CMMC 20X: A Working Blueprint for Securing the DIB

CMMC 20X: A Working Blueprint for Securing the DIB

Keep the Level 2 baseline. Change how it's verified. Deep Fathom's blueprint, reform analysis, and pilot proposal, published for the CMMC Reform Task Force.

Deep Fathom

The Defense Industrial Base is secured by systems that work: identities that are controlled, assets that are patched, data that can be recovered, actions that can be traced, and suppliers that can keep delivering when the mission depends on them. CMMC is useful when it tells the Department whether those things are true now.

Too often, the program asks a different question in practice: can a contractor reconstruct enough of the past to support a review?

That distinction is why we built CMMC 20X.

Cybersecurity is not paperwork. The security work should produce the proof.

CMMC 20X is our answer to a durable question: what would CMMC look like if it were designed to produce current security assurance across the entire DIB? The answer is a blueprint, a systems analysis of seven reform paths, a working system, and a proposed Government pilot, all published so they can be tested against hard cases.

The Department has already said the math doesn’t work

On July 13 the Department suspended CMMC Phase II and opened a 60-day review. The CIO put the problem plainly. More than 100,000 suppliers need a third-party assessment, roughly 100 assessors exist to do them, and in her words “the math just simply doesn’t math.” SBA estimated total compliance cost at about $388,600 per small firm for self-assessment and $593,800 for third-party certification, with more than 120,000 small businesses in scope. Those figures cover the whole effort, not just the assessment, and SBA hasn’t broken them down. The Under Secretary was equally clear that the standards themselves are not being relaxed.

So the Reform Task Force has a specific job to finish by mid-September: keep the security baseline, lower the barrier for small and nontraditional suppliers, and reach a scale the current model can’t.

CMMC should create current assurance

The security requirement isn’t the problem. Defense contractors that handle controlled information must protect it. The mission depends on that baseline.

The problem is how much of the surrounding system is built around recreating and transporting descriptions of security work after it happened.

A contractor collects screenshots, exports, policies, tickets, and explanations. An advisor reorganizes them. An assessor reconciles them before testing the implementation. A service provider answers similar questions for many customers. The same fact appears in an SSP, a spreadsheet, an evidence index, a readiness review, and an assessment package. Then the environment changes and every copy begins to age.

That activity can be necessary for a review without improving a single safeguard.

CMMC 20X starts one layer below the documents. An identity platform knows which accounts use MFA. A backup test records whether recovery worked. A ticket shows when a weakness was fixed. A provider knows what its service protects and what the customer still owns. Keep those facts connected to the requirements and claims they support. Generate the documents from that record instead of rebuilding the record for each new reader.

The RFI answers this year’s question

On August 13, Deep Fathom submitted its response to the CMMC Reform RFI. The filing asks the Department to preserve the Level 2 safeguard baseline while separating the cost of implementing security from the cost of producing and repeatedly verifying evidence. It proposes a common, vendor-neutral evidence profile, verification depth tied to risk and material change, and a controlled test of software-assisted review under accountable human authority.

The RFI addresses the immediate policy decision. CMMC 20X describes the system required to make the reform work.

Keep the safeguards. Change the verification.

CMMC Level 2 defines 110 safeguards. It shouldn’t force every supplier onto the same recurring third-party assessment cycle.

A two-person machine shop and a major prime may both handle CUI. Both must protect it. But their mission consequence, system scope, attack surface, supplier criticality, and available evidence can be radically different. Applying the same security baseline doesn’t require buying the same verification method for every contract.

Verification depth should follow consequence. Data sensitivity, mission consequence, threat exposure, supplier criticality, and material change set the tier. Evidence completeness and quality don’t set the tier. They drive sampling, correction, and escalation inside it. Missing, stale, or contradictory evidence triggers deeper, accountable human review at any tier. Independent or Government verification remains appropriate where data sensitivity or mission consequence demands greater confidence.

That is a different thing from self-attestation. Self-attestation failed because checking was the exception. Here every route gets checked. What varies is how deep. Consequence sets the depth. Evidence tells the reviewer where to look harder.

Software can do the repetitive work: map evidence to requirements, test freshness, identify conflicts, and prepare cited analysis. Qualified people still make the findings and decisions that matter.

Five principles, one boundary

The CMMC 20X Blueprint rests on five principles:

  1. Automation over documentation. Capture facts from the system or person that knows them. Generate documents from the connected record.
  2. Continuous over point-in-time. Reopen affected claims when a material change makes the old evidence incomplete or stale.
  3. Assessment-ready over dashboard-green. Prepare a record another qualified person can trace, test, challenge, and reproduce.
  4. Accessible over enterprise-only. Spend scarce supplier resources on safeguards and qualified help, not repeated package reconstruction.
  5. Ecosystem-wide over contractor-only. Let each party provide the proof for the work it performs without transferring its responsibility or authority.

All five preserve one boundary. Software can collect, map, compare, count, and identify conflicts. AI can prepare cited analysis. The authorized person owns the finding or program decision.

