RegScale CMMC Level 2 Blog_Post Preview

How We Earned CMMC Level 2 by Operating Securely 90% Faster 

By Dale Hoak |

October 5, 2026

When our security team set out to earn the Cybersecurity Maturity Model Certification (CMMC) Level 2, we made one early decision that would shape everything: we would not treat the assessment as a project. We would let our security program speak for itself. A resilient program should do more than pass an assessment. It should continuously prove that its controls work. That belief is why I can share that RegScale is now CMMC Level 2 certified with 110 of 110 requirements met and zero POA&M items. 

Why We Pursued Level 2 After the Pause 

Even after the Department of War (DoW) paused CMMC Phase 2 implementation, we chose to continue. Earning the trust of defense customers is not something I want to defer to a timeline that may shift again. CMMC Level 2 sets a high bar: 110 security requirements aligned with NIST SP 800-171, validated through an independent assessment by a Certified Third-Party Assessment Organization. If we expect our customers to hold that line, we should hold it ourselves first. 

We Did Not Prepare for an Audit. We Operated. 

Most organizations approach CMMC as an evidence-collection sprint. They stand up a project, bring in outside readiness consultants and reconstruct a point-in-time snapshot of their controls. We built our program the other way around. Leveraging our own RegScale Continuous Controls Monitoring (CCM) platform, the security team monitored controls continuously, and we collected evidence as a by-product of normal operations, from our delivery pipeline through production. When A-LIGN assessed us, the proof was already there. We did not have to go find it, repackage it or rebuild it. 

What Continuous Assurance Looked Like Under Assessment 

The results tell the story. We met 110 of 110 security requirements and all 14 CMMC domains across 320 assessment objectives, with zero POA&M items. As a security leader, the most telling number is 76%. Of the 25 follow-up items the assessors raised, 19 were resolved live, while the assessor was still on the call, because the evidence and control context were already connected and available in the RegScale platform. Our documentation stayed alive throughout. 14 controls moved from N/A to Fully Implemented with revised SSP statements during the sessions, and our SSP implementation statements were 100% complete at close. That is the difference between a static compliance package and a living compliance system. 

The Economics of Operating This Way 

There is a cost argument here that security leaders will appreciate. The DoW models 286 hours of combined internal and external effort for a small entity to prepare for and support a Level 2 assessment. We used 28 hours, roughly 90% less, and we used no outside readiness consultant. I want to be precise on why. We were able to shrink the preparation and support burden around the assessment because the security program was already doing that work every day with our own RegScale CCM platform. 

Compliance as a By-Product of Security 

This is the philosophy we build into our platform, and the one I would offer to any CISO: security operations should produce compliance evidence as a by-product, not as a separate project. When controls are monitored continuously and evidence is generated as part of normal operations, an assessment becomes validation of an existing posture rather than a scramble to reconstruct one. CMMC did not change how we operate. It confirmed that operating securely and continuously produces compliance as the outcome. 

Our Security Program has Evolved on Purpose 

CMMC Level 2 is another stepping stone in a deliberate climb, not a one-off certification, and proof of why CCM promotes good security. In the past few years, we earned ISO 27001 in under 30 days, using our own platform. We also became FedRAMP Class D (High) certified with agency sponsorship from the Department of Homeland Security. Now CMMC Level 2. Each standard is more demanding than the last, and we pursued them on purpose because our customers operate under exactly these pressures, and they should see us living them first. 

Here is the part I am proudest of. We earned every one of these certifications by leveraging our own platform. The continuous controls monitoring, the compliance-as-code architecture and the AI-driven evidence collection we build for our customers are the same machinery we use to meet these standards ourselves. Our security program compounds. Every certification makes the next one faster because the controls, evidence and discipline are already in place. That is what a maturing security program looks like, and it is why I can stand behind our platform without hesitation: we run our own company on it. 

What This Means Going Forward 

The commitment behind all of this is simple: prove it, continuously. If you are a security leader staring down CMMC, my advice is just as simple. Stop preparing for the audit and start operating the program that makes the audit a formality. 

See how RegScale’s Continuous Controls Monitoring platform helps organizations turn compliance into a by-product of security operations; schedule a product demo. 

Carahsoft Technology Corp. is The Trusted Government IT Solutions Provider, supporting Public Sector organizations across Federal, State and Local Government agencies and Education and Healthcare markets. As the Master Government Aggregator for our vendor partners, including RegScale we deliver solutions for Geospatial, Cybersecurity, MultiCloud, DevSecOps, Artificial Intelligence, Customer Experience and Engagement, Open Source and more. Working with resellers, systems integrators and consultants, our sales and marketing teams provide industry leading IT products, services and training through hundreds of contract vehicles. Explore the Carahsoft Blog to learn more about the latest trends in Government technology markets and solutions, as well as Carahsoft’s ecosystem of partner thought-leaders.

This post originally appeared on RegScale.com, and is re-published with permission.


Related Articles