CMMC20X
A movement for a secure, resilient Defense Industrial BaseLed by Deep Fathom

Cybersecurity
is not paperwork.

Adversaries target the DIB for the information and capabilities the mission depends on. CMMC should strengthen the DIB’s ability to protect that information, recover from attack, and keep delivering for the mission. It should give the Department current assurance that required safeguards are implemented and maintained—not another reconstruction of the past.

Secure the industrial base as a system.

The DIB is not a monolith. It is a living system of manufacturers, engineers, cloud services, managed providers, primes, assessors, and Government programs. Adversaries exploit the seams between them to reach defense information and the capabilities the mission depends on. Our cybersecurity model has to work across those seams too.

Today, too much CMMC effort begins after the security work is done. Suppliers assemble screenshots and documents. Advisors reorganize them. Assessors reconstruct the same facts. Providers answer similar questions for every customer. Repetition consumes scarce people and money without adding another safeguard.

CMMC 20X starts with the security outcome. Systems should produce usable facts as people protect them. Those facts should stay connected to scope, responsibility, time, conflicts, findings, and change. Then qualified people can spend their attention on risk and judgment—not clerical reconstruction.

This is larger than one product, one filing, or one office. It is a direction for the whole DIB—and a case anyone in the ecosystem can make.

The industrial base, in view

The mission is built here.

America’s defense capability is produced by people, suppliers, systems, and handoffs. Cybersecurity protects the information and operational continuity that let those capabilities reach the force.

The tools have changed. The dependency has not.

A woman production worker welds cooling-system parts to an aircraft supercharger at Ford’s Willow Run plant in Michigan in 1942.
Place
Willow Run, Michigan
Capability
Aircraft production
Record
July 1942

Ann Rosener / U.S. Office of War Information, Library of CongressLibrary of Congress record Download mission plate

One continuous record

Security changes every day. Its proof should keep up.

The record follows the work from the first scope decision through the next system change. It does not replace the SSP, assessment, or human finding; it gives each one a current basis.

Follow the operating loop
  1. ScopeKnow where the information goes and who protects it.
  2. ProtectImplement and operate the safeguards.
  3. RecordKeep the facts produced by that work.
  4. CheckTest the facts and resolve conflicts.
  5. DecidePut findings and authority with people.
  6. UpdateReopen what a material change made uncertain.
Test reform options against outcomes

CMMC reform choices reshape the DIB.

Deep Fathom modeled seven policy options for CMMC’s next phase through 2049. Reopening the existing program reaches 97% current assurance in the median run—but loses 36% of active suppliers. Graduated verification reaches 90% and loses 3%. Coordinated reform reaches 91% and loses 1%.

Conditional systems analysis, not a forecast. Assumptions, sensitivities, and model lineage are public.

Explore the reform analysis
Current work · August 2026One application of the larger vision

A concrete answer to the Department’s reform request.

Keep the Level 2 safeguards. Match verification depth to mission and data risk. Publish a common evidence format. Test software-assisted review before it affects a contractor. The RFI applies CMMC 20X to the decisions in front of the Department now; it does not define the movement.

Work with us

Help move CMMC 20X from argument to practice.

Bring a difficult case, test an interoperable workflow, challenge the model, or help carry the work across the DIB. You do not have to endorse every recommendation to make the work stronger.