Reform choices change the whole system

Debates about CMMC reform often isolate one constraint: assessment capacity, evidence burden, supplier cost, or the depth of verification. The DIB doesn’t experience those constraints one at a time. Change one and the bottleneck can move somewhere else.

We built a systems model to examine those interactions. The CMMC 20X reform analysis compares seven policy paths from 2026 through 2049 across five headline outcomes: current assurance, suppliers lost, peak review backlog, modeled control exposure, and annual contractor burden. Each path uses the same assumptions and 100 paired runs.

Under the model, reopening without structural reform reaches 97 percent current assurance among the suppliers that remain, but loses 36 percent of the modeled supplier base and produces a peak review backlog of roughly 32,600 organizations. Coordinated reform reaches 91 percent current assurance with about 1 percent supplier loss and a peak backlog of roughly 7,400. Rescinding the program lowers mandate burden, but produces no current assurance and never reaches the modeled control-exposure target. The method, assumptions, and machine-readable results are public.

These are conditional model results, not predictions. They show mechanisms and tradeoffs, not what will happen. The strongest result comes from coordinating scope, evidence, verification, capacity, timing, and supplier burden, not from declaring one of them the answer.

We publish the model so it can be challenged rather than quoted. It was derived from a policy simulation engine we built earlier, then stripped of everything that wasn’t analytically load-bearing. The methodology page lists what was removed and why. Anyone who thinks that provenance disqualifies the results should make the case there.

A working system, and its limits

Deep Fathom built the working system behind CMMC 20X. It represents all 110 CMMC Level 2 requirements and 320 assessment objectives in a connected graph, keeps each requirement attached to its evidence, conflicts, findings and change history, and can flag what’s stale, broken, or contradictory.

It cannot certify a contractor. It cannot award a contract. It cannot turn an AI conclusion into Government acceptance. The demonstrations show what exists today. The pilot below is how anyone should decide whether to trust it.

Put it through a Government pilot

The next step should be a controlled pilot, not another round of generalized claims about automation.

Use the same frozen cases. Give ordinary review and several software-assisted implementations, ours among them, the same source material. Compare all of them against independently resolved findings. Measure accuracy, missed conflicts, reviewer effort, correction behavior, performance across supplier contexts, and resistance to misleading inputs. Keep the experimental output separate from certification, award, enforcement, and supplier status while the method is being tested.

We published a concrete pilot design because “use AI” is not a testable reform proposal. Government defines the protocol and the reference findings. No vendor grades its own system, and that includes us.

Where we stand, and what we’d gain

CMMC 20X is a Deep Fathom initiative. It is not an industry consensus, a certification, or a Government program. We own the argument and the work.

Deep Fathom also builds compliance software for the DIB, and adoption of some of this would benefit us. A common evidence profile is something our platform produces. An assisted-review tier is something it could serve. Knowing that, we’ve tried to keep the interest from steering the position. The evidence schema is public so any tool can implement it. Our RFI argues for keeping all 110 Level 2 requirements in the near term, though a smaller baseline would shrink the market we sell into. And the conditions under which this whole proposal should be abandoned are published alongside it. Judge the argument on the evidence. The disclosure is here so you don’t have to guess.

Work with us

Both the argument and the work will improve when they meet reality. We want hard cases from contractors and counterexamples from assessors. Service and technology providers can bring integration experience, researchers can challenge the model, and anyone who knows where software-assisted review fails can help shape the pilot. Most of all we want field experience from people who’ve watched a sound security program disappear inside a weak evidence package, or an apparently strong package collapse when someone tested the system underneath.

The Task Force reports in mid-September. If any of this is useful to that work, take it. It doesn’t need our name on it. If any of it is wrong, tell us before then.

Read CMMC 20X. Challenge the analysis. Download the briefing. Work with us.

The objective is not a cleaner compliance process. It is a more secure, resilient industrial base that can keep delivering for the mission, and a CMMC program capable of showing whether that is true.

An independent Deep Fathom publication. Not affiliated with, or endorsed by, the Department of War.

Photo: Willow Run, Michigan, July 1942. Ann Rosener / U.S. Office of War Information, Library of Congress.

References · 6 primary sources
SourceWhat it coversType
Department of War CMMC Phase II suspension and reform review announcementThe 60-day CMMC review, Phase II suspension, continuing Phase I and DFARS obligations, and the Department’s reform objectivesOfficial release
SBA statement on the CMMC Phase II suspension and small-firm compliance costsSBA’s July 13 estimate of small-firm compliance cost for self-assessment and third-party certification, and the small-business population affectedOfficial release
Deep Fathom CMMC Reform RFI ResponseDeep Fathom’s submitted answers and near-term reform recommendationsSubmitted response
The CMMC 20X BlueprintThe security thesis, five principles, operating loop, and ecosystem responsibilitiesPrimary publication
CMMC 20X Reform AnalysisSeven policy paths, five headline outcomes, detailed results, and downloadable dataPrimary research
CMMC 20X Analysis MethodologyModel boundary, assumptions, sensitivity tests, and interpretation guidanceResearch methodology