How We Earned CMMC Level 2 by Operating Securely 90% Faster

When our security team set out to earn the Cybersecurity Maturity Model Certification (CMMC) Level 2, we made one early decision that would shape everything: we would not treat the assessment as a project. We would let our security program speak for itself. A resilient program should do more than pass an assessment. It should continuously prove that its controls work. That belief is why I can share that RegScale is now CMMC Level 2 certified (requires a CAC/PIV to login) with 110 of 110 requirements met and zero POA&M items.

Why we pursued Level 2 after the pause
Even after the Department of War (DoW) paused CMMC Phase 2 implementation, we chose to continue. Earning the trust of defense customers is not something I want to defer to a timeline that may shift again. CMMC Level 2 sets a high bar: 110 security requirements aligned with NIST SP 800-171, validated through an independent assessment by a Certified Third-Party Assessment Organization. If we expect our customers to hold that line, we should hold it ourselves first.
We did not prepare for an audit. We operated.
Most organizations approach CMMC as an evidence-collection sprint. They stand up a project, bring in outside readiness consultants, and reconstruct a point-in-time snapshot of their controls. We built our program the other way around. Leveraging our own RegScale Continuous Controls Monitoring (CCM) platform, the security team monitored controls continuously, and we collected evidence as a by-product of normal operations, from our delivery pipeline through production. When A-LIGN assessed us, the proof was already there. We did not have to go find it, repackage it, or rebuild it.
What continuous assurance looked like under assessment
The results tell the story. We met 110 of 110 security requirements and all 14 CMMC domains across 320 assessment objectives, with zero POA&M items. As a security leader, the most telling number is 76%. Of the 25 follow-up items the assessors raised, 19 were resolved live, while the assessor was still on the call, because the evidence and control context were already connected and available in the RegScale platform. Our documentation stayed alive throughout. 14 controls moved from N/A to Fully Implemented with revised SSP statements during the sessions, and our SSP implementation statements were 100% complete at close. That is the difference between a static compliance package and a living compliance system.
The economics of operating this way
There is a cost argument here that security leaders will appreciate. The DoW models 286 hours of combined internal and external effort for a small entity to prepare for and support a Level 2 assessment. We used 28 hours, roughly 90% less, and we used no outside readiness consultant. I want to be precise on why. We were able to shrink the preparation and support burden around the assessment because the security program was already doing that work every day with our own RegScale CCM platform.
Compliance as a by-product of security
This is the philosophy we build into our platform, and the one I would offer to any CISO: security operations should produce compliance evidence as a by-product, not as a separate project. When controls are monitored continuously and evidence is generated as part of normal operations, an assessment becomes validation of an existing posture rather than a scramble to reconstruct one. CMMC did not change how we operate. It confirmed that operating securely and continuously produces compliance as the outcome.
Our security program has evolved on purpose
CMMC Level 2 is another stepping stone in a deliberate climb, not a one-off certification, and proof of why CCM promotes good security. In the past few years, we earned ISO 27001 in under 30 days, using our own platform. We also became FedRAMP Class D (High) certified with agency sponsorship from the Department of Homeland Security. Now CMMC Level 2. Each standard is more demanding than the last, and we pursued them on purpose because our customers operate under exactly these pressures, and they should see us living them first.
Here is the part I am proudest of. We earned every one of these certifications by leveraging our own platform. The continuous controls monitoring, the compliance-as-code architecture, and the AI-driven evidence collection we build for our customers are the same machinery we use to meet these standards ourselves. Our security program compounds. Every certification makes the next one faster because the controls, evidence, and discipline are already in place. That is what a maturing security program looks like, and it is why I can stand behind our platform without hesitation: we run our own company on it.
What this means going forward
The commitment behind all of this is simple: prove it, continuously. If you are a security leader staring down CMMC, my advice is just as simple. Stop preparing for the audit and start operating the program that makes the audit a formality. To see what continuous controls monitoring looks like in practice, book a demo here.
Ready to get started?
Choose the path that is right for you!
Skip the line
My organization doesn’t have GRC tools yet and I am ready to start automating my compliance with continuous monitoring pipelines now.
Supercharge
My organization already has legacy compliance software, but I want to automate many of the manual processes that feed it.
