Reforming CMMC · Machine-verifiable cybersecurity evidence for the DIB
Every building block is already established. The join was never published.
The Federal government has published the referents that define conformance, and the standard already requires the defense contractor to maintain the system state those referents describe. That state is readable by machine, and NIST already built the schema to carry the results. What has never been published is the Department’s list of the assessment objectives a machine export may satisfy.
Select any component to trace its connections and read how they relate.
Department control plane
A civilian agency adopting these requirements under the FAR CUI rule has both boxes to fill. The Department has one.A civilian agency under the FAR CUI rule fills both boxes. The Department has one.
Published referents
Contractor environment — required stateRequired state
Validation method
Readers
Accept the artifact where it is offered; assess the remainder. Of the 320 assessment objectives in SP 800-171A, 44.7% fall to automated validation and need no assessor participation, 25.0% are narrowed by the artifact but closed by judgement, and 30.3% require manual validation by an assessor. Of the automated share, 31.2% of the standard is scored against a referent the Federal government publishes and 13.4% against one the organization is obliged to define but no one else can read. The three shares account for the whole standard. Nothing is removed from the requirement set; verification changes hands where the system can answer for itself.
The standard requires the state, not the reading of it. Nothing in SP 800-171 obliges a contractor to operate a scanner, query a configuration interface, or search a log store. What it obliges is the underlying condition — a hardened baseline, a configured tenant, scanned and remediated components, retained audit records — and that condition is already exposed in machine-readable form by the products that maintain it. This proposal adds no required component. It makes an existing required state reportable, for suppliers who choose to report it.
The ask is one act, and it is a publication. The Department publishes the list of assessment objectives a machine-readable export may satisfy, stating for each whether the export satisfies the objective outright — automated validation — or contributes evidence toward it — combination. Periodic exports then replace assessment for the listed objectives, at a cadence no more frequent than each control already requires. Nothing is asked of the Department beyond the list: how a supplier produces a conforming export is internal to the supplier. No Departmental tooling, no new system, no rulemaking — the April 2025 parameter values went out as a memorandum.
Established — required and readable todayNot yet designatedWhat designation would closeRead byArchstone Security · classification of 320 SP 800-171A assessment objectives against a single reference architecture · dataset v8.8
Figure 1 — Every building block is already established; the join was never published. Classification of all 320 assessment objectives in NIST SP 800-171A against a single test: does the system emit the evidence the objective requires? Identifiers follow SP 800-171A Rev 2 numbering; parameter values are the Department’s April 2025 assignments. Method and row-level data: archstonesecurity.com/research.html. Archstone Security, dataset v8.8.