Guide — CMMC L2

CMMC assessors ask for evidence, not intentions.

Access decisions for CUI environments need a traceable record: who approved access, under what policy, with what screening outcome, and whether MFA was enforced for privileged reviewers.

  • Audit chain
  • MFA gate
  • Evidence pack
CMMC L2 access decision evidence dashboard

Decision before access

Intake, screening, review, approval gate, and evidence export stay on one record.

Evidence

What to show an assessor

  • A case-level timeline of intake, screening, review, and final decision events.
  • Append-only audit rows with SHA-256 hash chaining — no silent edits.
  • Screening run metadata and match-resolution counts without raw PII in audit logs.
  • Exportable JSON / PDF / ZIP evidence packs scoped to a single request ID.
  • MFA enforcement for orgs that require AAL2 before dashboard and API access.

Practice

Where Regulated Access fits CMMC practice

Regulated Access is pre-access decision infrastructure — not a full CMMC platform. It complements identity providers, physical access systems, and visitor management by owning the compliance decision before someone reaches a CUI-controlled area.

For organizations already pursuing CMMC Level 2, the product gives compliance managers a reviewer queue, structured approvals, and an evidence export path that maps cleanly to access-control assessment interviews.