CMMC20X
The DIB Verification ModelMethodology · schema 3

Assumptions before conclusions.

How the model defines its question, moves organizations through the system, accounts for cost, tests uncertainty, and limits what its results can support.

Model
bf91444e3fcc
Assumption set
graduated-verification-2026-08-13.v1
Run design
100 paired primary runs per policy option
Record
Published August 14, 2026
01
Purpose and estimand

What question the curves answer

This is a comparative stock-and-flow model of seven policy options for CMMC’s next phase, not a prediction of a particular Department decision. It asks whether the mechanism and sequence of one option behave differently from another under the same starting population, exogenous world shocks, time horizon, and stated assumptions.

That separation matters. A percentile band that pooled an effective rule, a delayed rule, a failed congressional action, and a vacated rule would describe no coherent operating regime. The primary chart therefore estimates the system conditional on the named portfolio becoming effective and resourced. A separate first-attempt branch reports legal and process implementation risk through 2035.

The analytical run removes the interactive game’s political-capital economy, terminal loss conditions, map, and fictional narrative. It retains the same tested engine, intervention dependencies, implementation delays, queues, validity clocks, supplier pressure, and seeded uncertainty.

02
Mechanism

One baseline, three verification routes

Organizations first do the underlying safeguard work. Only implemented organizations can enter a route. Route assignment changes the depth and capacity of review; it never changes mission risk and never creates implementation credit by itself.

Graduated Level 2 stock-and-flow mechanismOrganizations move through readiness and a common evidence layer before risk assignment sends standard-risk work to self assessment, elevated-risk work to assisted human validation, and high-risk work to C3PAO assessment. Government sampling separately checks the self route.Potential scopeDemand ignitionReadinessSafeguard workCommon evidenceSource · scope · freshnessRisk assignmentMission + data consequenceEvidence-backed selfStandard risk · affirmationAssisted human validationElevated risk · finite reviewer queueC3PAOHigh riskGovernment samplingSeparate public capacity
Conceptual view. The implementation maintains distinct evidence, review, remediation, stale, renewal, legacy, workforce, and issuance cohorts.
Common Level 2 baseline
The reference case keeps NIST SP 800-171 Revision 2 and its 110 requirements. Graduated verification changes who reviews the evidence, not which safeguards the organization owes.
Evidence-backed self
The standard-risk route requires a current source-linked evidence package and accountable affirmation. A separately funded Government sample can return a weak result to correction.
Assisted human validation
Machine assistance handles defined evidence-mapping and checking tasks; accountable people disposition exceptions and findings. Machine throughput cannot clear a finite human queue.
Independent assessment
C3PAO capacity is protected for the high-risk cohort and remains constrained by qualified assessors, Lead CCAs, assessment teams, authorization, renewal, closeout, and rework.
Evidence currency
Statuses expire. Recurring review and material changes send affected evidence back through refresh or correction; no route renews automatically.
Risk assignment
Data sensitivity, mission consequence, threat exposure, and supplier criticality assign the route. Evidence defects can trigger correction or escalation, but do not redefine mission risk.
03
Measures

Controls are not assurance

The model deliberately separates the thing being protected, the record supporting it, and the depth of review. This prevents a cheaper route or administrative label from appearing as an instantaneous cyber-posture improvement.

Safeguard implementation

Share of the active in-scope population with modeled controls in place. Dormant organizations receive no credit; readiness and remediation receive partial credit.

Current evidence

Share with a current evidence record, including evidence waiting in an authorized review queue. Evidence completeness is not the same as an issued status.

Current assurance

Share holding current self, assisted, independent, alternative-path, or unexpired legacy status. Expired status returns to stale or unverified work.

Independent review

Classic C3PAO and accountable assisted-human results. Evidence-backed self is intentionally excluded; legacy self does not become independent after rescission.

Control exposure

(1 − implementation coverage) × threat factor, capped at 1.4. Route labels do not enter this calculation.

Assurance gap

Missing current route coverage, weighted 1.0 for standard, 1.5 for elevated, and 2.0 for high risk, then adjusted for threat.

Compact comparisons report the first month that begins twelve consecutive months at or below 0.35. The result is calculated separately for every primary run, then summarized as a reach rate, median month, and P10–P90 range. It measures how long modeled exposure persists. It does not determine compliance.

04
Economic accounting

Three jobs, two payers

Cost is not one undifferentiated “CMMC burden.” The ledger keeps implementation, evidence, and verification separate, then assigns contractor-paid work and Government work to different payers. The analysis reports both cumulative cost through 2049 and annual steady-state burden.

