top of page
JFHQ-DODIN · DISA · DCSA
Cyber Operational Readiness Assessment
READY BEFORE THEY ARRIVE
THE PROGRAM
CCRI is gone. CORA is not the same test.

For more than a decade, the Command Cyber Readiness Inspection (CCRI) measured one thing: could you pass a scheduled compliance check. In March 2024, JFHQ‑DODIN, part of U.S. Cyber Command, retired the CCRI and stood up CORA in its place.

 

For NISP contractor networks specifically, DCSA executes the inspection and sets the compliance bar.

Inspections follow risk,
not rotation

CCRI ran on a fixed cycle. CORA assigns visits using a risk-based model. Mission criticality and threat exposure decide who gets inspected, and how often. Some networks face multiple assessments a year; others go longer between visits.

UP TO 15% OF FY26 INSPECTIONS: NO NOTICE

A risk rating,
not a pass/fail line

CCRI graded a fixed pass/fail line at 70. CORA scores hardening, attack-surface reduction, and proactive defense against Key Indicators of Risk (KIORs) built on the MITRE ATT&CK framework.

 

KIORS TRACK: INITIAL ACCESS · PRIV ESCALATION · LATERAL MOVEMENT · EXFIL

Short notice is now
the baseline

Assessments have historically arrived inside a 30-day window. Starting FY26, DCSA has stated a share of inspections will carry no advance notice at all.

ODP FINDINGS DRIVE ~50% OF CURRENT FAILURES

WHAT'S ON THE LINE
A failed CORA doesn't stay on paper.

DCSA ties network authorization directly to the CORA outcome. A failing mark isn't a finding you quietly remediate next quarter, it's a decision about whether your network stays connected.

CORA doesn't publish a single pass/fail line, it publishes a risk rating.

Typical unprepared

baseline

Wider Security

target

posture

risk scale.png

The goal isn't a passing score. It's a defensible one.

Disconnection is on the table

Failing networks can be taken offline until findings are remediated and re-validated.

Eligibility follows the connection

Work that depends on the network is exposed the moment the network is. Contract loss and reduced eligibility both flow from a failed assessment.

Policy gaps outweigh technical ones

Orders, Directives, and Policies (ODP) compliance is now the single largest driver of CORA failures, ahead of misconfiguration. It's the easiest category to under-prepare for.

Clean STIGs aren't the whole picture

MITRE ATT&CK-aligned Key Indicators of Risk are newly weighted criteria that can move a network's grade even when legacy hardening looks complete.

wise choice.png
Find out where your network actually stands.

A 30-minute readiness briefing tells you where you'd land on the CORA risk scale today before DCSA does.

 

Request a readiness briefing today.

bottom of page