Readiness check
← CMMC Level 2
CMMC Level 2 / Control family · RA

Risk Assessment

That risk to CUI is assessed, vulnerabilities are found and scored, and they are remediated on a schedule.

3
requirements in this family
What it requires

The 3 requirements, in plain language.

3.11.1 Risk Assessments

Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI

3.11.2 Vulnerability Scan

Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified

3.11.3 Vulnerability Remediation

Remediate vulnerabilities in accordance with risk assessments

NIST SP 800-171 Rev 2 — Family RA. CMMC Level 2 assesses each requirement's objectives via a C3PAO. NIST SP 800-171r2 →
How Aletheon covers it

One owner across the whole family — built, run, and proven.

Enclave builds these controls into the boundary as code; Cadence keeps them enforced between assessments; Attest proves them to the C3PAO against every objective.

See all fourteen families →

Not sure which families your contract puts in scope?

A readiness check maps your environment to all 110 controls and tells you exactly where you stand.