A Growing Assessment Center
DIBCAC operates within the Defense Contract Management Agency. When DCMA established the center in 2019, it opened with 42 employees. By August 2024 the agency described a center of approximately 135 personnel, and the FY2027 budget documentation shows the trajectory continuing.
The funded expansion. DCMA's cyber assessment workforce grows from 141 civilian positions in FY2025 to 147 in FY2026 and, under the FY2027 request, to 167. The FY2026 increase established one additional functional assessment team expected to perform approximately 20 additional assessments annually. The FY2027 request adds three more teams and 65 additional assessments annually.
The two tracks. The July 2026 suspension of CMMC Phase II addressed the schedule for requiring third-party certifications in contracts. This budget line funds the government's own assessment workforce, which operates under DFARS clauses that remain in contracts today. Nothing in the budget documentation conditions the hiring plan on the Phase II schedule.
How Selection Concentrates
Exposure begins with the contract. DFARS 252.204-7012 obligates a contractor handling covered defense information to implement NIST SP 800-171, and DFARS 252.204-7020 requires the contractor to provide access to its facilities, systems, and personnel when the government conducts a Medium or High assessment. Any contractor holding the clause can lawfully be selected, and consent isn't part of the process.
The raw odds are low. Against a Defense Industrial Base of approximately 220,000 entities, of which roughly 80,000 handle CUI, DIBCAC's volume runs in the low hundreds of assessments per year, an undifferentiated base rate below one percent. That figure is a ceiling for the population rather than a probability for any particular company, because selection isn't random. A capacity measured in hundreds can't be spent randomly across a population measured in tens of thousands and still produce useful oversight, so selection concentrates where program criticality, CUI volume, and supply chain position intersect.
The subcontractor mechanism. When DIBCAC assesses a prime or mid-tier contractor, the System Security Plan, data flow diagrams, and subcontract records identify by name the downstream companies that receive CUI from the assessed environment. Every one of those subcontractors already holds the access clause through mandatory flowdown.
What that means. An assessment of a prime converts its subcontractors from anonymous entries in a population of tens of thousands into named CUI recipients on a program the Department has already prioritized. A subcontractor's exposure can begin with someone else's assessment.
The Notification Starts a Clock
No official template of a DIBCAC notification letter is published, and the pattern practitioners report reflects the accounts of assessed contractors rather than a government publication. The notification generally arrives as official DCMA correspondence, commonly by email to an executive or point of contact associated with the company in the System for Award Management. It directs the contractor to acknowledge receipt and designate a technical point of contact within a few business days, and it requests the current SSP, the POA&M, and network architecture diagrams. For Medium Assessments, assessed contractors have described document requests due within roughly one to two business weeks. For High Assessments, reported notice generally runs about 30 days. Because the access requirement is a contract term, the assessment itself isn't negotiable. The variables available to the contractor are scheduling details and the quality of what it produces.
The Evidence, Including the Truth About Log Retention
The full paper catalogs eleven evidence categories assessors consume, from the core documents through configuration baselines, audit logs, external provider documentation, and FIPS 140 validation certificates. It also settles a question that circulates with a wrong answer attached: no fixed number of years of log retention exists in the governing documents. The assessor scores retention against the period the contractor's own SSP defines. The only hard figure in the regime is the 90-day preservation of system images and packet capture data after a cyber incident report, and the six-year figures in industry guidance trace to the False Claims Act limitations period rather than to any log requirement.
How the Assessment Ends
Scoring follows the DoD Assessment Methodology: 110 requirements weighted at five, three, or one point, deducted from a perfect 110 with a floor of negative 203, verified against the assessment objectives in NIST SP 800-171A. The Department posts Medium and High summary scores to SPRS beside the self-reported Basic score, and the government's number is the one contracting officials weigh. Before posting, the contractor receives the score with an opportunity for rebuttal and adjudication, including 14 business days to provide additional evidence. The paper also explains how CMMC Level 3 assessments under 32 CFR part 170 differ from the Medium and High assessments that make up the bulk of DIBCAC's contractor-facing work.
A Test Any Executive Can Run
The paper closes with a one-day self-test. Ask the IT lead or managed service provider for four items within one business day: the current SSP, the POA&M, the network and CUI data flow diagrams, and audit logs covering a recent 30-day window. The request should arrive without advance warning, because a DIBCAC notification arrives the same way. Documents delivered within the day and consistent with the reported SPRS score indicate a company that would meet a real notification on its own terms. Documents that can't be produced at all indicate a reported score resting on implementation the company can't currently evidence, which is precisely the condition a Medium or High Assessment converts into a recorded government score.
Download the Full White Paper
The full paper covers the FY2026 and FY2027 capacity expansion with the budget figures, the contractual basis for selection and the base-rate arithmetic, the subcontractor visibility mechanism, the notification pattern and reported timelines, the eleven evidence categories with the log retention analysis, Medium and High assessment mechanics and scoring, SPRS posting and the rebuttal process, the CMMC Level 3 distinction, and the one-day executive test with a schedule for genuine self-audits. Claims are supported by citations to the FY2027 budget justification books, the DFARS clauses, the DoD Assessment Methodology, NIST SP 800-171A, 32 CFR part 170, and DCMA's published assessment materials.
The CMMC Decision, Second Edition
Strategic guide for CEOs and senior executives of small and mid-sized defense contractors. Level determination, enforcement timelines, certification economics, and the governance questions executives cannot delegate to the IT organization.
Read More →