Related · tier-1 reading. For what a portable artifact actually is, see Portable Artifact.
This is H33-74 evidence applied to CMMC 2.0. Cybersecurity Maturity Model Certification 2.0 requires verifiable evidence of operational controls. H33-74 produces/anchors that evidence as a portable post-quantum proof that survives the systems and chains it was anchored to. The primitive is unchanged — only the application context (CMMC assessment) differs.
Cybersecurity Maturity Model Certification 2.0 (United States Department of Defense, Defense Industrial Base contractors and subcontractors) places obligations on organizations to demonstrate that operational controls were in place, that automated decisions were governed, and that an audit trail exists for regulatory inquiry. Most existing audit-log architectures meet the letter of the requirement but produce evidence tied to the operator's current systems. If those systems change or fail, the evidence weakens.
CMMC 2.0 applies to organizations in the Defense Industrial Base (DIB) that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) under DoD contracts. Three certification levels: Level 1 Foundational (17 practices aligned to FAR 52.204-21, annual self-assessment) for FCI; Level 2 Advanced (110 practices aligned to NIST SP 800-171, triennial C3PAO assessment) for CUI; Level 3 Expert (110+ practices plus a subset of NIST SP 800-172, triennial DIBCAC assessment) for high-priority CUI. The DoD CMMC Final Rule (CFR 48 Part 204) became effective in 2025 and contracts are incorporating CMMC requirements as a condition of award. Contractors at every tier of the supply chain are in scope.
CMMC audit obligations require evidence that controls have been in place continuously across the contract performance period, often years after specific access events, configuration changes, and incidents occurred. Contractors routinely change MSP providers, replace SIEM tools, migrate to different clouds, and consolidate after M&A — and each change creates evidence gaps that complicate the next C3PAO assessment or DIBCAC review. H33-74 produces each access event, each configuration change, each incident classification, and each access-revocation decision as a cryptographically verifiable post-quantum proof at the moment it occurs. The C3PAO assesses controls by verifying the proofs directly; provider changes do not weaken the evidence.
None of this redefines the primitive: H33-74 produces/anchors the same portable 74-byte post-quantum receipt for CMMC 2.0 that it does for any other use, and it produces evidence that supports CMMC practices rather than making a contractor certified on its own. How anyone checks a receipt — recompute the commitment, verify the signatures, confirm the anchor, with H33 not in the loop — is described under Verification.
Read the architectural concept underneath every H33-74 regulatory deployment.
Chain Portability Why Chain Migration Shouldn't Exist