Show us where today’s process breaks.
Bring a synthetic or appropriately controlled example involving scope, inherited responsibility, provider evidence, conflicting support, stale conclusions, or a difficult review decision.
CMMC 20X is a public argument backed by research, program modeling, and working software. Now it needs hard cases, informed criticism, integrations, evaluations, and people willing to carry the work into the places where CMMC is shaped and practiced.
You do not have to endorse every recommendation. Tell Deep Fathom what concrete contribution you can make.
The industrial base has always depended on specialized people and organizations doing different jobs. Securing it now takes contractors, providers, assessors, primes, and Government working from the same current facts.
Bring the hard case only your part of the system can see.

Howard R. Hollem / U.S. Office of War Information, Library of CongressLibrary of Congress record Download mission plate
Start with the contribution closest to what you know, operate, build, test, or influence.
Bring a synthetic or appropriately controlled example involving scope, inherited responsibility, provider evidence, conflicting support, stale conclusions, or a difficult review decision.
Help define or run a bounded pilot using the same cases, reviewers, measures, decision rules, and security constraints for ordinary and software-assisted work.
Review the Blueprint, CMMC Reform Analysis, evidence profile, evaluation method, or working implementation. Bring a counterexample, missing source, better measure, or specific objection.
Explore how security facts, scope, responsibility, corrections, and findings can cross tools and organizational boundaries without becoming another pile of documents.
Contractors, providers, advisors, assessors, primes, researchers, and Government teams see different failure modes. Help us account for the operating reality in your part of the system.
Share the site, forward the briefing, use a figure in a presentation, host a working session, or invite a direct challenge from the people responsible for DIB security.
This is an invitation to do something specific—not a membership drive or a request for a logo.
Name the problem, case, capability, audience, or operating experience—not a generic interest in “partnering.”
We will agree on the question, boundary, participants, handling rules, and what a useful result would look like.
Where appropriate, we will publish the method, result, correction, or lesson so the broader DIB can use it.
Forward the site to the person who owns the decision. Put the briefing into a staff discussion. Use the program comparison in a presentation. Send a researcher the methodology. Every artifact links back to the public source so the next person can inspect the work for themselves.
CMMC 20X is owned and published by Deep Fathom. Working with us does not imply endorsement by your organization, Deep Fathom, the Department of War, the Cyber AB, or any assessment organization. It does not create a CMMC credential, certification, authorization, accreditation, assessment status, or Government approval.
Do not send CUI, export-controlled information, credentials, assessment evidence, security-sensitive system details, or other protected material through email or the public site. Begin with a sanitized description; we can establish an appropriate handling path before reviewing anything sensitive.
Introduce your organization, name your place in the CMMC ecosystem, and describe the specific case, capability, criticism, experience, or audience you can contribute.