RA · 3 requirements

Risk Assessment

Risk Assessment is about knowing your own weaknesses before an adversary does: scanning for vulnerabilities and judging the risk they pose. It turns security from guesswork into a managed program.

Build Risk Assessment, and all 14 families, with an officer

The Level 2 workspace walks all 110 requirements with you at the objective level, generates your SSP, POA&M, and Audit Room from real evidence, gives your assessor a read only seat, and puts a Registered Practitioner alongside you year round.

No credit card, and Level 1 and Level 2 are both open, so sign up for the level your contracts call for. Self assessment and self attestation are law today, DFARS 252.204-7012 is unaffected, and the NIST SP 800-171 Rev 2 baseline is unchanged, so the Level 2 work counts either way.

Questions, answered

How many CMMC Level 2 requirements are in Risk Assessment?+

The Risk Assessment family (RA) has 3 of the 110 CMMC Level 2 requirements, assessed against 9 objectives from NIST SP 800-171A.

What is the Risk Assessment family about?+

Risk Assessment is about knowing your own weaknesses before an adversary does: scanning for vulnerabilities and judging the risk they pose. It turns security from guesswork into a managed program.