LayerCentral assumptionWhat it represents
Implementation$80k initial · $12k/yearSafeguard gap closure and ongoing security sustainment
Evidence$40k initial · $6k/yearScoping, documentation, provenance, maintenance, and refresh
Self route$4k per cycleAccountable affirmation and route administration
Assisted route$3k + human hoursDefined machine tasks plus accountable human disposition
C3PAO route$30k per work unitIndependent assessment, adjusted for enclave or reuse topology
Government sample$12k per samplePublic sampling and cross-route calibration, not contractor revenue

These are explicit central assumptions, not a blend of incompatible public estimates. The published cost-range sensitivity changes initial implementation, sustainment, evidence, and verification assumptions together. No main result treats a modeled automation efficiency as measured Deep Fathom performance.

05
Uncertainty and stress tests

Paired worlds, explicit switch points

Every policy option uses the same deterministic seed sequence10000 + index × 7919. Independent random streams isolate world shocks, policy process, review findings, and narrative flavor. Policy actions therefore do not shift the exogenous breach stream merely because they consumed a random draw.

The primary series uses 100 paired runs and reports median plus P10–P90. The implementation branch uses100 stochastic first attempts through 2035. Sensitivities use 100 paired runs per case; coordinated-portfolio ablations use 100.

Route mix30/30/40, 40/35/25, and 55/25/20 self/assisted/C3PAO
Assisted review10–50% exception rate and 6,000–24,000 accountable human hours/month
Government sampling125, 250, and 500 sampled organizations/month
Evidence currency2–15% annual material-change rate
Evidence efficiency5–30% reduction in repeat handling from the common profile
EconomicsLow, central, and high implementation, evidence, sustainment, and verification ranges
Portfolio contributionRemove scope correction, supplier support, private capacity, graduated routing, or the evidence-and-route stack
Observed tested boundaries6,000 human hours/month ends at 12.0 months and fails the final envelope; 12,000 clears the median final queue. 125 samples/month ends at 74.4 months, while the 55% self case leaves 25.7 months at the 250-sample reference capacity.
06
Rescission mechanics

Why exposure can fall while assurance disappears

Rescission removes Part 170 and its acquisition gate; it does not remove every underlying CUI safeguard, incident-reporting, or flow-down obligation. On the effective date the model gives no control-implementation credit. Current route stocks move into source-preserving legacy cohorts and retain their original expiration clocks. No self, assisted, or successor route appears by implication.

Work already in readiness or corrective action continues. The reference case also assumes new voluntary and prime-flow-down safeguard starts continue at one-half their live-program rate. Those real control completions can lower control exposure gradually. At the same time, legacy CMMC status expires and no new current assurance is issued. The two curves move in opposite directions because they measure different things.

Day 0Program removed

Zero instantaneous control credit; no automatic successor

Following yearsUnderlying work may continue

Only completed safeguards can reduce control exposure

Original clocksLegacy status expires

Current and independent assurance fall without replacement issuance

The published rescission sensitivity sets new post-rescission starts to zero, keeps the reference rate, and doubles it. This directly exposes the assumption behind the declining exposure curve. In every case, rescission without a successor still loses current CMMC assurance.

07
Validation and reproducibility

A reproducible generated artifact

The site does not run the model in a visitor’s browser. It consumes a versioned JSON artifact tied to a model revision, assumption set, seed design, sources, scenario regimes, sensitivity cases, and limitations. The publisher rejects mixed primary regimes and refuses to produce a citable artifact from a dirty model tree.

Automated checks cover stock conservation, issuance cohorts, validity and rescission clocks, route-label neutrality, route prerequisites, finite human and Government capacity, cost-ledger separation, cancellation and vacatur restoration, deterministic policy mode, randomized stress, and schema ordering. Balance gates and longer stress runs are required before publication.

pnpm typecheck
pnpm test
pnpm analyze:balance
pnpm stress:10k
pnpm publish:verification-model -- \
  --out=../cmmc20x.com/src/data/analysis-results.json \
  --seeds=100 --risk-seeds=100 \
  --sensitivity-seeds=100 --ablation-seeds=100
08
Known limitations

Where the model stops

  • Aggregate stock-and-flow model, not a synthetic firm-level population or breach-loss forecast.
  • Risk cohorts and route assignment are policy assumptions until Government data can calibrate them.
  • Assisted-review exception, labor, and failure values are explicit hypotheses for sensitivity analysis, not measured Deep Fathom performance claims.
  • Cost layers reconcile scope conceptually but are ranges; official and SBA estimates are not blended into one false point estimate.
  • Primary series assumes named policies are effective and resourced; legal and process failure is displayed separately.
  • Level 2 focus. Level 1, Level 3, classified-program controls, and company-specific contract portfolios are outside scope.
  • No breach-loss forecast. Control exposure is a comparative implementation index, not a probability of compromise, loss expectancy, or actuarial measure.
  • No empirical route assignment yet. The 40/35/25 reference mix is a decision hypothesis until Government data can calibrate mission and data-risk cohorts.
09
Selected sources

Public record and claim boundaries

Use the reform analysis

Compare the policy options.
Keep the conditions attached.