<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title>CMMC 20X Research</title>
<link>https://cmmc20x.com/research</link>
<description>Research papers, design proposals, policy records, and public methods for securing the Defense Industrial Base.</description>
<language>en-us</language>
<lastBuildDate>Fri, 14 Aug 2026 00:00:00 GMT</lastBuildDate>
<atom:link href="https://cmmc20x.com/research/feed.xml" rel="self" type="application/rss+xml"/>
<item><title>A Security Claim Should Carry Its Own Receipts</title><link>https://cmmc20x.com/research/a-security-claim-should-carry-its-own-receipts</link><guid isPermaLink="true">https://cmmc20x.com/research/a-security-claim-should-carry-its-own-receipts</guid><description>A security claim is reusable only when its scope, source, date, responsibility, conflicts, and reviewer stay attached.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>evidence</category><category>oscal</category><category>verification</category><category>human-review</category></item><item><title>How a Correction Should Move Through the Record</title><link>https://cmmc20x.com/research/how-a-correction-should-move-through-the-record</link><guid isPermaLink="true">https://cmmc20x.com/research/how-a-correction-should-move-through-the-record</guid><description>A corrected source should reopen every dependent claim, finding, package, and authorized use without erasing the earlier decision trail.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>corrections</category><category>provenance</category><category>change-management</category></item><item><title>How a Provider Claim Should Travel</title><link>https://cmmc20x.com/research/how-a-provider-claim-should-travel</link><guid isPermaLink="true">https://cmmc20x.com/research/how-a-provider-claim-should-travel</guid><description>A proposed exchange record for carrying provider evidence into a contractor&apos;s CMMC claim without erasing scope, customer duties, or reviewer judgment.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>service-providers</category><category>shared-responsibility</category><category>evidence</category><category>interoperability</category></item><item><title>How Verification Should Scale</title><link>https://cmmc20x.com/research/how-verification-should-scale</link><guid isPermaLink="true">https://cmmc20x.com/research/how-verification-should-scale</guid><description>A proposal for varying CMMC Level 2 review depth while preserving safeguards, human authority, escalation, and Government oversight.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>graduated-verification</category><category>risk</category><category>assessment</category><category>oversight</category></item><item><title>The Minimum Viable CMMC 20X Pilot</title><link>https://cmmc20x.com/research/the-minimum-viable-cmmc20x-pilot</link><guid isPermaLink="true">https://cmmc20x.com/research/the-minimum-viable-cmmc20x-pilot</guid><description>A pilot should compare methods on frozen cases, publish dangerous errors, and earn each expansion of permitted use.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>evaluation</category><category>pilot</category><category>ai-assisted-review</category></item><item><title>What a Common Evidence Profile Must Preserve</title><link>https://cmmc20x.com/research/what-a-common-evidence-profile-must-preserve</link><guid isPermaLink="true">https://cmmc20x.com/research/what-a-common-evidence-profile-must-preserve</guid><description>The minimum context a CMMC security claim needs to remain traceable, challengeable, and useful across tools and reviewers.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>evidence-profile</category><category>oscal</category><category>interoperability</category><category>provenance</category></item><item><title>What Actually Holds Up?</title><link>https://cmmc20x.com/research/what-actually-holds-up</link><guid isPermaLink="true">https://cmmc20x.com/research/what-actually-holds-up</guid><description>Seven CMMC policy options produce very different results for security, suppliers, review queues, and cost.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>reform-analysis</category><category>verification</category><category>research</category></item><item><title>What Changed After the July Reform Review</title><link>https://cmmc20x.com/research/what-changed-after-the-july-reform-record</link><guid isPermaLink="true">https://cmmc20x.com/research/what-changed-after-the-july-reform-record</guid><description>The July record narrowed CMMC 20X: preserve the baseline, separate evidence from verification, name legal instruments, and test assistance before reliance.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>reform</category><category>change-record</category><category>july-13</category></item><item><title>What CMMC 20X Cannot Automate</title><link>https://cmmc20x.com/research/what-cmmc20x-cannot-automate</link><guid isPermaLink="true">https://cmmc20x.com/research/what-cmmc20x-cannot-automate</guid><description>A task-level boundary for software-assisted CMMC evidence work, including the judgments, authorities, and field conditions that remain human.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>automation</category><category>ai-evaluation</category><category>human-judgment</category><category>assurance</category></item><item><title>What the Model Says About Evidence and Review</title><link>https://cmmc20x.com/research/what-the-program-model-says-about-evidence-and-review-capacity</link><guid isPermaLink="true">https://cmmc20x.com/research/what-the-program-model-says-about-evidence-and-review-capacity</guid><description>The CMMC 20X model separates evidence handling from review capacity and shows why improving either one alone leaves a different constraint in place.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>reform-analysis</category><category>evidence</category><category>review-capacity</category><category>verification</category></item><item><title>What Would Falsify the CMMC 20X Thesis?</title><link>https://cmmc20x.com/research/what-would-falsify-cmmc20x</link><guid isPermaLink="true">https://cmmc20x.com/research/what-would-falsify-cmmc20x</guid><description>Six observable failures would require the proposal to narrow, change, or stop. A reform thesis should expose those conditions in advance.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>falsification</category><category>evaluation</category><category>research</category></item><item><title>When Evidence Can Be Reused</title><link>https://cmmc20x.com/research/when-evidence-can-be-reused</link><guid isPermaLink="true">https://cmmc20x.com/research/when-evidence-can-be-reused</guid><description>A decision test for reusing CMMC evidence without detaching it from scope, time, responsibility, or reviewer purpose.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>evidence-reuse</category><category>providers</category><category>change-management</category><category>verification</category></item><item><title>Accountability for Software-Produced Evidence</title><link>https://cmmc20x.com/research/who-remains-accountable-when-software-produces-evidence</link><guid isPermaLink="true">https://cmmc20x.com/research/who-remains-accountable-when-software-produces-evidence</guid><description>A proposed authority map for keeping source records, machine analysis, human findings, and CMMC decisions distinct.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>accountability</category><category>human-review</category><category>ai-governance</category><category>evidence</category></item><item><title>Why CMMC 20X Separates Three Policy Layers</title><link>https://cmmc20x.com/research/why-cmmc20x-separates-baseline-evidence-verification</link><guid isPermaLink="true">https://cmmc20x.com/research/why-cmmc20x-separates-baseline-evidence-verification</guid><description>A design case for keeping required safeguards, proof structure, and review depth as three separate policy decisions.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>baseline</category><category>evidence</category><category>verification</category><category>policy-design</category></item><item><title>The Phase 2 Suspension: What the Record Says</title><link>https://cmmc20x.com/research/phase-2-suspension-what-changed</link><guid isPermaLink="true">https://cmmc20x.com/research/phase-2-suspension-what-changed</guid><description>What the July 13 CMMC documents changed, left in place, and left unresolved.</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>policy</category><category>phase-2</category><category>current-intervention</category></item><item><title>Introducing CMMC 20X</title><link>https://cmmc20x.com/research/introducing-cmmc-20x</link><guid isPermaLink="true">https://cmmc20x.com/research/introducing-cmmc-20x</guid><description>Five changes to how CMMC evidence is collected, reviewed, reused, and updated.</description><pubDate>Sat, 24 Jan 2026 00:00:00 GMT</pubDate><dc:creator>Deep Fathom</dc:creator><category>cmmc</category><category>announcement</category><category>automation</category></item>
</channel>
</rss>