DIBCAC Assessment: No Tricks, No Treats, Just the Facts

Before DIBCAC Comes Calling: What Contractors Need to Know

DATE

28 OCT 2026

TIME

9:00am PT | 12:00pm ET

Register today!

By completing this form, I consent to receiving calls, texts and/or emails from CyberSheath regarding services and programs.

A DIBCAC assessment shouldn't come with surprises.

For defense contractors, demonstrating implementation of NIST SP 800-171 requires more than having policies and security controls in place. Your documentation, evidence, and actual practices should align and demonstrate that the security requirements described in your System Security Plan are implemented in practice.

This webinar will take you inside the DOD assessment process, including what can lead to an assessment, what assessors evaluate, and what contractors should expect before, during, and after the assessment. We'll also share lessons learned from assessment preparation and remediation to help you identify potential gaps before they are identified by the government.

What You'll Learn

What tends to catch contractors off guard during an assessment? Where do organizations struggle most? And what separates those that are prepared from those that aren't?

We'll share patterns and lessons learned from assessment preparation and remediation, including common misconceptions, recurring challenges, and practical advice for contractors preparing today.

By the end of this session, you'll have a better understanding of:

  • DIBCAC’s role and when assessments occur
  • What to expect from Medium and High assessments
  • What assessors look for in your SSP, controls, and evidence
  • Common assessment gaps and how to prepare
  • How DIBCAC and C3PAO assessments differ within CMMC

Why Attend?

A successful assessment requires more than checking compliance boxes. Contractors need to be able to demonstrate that documented policies and practices reflect what's actually happening in their environment.

Drawing on experience supporting organizations through assessment preparation and remediation, this session will explore where contractors commonly struggle, misconceptions that can create problems, and practical steps organizations can take to prepare.

You'll walk away with a clearer picture of the DIBCAC assessment experience and how to strengthen your documentation, evidence, and cybersecurity program before an assessment begins.

Who Should Attend?

  • Defense contractors subject to NIST SP 800-171 and DFARS requirements
  • Organizations preparing for or anticipating a DIBCAC assessment
  • Executives responsible for cybersecurity and compliance strategy
  • IT and security leaders responsible for NIST SP 800-171 implementation
  • Compliance teams responsible for SSPs, evidence, and assessment readiness
  • Program and contract managers supporting DoD contracts
  • Organizations preparing for CMMC assessments

Next Steps

Don't wait until an assessment is underway to find the gaps. Reserve your spot today to learn what DIBCAC looks for, what to expect during an assessment, and how to prepare before DCMA comes calling.

Andrew Zoppi CyberSheath Director of Compliance Operations

Andrew Zoppi

CyberSheath Compliance

Andrew Zoppi has over 12 years of experience in cybersecurity, information technology, and cyber innovations, holding various positions in the Department of Defense, academia, and consulting firms. He has extensive expertise in serving as a trusted advisor to leadership and stakeholders in designing a security program that complies with regulations.