Guide — CMMC L2
CMMC assessors ask for evidence, not intentions.
Access decisions for CUI environments need a traceable record: who approved access, under what policy, with what screening outcome, and whether MFA was enforced for privileged reviewers.
- Audit chain
- MFA gate
- Evidence pack

Decision before access
Intake, screening, review, approval gate, and evidence export stay on one record.
Evidence
What to show an assessor
- A case-level timeline of intake, screening, review, and final decision events.
- Append-only audit rows with SHA-256 hash chaining — no silent edits.
- Screening run metadata and match-resolution counts without raw PII in audit logs.
- Exportable JSON / PDF / ZIP evidence packs scoped to a single request ID.
- MFA enforcement for orgs that require AAL2 before dashboard and API access.
Practice
Where Regulated Access fits CMMC practice
Regulated Access is pre-access decision infrastructure — not a full CMMC platform. It complements identity providers, physical access systems, and visitor management by owning the compliance decision before someone reaches a CUI-controlled area.
For organizations already pursuing CMMC Level 2, the product gives compliance managers a reviewer queue, structured approvals, and an evidence export path that maps cleanly to access-control assessment interviews.