CMMC 20X PRESS COPY SHEET Reviewed: August 13, 2026 Canonical source room: https://cmmc20x.com/press PUBLICATION CMMC 20X is Deep Fathom's independent policy, research, and technical publication. It defines a model for maintaining source-linked, independently verifiable security assurance across the Defense Industrial Base. It is not affiliated with or endorsed by the Department of War, the Cyber AB, or any assessment organization, and it does not claim to represent industry consensus. THESIS Cybersecurity is not paperwork. CMMC should strengthen the DIB's ability to protect defense information, recover from attack, and keep delivering for the mission. COMPANY BOILERPLATE Deep Fathom builds security and compliance software for the Defense Industrial Base. Its working platform connects CMMC requirements, assessment objectives, scoped implementation, source evidence, responsibility, findings, and remediation in one graph with accountable human review. CMMC 20X is the company's public vision, research, and technical work on modern DIB assurance. STEVEN HESS — SHORT BIOGRAPHY Steven Hess is co-founder and CEO of Deep Fathom. Before Deep Fathom, he was CEO of Cloud Storage Security and led businesses and teams across healthcare, fintech, and supply chain. He focuses on turning high-stakes security and compliance complexity into operating systems people can use to protect the mission. STEVEN HESS — EXTENDED BIOGRAPHY Steven Hess is co-founder and chief executive officer of Deep Fathom, where he leads company strategy and the development of security and compliance systems for the Defense Industrial Base. Before Deep Fathom, he served as chief executive officer of Cloud Storage Security, a cloud-native security company serving regulated public- and private-sector environments. Earlier, he led businesses and teams across data-intensive, highly regulated industries including healthcare, fintech, and supply chain. Hess co-founded Deep Fathom to replace fragmented, document-heavy compliance work with an operating model that connects implementation, evidence, responsibility, review, and change. His work centers on making rigorous security assurance achievable for both suppliers and the providers that support them. Within CMMC 20X, he connects the publication's policy argument to practical adoption: a system must preserve security rigor and accountable decisions while making evidence maintenance and verification workable for small suppliers and the service providers they depend on. He is based in Colorado. KEVIN HUNT — SHORT BIOGRAPHY Kevin Hunt is co-founder and CTO of Deep Fathom, where he leads platform architecture, engineering, and technical strategy. He previously served as CTO of Cloud Storage Security and held engineering leadership roles at Microsoft after joining as an early engineer at Yammer. His work spans regulated public- and private-sector environments. KEVIN HUNT — EXTENDED BIOGRAPHY Kevin Hunt is co-founder and chief technology officer of Deep Fathom, where he leads platform architecture, engineering, and technical strategy for security and compliance software serving the Defense Industrial Base. His work includes the company's source-linked CMMC evidence model, machine-assisted review systems, and the technical implementation behind CMMC 20X. Hunt has spent more than two decades building and scaling enterprise software and infrastructure. Before Deep Fathom, he served as chief technology officer of Cloud Storage Security. At Microsoft, he led product development and infrastructure initiatives after joining as an early engineer at Yammer and continuing through its acquisition. Across his career, he has led engineering, security, data, infrastructure, operations, and IT organizations. Within CMMC 20X, he connects the public architecture to implemented evidence graphs, deterministic validation, synthetic proof, and machine assistance limited to defined evidence tasks, with explicit separation between technical recommendations, human professional judgment, and decisions reserved to authorized Government actors. He is based in California. CONTACT Media: press@deepfathom.ai Technical CMMC 20X inquiries: cmmc20x@deepfathom.ai Corrections: cmmc20x@deepfathom.ai For deadline-sensitive requests, include the outlet, topic, deadline, and time zone. Embargo, background, and attribution terms apply only when confirmed in writing. REUSE BOUNDARIES The public source room contains official founder portraits and synthetic or model-derived CMMC 20X proof images. It contains no customer, contractor, CUI, FCI, assessment, or production-system data. Product capability, policy recommendations, conditional analysis, human judgment, and authorized Government decisions must retain their published labels when reused.