CMMC20X
Authorship and intent

We built the working system behind CMMC 20X.

CMMC 20X is Deep Fathom’s public position on how CMMC should work, backed by working software, a policy model, synthetic examples, and public methods.

CMMC should show what is secure now, what evidence supports that conclusion, and what changed. Today, contractors and reviewers still spend too much time reconstructing those answers from files.

We think the security work should produce reusable evidence. Providers should supply their part. Contractors should keep their part current. Assessors should test the hard questions. Software should do the repeatable collection and comparison.

This site publishes the argument, the working example, the program analysis, the current reform recommendation, and the limits of what we have proved so far.

Here is what we have actually built.

Deep Fathom builds security and compliance software for the Defense Industrial Base. Its working platform represents all 110 NIST SP 800-171 Revision 2 requirements and all 320 CMMC Level 2 assessment objectives in one graph.

The graph connects systems, boundaries, controls, implementation statements, evidence, inherited responsibilities, findings, and remediation. The same source information can support human-readable SSP and assessment views and machine-readable exchange.

Machine assistance can map evidence, identify missing or conflicting support, and draft candidate findings. A human reviewer confirms, changes, or rejects the conclusion. The software does not confer certification, Government acceptance, or procurement status.

Visit Deep Fathom Follow the evidence lifecycle
Keep the claims straight

What we believe. What we built. What needs to happen next.

  1. №01

    Published position

    CMMC 20X is a Deep Fathom initiative. The published position is ours. Participation does not turn it into industry consensus or Government policy.

  2. №02

    Working capability

    Deep Fathom has implemented the full Level 2 requirement and objective model, links claims to evidence, uses software to flag gaps, and records the human reviewer’s finding separately.

  3. №03

    Proposed mechanism

    The common evidence profile, graduated verification model, and provider-evidence framework require open development, policy definition, and independent testing.

  4. №04

    Authorized decision

    Only authorized assessors, contracting officials, affirming officials, and Government decision-makers can give conclusions their program or contractual effect.

Who is making the argument

Deep Fathom publishes CMMC 20X.

CMMC 20X is a Deep Fathom-owned and managed initiative. It is not affiliated with or endorsed by the Department of War, the Cyber AB, or any assessment organization, and it does not claim to represent industry consensus. Deep Fathom advances the position publicly so it can be tested, criticized, improved, and—where it proves useful—adopted.

Organizations can contribute cases, criticism, technical review, interoperability work, evaluation support, or distribution without endorsing every CMMC 20X recommendation.

We publish sources and model assumptions. The CMMC Reform Analysis is conditional, not a forecast. Our working AI-assisted review system is ready for independent evaluation against Government-selected cases, reviewers, measures, and operating constraints.

Work with us

Put the model through its hardest tests.

Government offices can sponsor a controlled pilot. Organizations across the ecosystem can contribute difficult cases, technical review, interoperable workflows, or distribution.