CMMC Level 2 · Phase 2 begins November 10, 2026

The standard is 110 controls.
Prove yours.

RiskTape maps your security controls to the evidence that proves them and keeps the record assessor-ready every day. Reach CMMC Level 2 certification faster — and stay certified after the assessor leaves.

Scroll
The stakes

The clause is already in contracts. The certification is not something you stand up in a month.

As of November 10, 2025, CMMC requirements appear in new DoD solicitations. On November 10, 2026, the DoD can require third-party CMMC Level 2 certification as a condition of award for any contract touching Controlled Unclassified Information. Level 2 means proving all 110 NIST SP 800-171 controls to a certified assessor — with evidence, not attestations. Preparation runs six to twelve months, and C3PAO capacity is scarce. If you start when the clause shows up in a solicitation you want, you are already behind.

Nov 10, 2025CMMC requirements appear in new DoD solicitations.
Nov 10, 2026Level 2 certification can be required as a condition of award.
C3PAOCertification is third-party. Assessor capacity is scarce.
6–12 monthsTypical preparation time to reach Level 2.
110
controls in NIST SP 800-171. Level 2 means proving every one to a certified assessor — with evidence, not attestations.
Where compliance breaks

Evidence is where certification fails.

Most contractors have policies. Few can show, on demand, that the controls those policies describe are operational. Assessors flag the gap between what the System Security Plan says and what the systems actually do — and an inflated SPRS score is now a legal liability, not just a failed audit. RiskTape closes that gap: it maps your controls to the evidence that proves them, catches drift when a control stops holding, and keeps the record assessor-ready every day, not just at assessment time.

How it works

Continuous evidence, mapped to every control.

Map

Every control, to its evidence

RiskTape connects each NIST SP 800-171 control to the evidence that proves it — automated checks where your systems can answer, tracked manual evidence where an assessor expects documents.

Watch

Catch drift as it happens

When a control drifts out of compliance, RiskTape catches it and tells you what to fix.

Prove

Assessor-ready on demand

Generate an assessor-ready evidence package on demand — the same view your C3PAO will want.

One analyst can maintain a compliance posture that used to take a team. That is the point.

Frameworks

Start with CMMC. Extend across the framework graph.

RiskTape is built on NIST CSF 2.0 and NIST SP 800-171, with its deepest automated checks on CIS v8. The same evidence maps across CMMC, ISO 27001, SOC 2, HIPAA, PCI DSS, and HITRUST — so the work you do for certification carries into every framework a buyer or auditor asks for next.

800-171110 controls
Why RiskTape

Built by operators, on a platform that already works.

RiskTape did not start from a slide. It runs on a working compliance engine that ships as a single self-contained appliance you can stand up on day one — a real platform, not a roadmap. It is built by a cybersecurity executive who has run these programs, for the contractors who have to pass these assessments.

Founder

From someone who has been on your side of the assessment.

RiskTape is built by Kevin Stallard, a cybersecurity executive who has run security and compliance programs end to end. RiskTape is the tool he wanted when the deadline was his.

Start now

Your award depends on it. Start now.

A readiness assessment shows exactly where you stand against the 110-control standard and what it takes to certify. Tell us where you are today — it goes straight to the founder, and you will hear back within one business day.

No newsletter, no drip campaign. Your note goes to a person.