CMMC20X

Make the security work visible, testable, and current.

Keep the safeguards. Stop rebuilding their proof for every review. Match review depth to risk, keep human judgment accountable, and recheck the claims affected when a system changes.

The outcome

CMMC should tell us whether the DIB is getting more secure.

A successful program does more than produce passing packages. It helps suppliers implement and sustain safeguards, gives reviewers a reliable basis for findings, concentrates scarce independent capacity where failure matters most, and reveals when an earlier conclusion is no longer current.

Done right, CMMC gives the Department current assurance that required safeguards are implemented and maintained, while keeping capable suppliers in the industrial base. That is how compliance supports the mission.

Near term, CMMC 20X keeps all 110 Level 2 requirements. The change is how implementation is evidenced, reviewed, reused, and refreshed—not a lower cybersecurity baseline.

The operating model

One record follows the security work.

The six stages maintain one continuing record; they do not create six deliverables. Existing system facts, documents, tests, findings, and decisions stay connected as the work moves from scope through change.

  1. 01

    Scope

    Name the CUI, systems, people, services, and responsibility boundaries.

  2. 02

    Protect

    Implement the safeguards and operate them every day.

  3. 03

    Record

    Keep the facts, dates, coverage, owners, and known conflicts.

  4. 04

    Check

    Run repeatable tests and send exceptions to qualified people.

  5. 05

    Decide

    Record the finding and the person with authority to act on it.

  6. 06

    Update

    Reopen every claim that a material change made uncertain.

Graduated Level 2 verification

Keep one baseline. Vary how deeply the work is checked.

Mission consequence, data sensitivity, threat exposure, supplier criticality, and material change should determine review depth. Evidence quality tells a reviewer what needs correction; it does not decide how important the mission is.

Evidence-backed self-review

For lower-consequence work when the organization can support its claims and Government can sample the method.

Assisted human review

For work that needs qualified review without consuming a complete C3PAO assessment. Software handles repeatable checks; a person resolves exceptions and reaches findings.

Independent C3PAO assessment

For the highest-consequence missions, sensitive data, significant unresolved risk, or conditions that require full independent examination.

The authority boundary

Software can find a problem. People make the finding.

Rules and AI can collect, compare, map, and flag evidence. A qualified reviewer decides whether the evidence supports a claim. Only an authorized person can certify, affirm, accept, award, or enforce.

The ecosystem

The proof crosses company lines. Responsibility does not disappear.

Providers should prove what their services do. Contractors should prove how those services are configured and used. Advisors prepare the work. Assessors test it independently. Primes supply mission and flowdown context. Government defines the rules, samples the system, and makes public decisions.

See the complete ecosystem
Current application · August 2026

The RFI turns this model into decisions the Department can make now.

It proposes graduated verification, a common evidence format, clearer scope and provider rules, reusable provider evidence, and a controlled evaluation of software-assisted review.

Read the submitted RFI response