's guided, phase-by-phase path from first scoping to certification — always showing your current phase and the single best next step. - [Assessment & Scoring](https://docs.dibfi.com/raw/01-assessment-and-scoring.md): Run CMMC assessments, track objectives, follow the guided journey, and watch your SPRS score. - [Self-Assessment](https://docs.dibfi.com/raw/01-assessment-and-scoring/self-assessment.md): Work through your CMMC objectives one at a time, record a determination and narrative for each, and watch your SPRS score update live as you go. - [SPRS Score](https://docs.dibfi.com/raw/01-assessment-and-scoring/sprs-score.md): Your SPRS score is the single number that summarizes CMMC Level 2 readiness. Learn how it's calculated, why controls are weighted, and how to raise it fastest. - [Systems & Objectives](https://docs.dibfi.com/raw/01-assessment-and-scoring/systems-and-objectives.md): Catalog the systems in your CUI environment, categorize each by its role in scope, and work every control objective against them — the day-to-day compliance work that drives your assessment, SPRS score, and SSP. - [Assessment Workbench](https://docs.dibfi.com/raw/01-assessment-and-scoring/workbench.md): Review a single objective in depth — its 800-171A guidance, the implementation narrative, linked evidence, and recorded interviews and tests — in one focused workspace built for internal validation before a formal assessment. ## Evidence & Documents - [Asset Inventory](https://docs.dibfi.com/raw/02-evidence-and-documents/asset-inventory.md): Build a categorized inventory of every asset in your CMMC environment, classify each one by CUI scope to define your assessment boundary, and track what still needs review. - [Attestations](https://docs.dibfi.com/raw/02-evidence-and-documents/attestations.md): Freeze your compliance posture into tamper-evident, point-in-time attestation records, capture a senior official's affirmation, and keep a permanent, downloadable archive for auditors. - [Document Library](https://docs.dibfi.com/raw/02-evidence-and-documents/document-library.md): Generate, edit, review, approve, and publish the policies CMMC requires — with merge fields, CMMC clause highlighting, full revision history, and PDF/Word export. Publishing turns a policy into control-linked evidence. - [Evidence Locker & Requests](https://docs.dibfi.com/raw/02-evidence-and-documents/evidence-locker.md): Collect, store, organize, and maintain the evidence that proves each CMMC objective is met — upload files or links, link them to objectives, track expiry, and request evidence from your team. - [Evidence & Documents](https://docs.dibfi.com/raw/02-evidence-and-documents.md): Collect evidence, build policies, and generate your System Security Plan. - [SSP Builder](https://docs.dibfi.com/raw/02-evidence-and-documents/ssp-builder.md): Assemble a complete, assessor-ready System Security Plan — organization and system details, boundary, asset inventory, external providers, interconnections, diagrams, and per-control implementation narratives — then preview, print, or export it to PDF. ## Operations & Risk - [Compliance Operations](https://docs.dibfi.com/raw/03-operations-and-risk/compliance-operations.md): Keep your CMMC posture current between assessments with a calendar of recurring compliance tasks — scheduled by cadence, completed with a guided checklist, and turned into dated evidence automatically. - [Operations & Risk](https://docs.dibfi.com/raw/03-operations-and-risk.md): Manage risk, run recurring compliance tasks, and track remediation with POA&Ms. - [POA&M](https://docs.dibfi.com/raw/03-operations-and-risk/poam.md): Track remediation of compliance gaps and risks as a Plan of Action & Milestones — targets, milestones, status, and system scope — and see how open and overdue items shape your SPRS score and posture. - [Reviews & Readiness](https://docs.dibfi.com/raw/03-operations-and-risk/reviews-and-readiness.md): Request an expert reviewer to validate your evidence, SSP, and scope before a formal C3PAO assessment, receive a readiness score and written findings, and track each review from request to completed report. - [Risk Management](https://docs.dibfi.com/raw/03-operations-and-risk/risk-management.md): Identify, score, treat, and review information-security risks against a 5×5 model, link them to POA&Ms, and track your active risk posture over time. ## Billing & MSP - [Billing & Subscriptions](https://docs.dibfi.com/raw/04-billing-and-msp/billing-and-subscriptions.md): Choose a plan, track your assessment, user, and storage usage against its limits, manage your payment method and invoices, and cancel or reactivate — all from one billing page. - [Billing & MSP](https://docs.dibfi.com/raw/04-billing-and-msp.md): Manage your plan, and — for partners — run compliance across multiple client organizations. - [MSP Portal](https://docs.dibfi.com/raw/04-billing-and-msp/msp-portal.md): Run CMMC compliance across many client organizations from one place — manage and onboard clients, watch every client's readiness at a glance, reuse shared templates, and put your own brand on the platform. ## Integrations & AI - [AI Connector](https://docs.dibfi.com/raw/05-integrations-and-ai/ai-connector.md): Give an approved AI assistant read-only, permission-scoped access to your compliance data so it can answer posture, SPRS, gaps, evidence, risk, and POA&M questions and guide your CMMC journey. - [Integrations & AI](https://docs.dibfi.com/raw/05-integrations-and-ai.md): Connect Microsoft 365 and give an approved AI assistant read-only access to your data. - [Microsoft 365 Integration](https://docs.dibfi.com/raw/05-integrations-and-ai/microsoft-365.md): Connect your Microsoft 365 tenant so DIBFI can read configuration signals from Entra and Intune, turn them into CMMC findings, and pre-fill implementation status and statements on your assessment. ## Platform & Admin - [Appearance & Layout](https://docs.dibfi.com/raw/06-platform-and-admin/appearance.md): Personalize how the app looks and lays out for you — light or dark mode, color theme presets, sidebar style, content width, and navbar behavior — with your choices remembered across sessions. - [Platform & Admin](https://docs.dibfi.com/raw/06-platform-and-admin.md): Platform administration, appearance and branding, and the CMMC Rev 3 transition. - [Revision 3 Transition](https://docs.dibfi.com/raw/06-platform-and-admin/rev3-transition.md): Prepare for the NIST SP 800-171 Revision 3 update — set organization-defined parameters (ODPs), see how each control changes between Rev 2 and Rev 3, and opt in to the Rev 3 experience early. ## Reference - [Glossary](https://docs.dibfi.com/raw/99-reference/glossary.md): Plain-language definitions of the CMMC, NIST, and DIBFI terms you'll meet throughout the platform. - [Reference](https://docs.dibfi.com/raw/99-reference.md): Definitions for CMMC, SPRS, POA&M, SSP, CUI, and the other terms you'll meet in DIBFI. ## Notes - DIBFI covers CMMC (Cybersecurity Maturity Model Certification) readiness for defense contractors. - Core topics: assessments and scoring, SPRS, evidence collection, SSP generation, POA&Ms, risk management, recurring compliance operations, and MSP multi-client management. - The DIBFI application itself is a separate site at https://app.dibfi.com.