How RegScale Earned CMMC Level 2 with Its Own Platform

Industry Type
Technology, SaaS
Use Cases
CCM, evidence collection, audit readiness
Frameworks
CMMC Level 2
NIST SP 800-171 Rev. 2
Impact
Challenge: Prove a security program genuinely works under an independent CMMC Level 2 assessment, without a costly evidence scramble.
Solution: RegScale ran the CMMC assessment on its own CCM platform, using continuous evidence collection.
Results: 100% requirements met, zero POA&M, and 90% less assessment-support effort than the DoW model, all run on RegScale’s own platform.
Customer Outcomes
Less hours than the DoW small-entity model
14/14 CMMC domains, 320 objectives evaluated
No post-assessment remediation backlog
Summary
RegScale is an AI-powered continuous controls monitoring (CCM) platform built for the CISO, running on a compliance-as-code foundation that automates evidence and keeps controls under constant watch. When RegScale pursued Cybersecurity Maturity Model Certification (CMMC) Level 2, it did not prepare by assembling an evidence binder for an audit. It ran the assessment end-to-end on the RegScale platform, using continuous evidence collection, so the proof of security performance was ready the moment the assessor asked for it. Independently validated by C3PAO A-LIGN, the result was 110 of 110 NIST SP 800-171 Rev. 2 requirements met, all 14 CMMC domains met, all 320 assessment objectives evaluated, and zero POA&M items, achieved with 90% less assessment-support effort than the Department of War models for a small entity. This certification is the latest step in a deliberate evolution of RegScale’s own security program, and like the harder milestones before it, RegScale earned its own RegScale platform.
“We didn’t build a security program to pass an assessment. We built one that could continuously prove our controls work. CMMC simply validated the model: 110 requirements met, 320 assessment objectives, 90% faster compared to the DoW benchmark, and zero POA&M. Compliance wasn’t the goal. It was the outcome of operating securely.”
Dale Hoak, CISO, RegScale
Challenge: Proving continuous security, not just passing an audit
A high bar for protecting defense information
CMMC Level 2 requires organizations that handle Controlled Unclassified Information (CUI) to implement 110 security requirements aligned with NIST SP 800-171 and to prove their effectiveness through an independent assessment by a Certified Third-Party Assessment Organization (C3PAO). It is one of the most demanding bars in the defense supply chain. Even after the Department of War (DoW) paused CMMC Phase 2 implementation, RegScale chose to continue pursuing certification, because earning the trust of defense customers should not wait on a shifting timeline.
The usual path is a scramble
Most organizations prepare for CMMC by standing up a project: pulling together evidence, hiring external readiness consultants, and reconstructing a point-in-time picture of their controls. The DoW models that burden for a small entity at 286 combined hours of director and external service-provider effort just to prepare for and support the assessment, before the assessor ever issues a finding. That is the cost of treating compliance as a periodic event.
Operate security program continuously, not as a project
RegScale set out to make its assessment a validation of an existing security posture rather than a race to rebuild one. The goal was straightforward: operate the security program continuously, generate evidence as a by-product of normal operations, and let the certification confirm what was already true.
Solution: One platform for continuous control monitoring, evidence, and assurance
Continuous control monitoring
Instead of asking “are we compliant today,” RegScale uses its own CCM platform to continuously evaluate whether the controls that produce compliance are operating. Control status, ownership, and implementation statements remain connected to the live system within the platform, so gaps surface and are corrected during normal operations rather than during an assessment. Control health was visible before an assessor asked for it.
Continuous evidence from pipeline to production
On the same platform, RegScale gathered and organized evidence across the technology lifecycle, from development and delivery pipelines into the production environment, then mapped that evidence to the applicable requirements and assessment objectives. Assessors worked from a single repository, the RegScale platform, with full control over context, rather than a chain of shared folders and ad hoc requests. Responding to a question became retrieval and validation rather than rediscovery and repackaging.
Cyber resilience as the foundation
The point of CMMC is protecting sensitive information, not the certificate itself. RegScale operates its controls to reduce operational risk first, and the resulting evidence demonstrates compliance. That resilience-first model is what produced a clean assessment outcome.
Assessed end to end on the RegScale platform
RegScale managed its own CMMC Level 2 certification assessment entirely on the RegScale platform, with A-LIGN acting as the independent C3PAO. The assessment covered the full scope of 110 NIST SP 800-171 Rev. 2 security requirements and 320 NIST SP 800-171A Rev. 2 assessment objectives across the RegScale SaaS platform in Microsoft Azure Government Cloud. Put simply, RegScale ran its CMMC Level 2 assessment on the very product it sells to its customers.
“When your controls are continuously monitored and your evidence is generated from the pipeline through production, compliance stops being an event and becomes an outcome of how you operate.”
Dale Hoak, CISO, RegScale
Results: A clean certification, earned efficiently
110 of 110 requirements met, and zero POA&M
RegScale met 110 of 110 security requirements and all 14 CMMC domains, with all 320 assessment objectives evaluated. Critically, the assessment produced zero POA&M items. Zero POA&M means there was no post-assessment remediation backlog to close as a condition of certification, and no operational disruption from remediation, evidence recollection, and re-verification that a backlog creates.
76% of follow-ups resolved live
Assessors raised 25 follow-up items during the engagement. Nineteen were resolved during the live sessions, a 76% live-resolution rate, with only six carrying into the formal follow-up window. Because the relevant evidence and control context were already connected and available in the RegScale platform, the team answered most questions while the assessor was still on the call. Documentation stayed live throughout: 14 controls moved from N/A to Fully Implemented with revised System Security Plan statements during the sessions, and SSP implementation statements were 100% complete at assessment close.
Roughly 90% lower assessment-support burden
Against the DoW modeled baseline of 286 hours for a small entity, RegScale used 28 hours of internal preparation and assessment support, a reduction of 258 hours. Preparation fell from a modeled 94 hours to 20, and additional assessment support fell from a modeled 192 hours to 8. RegScale used no outside readiness consultant, where the DoW model assumes 168 external-provider hours. The efficiency came from reducing the internal and external effort around the assessment, since the security program was already doing that work every day on RegScale’s own platform.
A deliberate climb in security maturity
CMMC Level 2 did not happen in isolation. It is an additional step in the deliberate evolution of RegScale’s security posture, and each step has been harder than the last. In the past 6 months, RegScale first earned ISO 27001, achieving certification in under 30 days using its own platform. It then earned FedRAMP Class D (High) authorization with agency sponsorship from the Department of Homeland Security, one of the most demanding bars in federal security. CMMC Level 2 raises the bar again, this time for the defense supply chain and the protection of Controlled Unclassified Information.
The through-line matters as much as the milestones: RegScale earned every one of these certifications by running its own platform. The same continuous controls monitoring, compliance-as-code architecture, and AI-driven evidence collection that RegScale delivers to its customers is what RegScale uses to meet progressively more complex standards itself. Each new certification is both a milestone in the company’s security maturity and a live proof point for the product, independently validated across government and commercial markets.
That is what makes this more than a compliance story. It is a security evolution story. A program that compounds, where the controls, evidence, and discipline built for one framework accelerate the next, is the clearest evidence that continuous assurance works, because RegScale keeps proving it on itself as the requirements get harder.
Read more success stories
See what RegScale can streamline for you
Book a demo now for a quick walkthrough of how our continuous controls monitoring can solve your compliance, risk, and cybersecurity challenges.

