CMMC20X
The working system

One system from requirement to proof.

Deep Fathom has built the working software behind the CMMC 20X argument: the complete Level 2 model, the work required to implement it, the evidence that supports it, and the review that tests it—all connected in one record.

Mission Control in the working Deep Fathom platform. Demonstration workspace; no contractor data.
Text description: Mission Control

This silent video illustrates the platform overview above. Mission Control comes into focus, then highlights summary panels for controls met, SPRS score, SSP completion, and objective burndown, keeping readiness measures and outstanding objectives in one view.

Working softwareComplete Level 2 modelHuman-reviewed findingsReady for a controlled pilot
One connected record

The work does not break at the handoffs.

A requirement is useful only if it stays connected to what was built, what proves it, what failed review, who owns the fix, and what changed afterward. Deep Fathom keeps those relationships intact.

  1. Requirements

    All 110 Level 2 requirements and 320 assessment objectives form the common model.

  2. Implementation

    Systems, policies, people, and open work stay attached to the requirement they support.

  3. Evidence

    Each source carries its scope, collection time, coverage, integrity, and limits.

  4. Checks

    Software finds missing fields, stale records, broken references, and known conflicts.

  5. Review

    AI prepares cited analysis. A qualified person reviews the record and makes the finding.

  6. Change

    New implementation or evidence updates the affected record without erasing what came before.

Product footage

Watch the record move.

These are short captures from the working platform—not renderings. They show two places where the connected record changes the work: closing a gap and reviewing the result.

Implementation → remediation

Turn a gap into owned work.

Deep Fathom keeps the unmet objective, the plan, the evidence, the owner, and the due work together. The team can act without reconstructing context from a spreadsheet and a folder tree.

Guided remediation in a demonstration workspace.
Text description: Guided remediation

This silent video illustrates the remediation workflow described above. It moves from the requirement-family overview to unmet objective CM.L2-3.4.5, opens its remediation plan, reviews a set of suggested steps, and adds those steps to the plan attached to the objective.

Evidence → review

Review the same record the team built.

The assessment workflow reads the policy, implementation, objectives, evidence, SSP, and POA&M together. It can prepare cited analysis while the finding remains a human decision.

AI-assisted assessment in a demonstration workspace.
Text description: AI-assisted assessment

This silent video illustrates the review workflow described above. A status view advances through reviewing policy documents, evaluating control implementations, correlating evidence, evaluating objectives, auditing the SSP and POA&M register, and generating a report. It shows process status, not a finding.

Capability ledger

What is working now.

“Working” means the capability can be demonstrated in the platform. “Prototype” marks the part that still needs common exchange rules and interoperability testing.

  • Complete Level 2 model

    Working

    110 requirements and 320 assessment objectives connected to implementation, ownership, evidence, findings, and open work.

  • Guided implementation

    Working

    Turns gaps into specific work, assigns responsibility, and keeps remediation with the requirement it is meant to satisfy.

  • Source-linked evidence

    Working

    Records where evidence came from, what it covers, when it was collected, who owns it, and what it cannot prove.

  • Repeatable checks

    Working

    Tests required fields, freshness, integrity, references, and known conflicts without turning a software result into a finding.

  • AI-assisted assessment

    Working

    Reviews policy, implementation, objectives, and evidence together, then prepares cited analysis for a qualified reviewer.

  • Portable evidence package

    Prototype

    Exports a readable record and schema-valid JSON. Final exchange rules and interoperability profiles remain open work.

Synthetic MFA claim record showing coverage, source, freshness, responsibility, and integrity.
Technical appendix

Inspect one claim down to the source.

The public evidence package is deliberately narrow: one synthetic MFA claim, its source result, an open conflict, and a human disposition. It lets technical readers inspect the record structure without pretending one example represents the whole platform.

Open the worked evidence example
The next step

Put the working system through a Government pilot.

Use Government-selected cases, reviewers, thresholds, and operating constraints. Measure accuracy, reviewer effort, failure modes, and the conditions required to scale.