What question the curves answer
This is a comparative stock-and-flow model of seven policy options for CMMC’s next phase, not a prediction of a particular Department decision. It asks whether the mechanism and sequence of one option behave differently from another under the same starting population, exogenous world shocks, time horizon, and stated assumptions.
That separation matters. A percentile band that pooled an effective rule, a delayed rule, a failed congressional action, and a vacated rule would describe no coherent operating regime. The primary chart therefore estimates the system conditional on the named portfolio becoming effective and resourced. A separate first-attempt branch reports legal and process implementation risk through 2035.
The analytical run removes the interactive game’s political-capital economy, terminal loss conditions, map, and fictional narrative. It retains the same tested engine, intervention dependencies, implementation delays, queues, validity clocks, supplier pressure, and seeded uncertainty.
One baseline, three verification routes
Organizations first do the underlying safeguard work. Only implemented organizations can enter a route. Route assignment changes the depth and capacity of review; it never changes mission risk and never creates implementation credit by itself.
- Common Level 2 baseline
- The reference case keeps NIST SP 800-171 Revision 2 and its 110 requirements. Graduated verification changes who reviews the evidence, not which safeguards the organization owes.
- Evidence-backed self
- The standard-risk route requires a current source-linked evidence package and accountable affirmation. A separately funded Government sample can return a weak result to correction.
- Assisted human validation
- Machine assistance handles defined evidence-mapping and checking tasks; accountable people disposition exceptions and findings. Machine throughput cannot clear a finite human queue.
- Independent assessment
- C3PAO capacity is protected for the high-risk cohort and remains constrained by qualified assessors, Lead CCAs, assessment teams, authorization, renewal, closeout, and rework.
- Evidence currency
- Statuses expire. Recurring review and material changes send affected evidence back through refresh or correction; no route renews automatically.
- Risk assignment
- Data sensitivity, mission consequence, threat exposure, and supplier criticality assign the route. Evidence defects can trigger correction or escalation, but do not redefine mission risk.
Controls are not assurance
The model deliberately separates the thing being protected, the record supporting it, and the depth of review. This prevents a cheaper route or administrative label from appearing as an instantaneous cyber-posture improvement.
Share of the active in-scope population with modeled controls in place. Dormant organizations receive no credit; readiness and remediation receive partial credit.
Share with a current evidence record, including evidence waiting in an authorized review queue. Evidence completeness is not the same as an issued status.
Share holding current self, assisted, independent, alternative-path, or unexpired legacy status. Expired status returns to stale or unverified work.
Classic C3PAO and accountable assisted-human results. Evidence-backed self is intentionally excluded; legacy self does not become independent after rescission.
(1 − implementation coverage) × threat factor, capped at 1.4. Route labels do not enter this calculation.
Missing current route coverage, weighted 1.0 for standard, 1.5 for elevated, and 2.0 for high risk, then adjusted for threat.
Compact comparisons report the first month that begins twelve consecutive months at or below 0.35. The result is calculated separately for every primary run, then summarized as a reach rate, median month, and P10–P90 range. It measures how long modeled exposure persists. It does not determine compliance.
Three jobs, two payers
Cost is not one undifferentiated “CMMC burden.” The ledger keeps implementation, evidence, and verification separate, then assigns contractor-paid work and Government work to different payers. The analysis reports both cumulative cost through 2049 and annual steady-state burden.
These are explicit central assumptions, not a blend of incompatible public estimates. The published cost-range sensitivity changes initial implementation, sustainment, evidence, and verification assumptions together. No main result treats a modeled automation efficiency as measured Deep Fathom performance.
Paired worlds, explicit switch points
Every policy option uses the same deterministic seed sequence10000 + index × 7919. Independent random streams isolate world shocks, policy process, review findings, and narrative flavor. Policy actions therefore do not shift the exogenous breach stream merely because they consumed a random draw.
The primary series uses 100 paired runs and reports median plus P10–P90. The implementation branch uses100 stochastic first attempts through 2035. Sensitivities use 100 paired runs per case; coordinated-portfolio ablations use 100.
Why exposure can fall while assurance disappears
Rescission removes Part 170 and its acquisition gate; it does not remove every underlying CUI safeguard, incident-reporting, or flow-down obligation. On the effective date the model gives no control-implementation credit. Current route stocks move into source-preserving legacy cohorts and retain their original expiration clocks. No self, assisted, or successor route appears by implication.
Work already in readiness or corrective action continues. The reference case also assumes new voluntary and prime-flow-down safeguard starts continue at one-half their live-program rate. Those real control completions can lower control exposure gradually. At the same time, legacy CMMC status expires and no new current assurance is issued. The two curves move in opposite directions because they measure different things.
Zero instantaneous control credit; no automatic successor
Only completed safeguards can reduce control exposure
Current and independent assurance fall without replacement issuance
The published rescission sensitivity sets new post-rescission starts to zero, keeps the reference rate, and doubles it. This directly exposes the assumption behind the declining exposure curve. In every case, rescission without a successor still loses current CMMC assurance.
A reproducible generated artifact
The site does not run the model in a visitor’s browser. It consumes a versioned JSON artifact tied to a model revision, assumption set, seed design, sources, scenario regimes, sensitivity cases, and limitations. The publisher rejects mixed primary regimes and refuses to produce a citable artifact from a dirty model tree.
Automated checks cover stock conservation, issuance cohorts, validity and rescission clocks, route-label neutrality, route prerequisites, finite human and Government capacity, cost-ledger separation, cancellation and vacatur restoration, deterministic policy mode, randomized stress, and schema ordering. Balance gates and longer stress runs are required before publication.
pnpm typecheck
pnpm test
pnpm analyze:balance
pnpm stress:10k
pnpm publish:verification-model -- \
--out=../cmmc20x.com/src/data/analysis-results.json \
--seeds=100 --risk-seeds=100 \
--sensitivity-seeds=100 --ablation-seeds=100Where the model stops
- Aggregate stock-and-flow model, not a synthetic firm-level population or breach-loss forecast.
- Risk cohorts and route assignment are policy assumptions until Government data can calibrate them.
- Assisted-review exception, labor, and failure values are explicit hypotheses for sensitivity analysis, not measured Deep Fathom performance claims.
- Cost layers reconcile scope conceptually but are ranges; official and SBA estimates are not blended into one false point estimate.
- Primary series assumes named policies are effective and resourced; legal and process failure is displayed separately.
- Level 2 focus. Level 1, Level 3, classified-program controls, and company-specific contract portfolios are outside scope.
- No breach-loss forecast. Control exposure is a comparative implementation index, not a probability of compromise, loss expectancy, or actuarial measure.
- No empirical route assignment yet. The 40/35/25 reference mix is a decision hypothesis until Government data can calibrate mission and data-risk cohorts.
Public record and claim boundaries
A source supports the stated structural assumption or claim boundary; it does not imply endorsement of CMMC 20X, Deep Fathom, or any modeled policy option.