Primary sources Primary resources

Primary Resources for Readiness and Review

The references behind our readiness and review proposition, collected for convenient access. Publisher, version, and relevance accompany each link.

The summaries reflect our source review. Publishers maintain the original documents. Deep Fathom's collaboration perspectives are our own interpretation.

Department of War CIO External reference

CMMC Phase II implementation procedures, Attachment 1

The implementation procedures address permitted assessment designations during the suspension and retain DFARS 7012 requirements. They provide the policy context for our discussion, without establishing the eventual reform outcome.

July 2026

Cyber AB External reference

Statement on Phase II suspension

The Cyber AB statement addresses the continued availability of program elements, including C3PAO Level 2 certification assessments. It complements the government implementation direction above.

July 15, 2026

Cyber AB External reference

C3PAO Accreditation Requirements

R2002 addresses accreditation, ancillary services, and impartiality. It is part of the governing context for the client and platform relationships discussed in our proposal.

v1.0, January 2026

Cyber AB External reference

Code of Professional Conduct

The Code addresses professional conduct and conflicts, including advisory activity and conditions for formal non-certification assessments. Our proposed collaboration creates no exception to those conditions.

v2.0, effective December 2024

Department of Defense CIO External reference

CMMC Assessment Guide Level 2

The official Level 2 assessment guide references NIST SP 800-171 Revision 2. It is included as the CMMC-specific assessment reference for this collection.

v2.13, September 2024

NIST External reference

NIST SP 800-171A Revision 3

NIST's Revision 3 assessment methodology provides broader context for the discussion of professional scrutiny. This entry is contextual. The CMMC Level 2 guide above references Revision 2.

May 2024

eCFR External reference

32 CFR Part 170

32 CFR Part 170 contains the CMMC program's regulatory framework, alongside the separate operative implementation direction.

Current online edition

Department of War CIO External reference

CMMC Resources and Documentation

The CMMC resources and documentation page provides a maintained starting point for official guides and program sources.

Current online index

NIST External reference

NIST SP 800-171 Revision 2

Security assessment requirements address periodic assessment, ongoing monitoring, and updating system security plans. These support the discussion of maintaining a compliance position.

February 2020, updated January 2021

Federal Register External reference

CMMC Program Final Rule

The program rule includes affirmations of continuing compliance in section 170.22. Read it alongside current implementation direction.

October 15, 2024

U.S. Department of Justice External reference

Civil Cyber-Fraud Initiative

DOJ describes False Claims Act enforcement for knowing cybersecurity misrepresentations and related misconduct. This is the context for the supplier-accountability discussion.

October 6, 2021; updated February 6, 2025

Explore working together

Talk with us about your practice.

Tell us which services your firm provides and where you see opportunity. Our team will discuss the relevant platform workflow and ways to work together.

There is no need to bring a client engagement to the first conversation.

A conversation about your practice

Include whether readiness, ongoing client support, independent review, or another arrangement interests you.

Email Deep Fathom

Opens your email app. Already know someone at Deep Fathom? Reply to them directly.

Please keep client evidence and sensitive information out of an introductory inquiry.