Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
LEADERSHIP SELF-CHECK · 12 ACTIONS · ANSWERS STAY IN THIS BROWSER

The twelve actions, honestly rated

Twelve governance actions that carry contractual or legal consequence today — independent of whether a certification assessment is scheduled. Rate where you honestly stand. Nothing is sent unless you choose to email it.

A01 Freeze the phase calendar — not the security program

Remove November 2026/2027/2028 certification assumptions from operating plans until revised guidance is issued, while continuing funded remediation and evidence development.

A02 Reconfirm clause and data scope

Map FCI, CUI, CDI and export-controlled information to contracts, systems, users, suppliers and services. Distinguish clause applicability from generalized data sensitivity.

A03 Validate every SPRS score

Reconcile the posted score to the current SSP, scoring methodology, objective-level evidence, POA&Ms and system boundary. Correct unsupported claims through the appropriate process.

A04 Maintain a CMMC-ready evidence package

Keep the asset inventory, network diagram, SSP, policies, procedures, technical artifacts, interview owners and evidence current even while third-party designations are suspended.

A05 Reassess cloud and external service provider dependencies

Validate the exact offering's authorization or equivalency, incident terms, forensic access, shared-responsibility matrix, assessment treatment, source allowability and export-personnel model.

A06 Build an AI and ICT dependency register

Maintain an AIBOM/SBOM covering models, APIs, hosting platforms, agents, libraries, data sources, routing services, embedded integrations, subprocessors and downstream consumers.

A07 Create a source-allowability gate

Require contract, program, supply-chain and legal review before a new AI or ICT source enters a defense workflow. Do not treat FedRAMP or CMMC eligibility as approval for every contract.

A08 Control vendor-removal migrations

Confirm scope with the contracting officer; preserve incident and audit evidence; export only authorized records; revoke keys; validate retention and deletion; reassess the replacement; document cost and schedule effects.

A09 Design for portability

Use modular integrations, controlled prompt and configuration repositories, portable test suites and multi-vendor contingency plans so a source restriction does not become an operational outage.

A10 Establish an affirmation governance gate

Require scope confirmation, control-owner attestation, evidence review, legal/compliance review and documented exceptions before an affirming official submits an annual statement.

A11 Build the Rev. 3 delta backlog

Maintain Rev. 2 compliance as the contractual baseline while mapping Revision 3 families, organization-defined parameters and supply-chain requirements for planned uplift.

A12 Monitor the live policy events

Track post-review CMMC guidance, the final disposition of the FAR CUI proposal, and any source-restriction direction. Update contract playbooks only when official text or direction changes.

0 / 12 rated