Press and analyst
source room
Facts, primary sources, reusable files, and direct contacts for reporting on CMMC 20X and Deep Fathom’s work on DIB security.
What CMMC 20X is—and is not.
- Publication
- CMMC 20X is an independent Deep Fathom policy, research, and technical publication.
- Thesis
- Cybersecurity is not paperwork. CMMC should strengthen the DIB’s ability to protect defense information, recover from attack, and keep delivering for the mission.
- Working software
- Deep Fathom represents all 110 Level 2 requirements and 320 assessment objectives in software, links claims to evidence, and records machine analysis separately from human findings. Public examples use synthetic data; they are not customer results or proof of machine accuracy.
- Policy and model boundaries
- The common evidence profile and graduated verification are proposals, not current Government policy. The Government pilot is a proposal for vetting the working system. Results from the CMMC Reform Analysis are conditional model outputs, not forecasts.
Five questions, with sources.
- Read the Blueprint
What should CMMC tell us about DIB cybersecurity?
The Blueprint connects maintained safeguards, review depth, human authority, and material change.
- Compare the policy options
What changes under seven CMMC policy options?
The CMMC Reform Analysis compares verification coverage, supplier survival, review backlog, exposure, cost, and implementation constraints.
- See the Government pilot
What is ready to pilot?
Deep Fathom has built the complete Level 2 model, source-linked evidence, repeatable checks, and AI-assisted review. The pilot proposal vets that system against frozen cases, independent reference findings, predeclared thresholds, and published errors.
- Inspect the evidence example
What does a reusable security claim contain?
The worked example separates source evidence, deterministic checks, machine analysis, human findings, and authorized decisions.
- Review capability status
What has Deep Fathom implemented?
Capability status, a public synthetic export, and the boundaries of what has not been validated or authorized.
Briefing, copy, and source files ready to use.
How We Secure the DIB
The self-contained CMMC 20X argument: the current moment, cost, principles, Blueprint, worked example, reform proposal, working system, and recommended next action.
Reviewed August 14, 2026Tagged portrait PDF · designed for close reading
Download briefing PDFEditable CMMC 20X presentation
A concise visual presentation of the CMMC 20X argument, with editable text, speaker notes, sources, and live links.
Reviewed August 14, 2026PPTX · 16:9 · editable slides
Download editable PowerPointCMMC 20X presentation PDF
A forwardable PDF that matches the widescreen PowerPoint presentation.
Reviewed August 14, 2026Tagged PDF · 16:9
Download presentation PDFPress copy sheet
Boilerplate, founder biographies, contacts, and reuse boundaries.
Reviewed August 13, 2026TXT · 4.5 KB
Download press copy sheetCMMC 20X Vision Brief
The thesis, five principles, operating loop, ecosystem responsibilities, and modeled outcomes.
Reviewed August 13, 2026Tagged PDF/UA-1 · 1 page · 26 KB
Download vision briefCMMC Reform RFI Response Overview
One-page overview of Deep Fathom’s response submitted August 13, 2026.
Submitted August 13, 2026Tagged PDF/UA-1 · 1 page · 24 KB
Download response overview
Mission imagery and model figures.

Built Across America mission plate
A presentation-ready statement connecting CMMC to the American industrial work the mission depends on.
PNG · 2400×1350 · 16:9Archival photograph: Ann Rosener / U.S. Office of War Information, Library of Congress, July 1942. Public domain; free to use and reuse. Editorial composition: Deep Fathom. Archive record
Seven CMMC policy options
Five modeled outcomes for seven CMMC policy options.
PNG · 2400×1350 · 261 KBSource: CMMC 20X Reform Analysis. Conditional model output; not a forecast. Editorial composition: Deep Fathom. Methodology
These files contain no customer, contractor, CUI, FCI, production, or assessment data. Each carries a visible route back to CMMC20x.com.
Check the claims at their source.
Government and standards sources
- CMMC Program final rule · 89 FR 83092Program structure, assessment types, cost model, and regulatory basis.↗
- 32 CFR Part 170Current CMMC program requirements, scoping, assessment, affirmation, and provider treatment.↗
- NIST OSCALMachine-readable models for controls, system plans, assessment results, and POA&Ms.↗
- DCMA DIBCACPublic assessment resources and the Top Other Than Satisfied Requirements analysis.↗
- FAR 52.204-21Basic safeguarding requirements for covered contractor information systems.↗
CMMC 20X and Deep Fathom sources
Talk to the people doing the work.
Co-founder and CEOSteven Hess
Company strategy, supplier adoption, and practical program design.
JPG · 1000×1316 · 97 KB
Co-founder and CTOKevin Hunt
Technical architecture, product implementation, evidence, and CMMC reform analysis.
JPG · 1000×1385 · 65 KB
Press deadlines and factual corrections
For deadline-sensitive requests, include the outlet, topic, deadline, and time zone. Material corrections are recorded on the affected source page.