Cybersecurity
is not paperwork.
Adversaries target the DIB for the information and capabilities the mission depends on. CMMC should strengthen the DIB’s ability to protect that information, recover from attack, and keep delivering for the mission. It should give the Department current assurance that required safeguards are implemented and maintained—not another reconstruction of the past.
Secure the industrial base as a system.
The DIB is not a monolith. It is a living system of manufacturers, engineers, cloud services, managed providers, primes, assessors, and Government programs. Adversaries exploit the seams between them to reach defense information and the capabilities the mission depends on. Our cybersecurity model has to work across those seams too.
Today, too much CMMC effort begins after the security work is done. Suppliers assemble screenshots and documents. Advisors reorganize them. Assessors reconstruct the same facts. Providers answer similar questions for every customer. Repetition consumes scarce people and money without adding another safeguard.
CMMC 20X starts with the security outcome. Systems should produce usable facts as people protect them. Those facts should stay connected to scope, responsibility, time, conflicts, findings, and change. Then qualified people can spend their attention on risk and judgment—not clerical reconstruction.
This is larger than one product, one filing, or one office. It is a direction for the whole DIB—and a case anyone in the ecosystem can make.
The mission is built here.
America’s defense capability is produced by people, suppliers, systems, and handoffs. Cybersecurity protects the information and operational continuity that let those capabilities reach the force.
The tools have changed. The dependency has not.

- Place
- Willow Run, Michigan
- Capability
- Aircraft production
- Record
- July 1942
Ann Rosener / U.S. Office of War Information, Library of CongressLibrary of Congress record Download mission plate
Five principles for changing the system.
The principles set the direction. The Blueprint turns them into a practical model for security work, evidence, review, and change.
- №01
Automation over documentation
Collect security facts where the work happens. Stop making every supplier and reviewer rewrite them.
Read the principle → - №02
Continuous over point-in-time
Recheck the claims affected when accounts, systems, providers, or boundaries change.
Read the principle → - №03
Assessment-ready over dashboard-green
Prepare evidence another person can trace, test, challenge, and disagree with.
Read the principle → - №04
Accessible over enterprise-only
Make strong cybersecurity achievable for the small suppliers the defense mission depends on.
Read the principle → - №05
Ecosystem-wide over contractor-only
Give providers, contractors, assessors, primes, and Government a clear part without letting anyone pass responsibility downstream.
Read the principle →
Security changes every day. Its proof should keep up.
The record follows the work from the first scope decision through the next system change. It does not replace the SSP, assessment, or human finding; it gives each one a current basis.
Follow the operating loop- ScopeKnow where the information goes and who protects it.
- ProtectImplement and operate the safeguards.
- RecordKeep the facts produced by that work.
- CheckTest the facts and resolve conflicts.
- DecidePut findings and authority with people.
- UpdateReopen what a material change made uncertain.
CMMC reform choices reshape the DIB.
Deep Fathom modeled seven policy options for CMMC’s next phase through 2049. Reopening the existing program reaches 97% current assurance in the median run—but loses 36% of active suppliers. Graduated verification reaches 90% and loses 3%. Coordinated reform reaches 91% and loses 1%.
Conditional systems analysis, not a forecast. Assumptions, sensitivities, and model lineage are public.
Explore the reform analysisEvery role owns a different part.
Security crosses company lines. Responsibility should not disappear when the work moves between a supplier, provider, advisor, assessor, prime, and Government office.
DIB contractors
Scope, safeguards, readiness and affirmation
See this role →MSPs, MSSPs & ESPs
Shared responsibility, service evidence and change
See this role →RPOs & advisors
Scoping, remediation, preparation and method
See this role →C3PAOs & assessors
Independent examination, findings and judgment
See this role →Primes
Flowdown, mission context and shared services
See this role →Government
Program rules, review depth, testing and decisions
See this role →
A concrete answer to the Department’s reform request.
Keep the Level 2 safeguards. Match verification depth to mission and data risk. Publish a common evidence format. Test software-assisted review before it affects a contractor. The RFI applies CMMC 20X to the decisions in front of the Department now; it does not define the movement.
Help move CMMC 20X from argument to practice.
Bring a difficult case, test an interoperable workflow, challenge the model, or help carry the work across the DIB. You do not have to endorse every recommendation to make the work stronger.
