How to Approach a CMMC Self-Assessment: A Small DIB Walkthrough
In the current phase, many contracts accept a self-assessment. Here's the generic process — scope, evidence, SSP, POA&M, score — for a small DIB team.
What a self-assessment is
In the current phase of the CMMC rollout, many applicable contracts accept a self-assessment — you evaluate your own program against the requirements rather than bringing in a third-party assessor. For Level 2 / NIST SP 800-171, that includes calculating a score using the DoD methodology and posting it in SPRS.
This article is generic and educational. A self-assessment is something you perform, using qualified internal personnel or a qualified advisor. DIBStack provides tools to help you organize the evidence; it does not perform, score, or interpret your assessment, and nothing here determines your result. Use the authoritative sources for the methodology and the requirements.
The generic shape of the process
Every small team’s path looks a little different, but the steps are broadly the same:
- Define your scope. Identify the FCI and CUI you handle and where it lives, and draw the boundary of the systems in scope. A scoping workbook helps you think this through.
- Gather and organize your evidence. For each area, collect the artifacts that show what you actually do — screenshots, exports, records, logs, approvals — and file them consistently. This is the part that makes or breaks the effort, and it’s where a folder structure and an owner per artifact pay off.
- Document your system. Write a System Security Plan describing your environment and how you address each family, in your own words.
- Track the gaps. Record items you’re still working on in a POA&M, with owners and target dates.
- Score and report. For Level 2 / 800-171, calculate your score using the DoD assessment methodology and post it in SPRS as your contracts require. The scoring and the reporting are yours to perform.
Honesty beats optimism
The most common self-assessment mistake is scoring to a number you wish were true. A self-assessment that overstates your posture helps no one — least of all you when a prime or a later third-party assessment looks closely. Record what’s real, track the rest in your POA&M, and keep the evidence current.
Read it at the source
- NIST SP 800-171A — assessment procedures and evidence planning: https://csrc.nist.gov/pubs/sp/800/171/a/final
- DFARS 252.204-7019 / 7020 — the DoD assessment and SPRS posting requirements: https://www.ecfr.gov/current/title-48/chapter-2/subchapter-H/part-252/subpart-252.2/section-252.204-7020
- NIST SP 800-171 Rev. 2 — the requirements themselves: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final
See the full regulatory sources guide.
Organizing the evidence behind the score
A self-assessment is only as credible as the evidence behind it. The DIBStack Evidence Binder gives you a standardized way to organize that evidence — folders, checklists, inventories, the SSP outline, and the POA&M tracker — as blank templates you complete yourself. It helps you organize; it does not perform, score, or interpret your self-assessment, or determine whether your organization is compliant.
Related product
DIBStack Evidence Binder
Folder structures, evidence checklists, workbooks, logs, and templates for organizing cybersecurity evidence.
View DIBStack Evidence Binder