RA Domain

Risk Assessment CMMC Level 2

Assess risk to organizational operations and assets — 3 requirements covering 9 total SPRS points.

3 Requirements
9 SPRS Points at Risk
100% Complete Coverage

Risk Assessment Domain Overview

The Risk Assessment domain requires organizations to periodically assess the risk to organizational operations, assets, and individuals resulting from operating information systems — and to scan for and remediate vulnerabilities. Risk assessment connects your security controls to the actual threats your organization faces. Vulnerability scanning requirements here are among the most commonly cited findings in C3PAO assessments.

All 3 Risk Assessment Requirements

Every NIST SP 800-171 Rev 2 requirement in the RA family, with SPRS point weight and POA&M eligibility.

RequirementDescriptionPointsPOA&M
RA.L2-3.11.1Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.3Yes
RA.L2-3.11.2Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.5Conditional
RA.L2-3.11.3Remediate vulnerabilities in accordance with risk assessments.1Yes

How 1TEN Covers This Domain

Risk Register & Heat Map

Catalog every organizational risk with likelihood and impact scores. The visual heat map prioritizes threats to CUI operations, giving assessors the evidence 3.11.1 demands.

Automated Vulnerability Scanner Integration

Ingest scan results from Nessus, Qualys, or OpenVAS on a scheduled or on-demand basis. New CVEs automatically create findings linked to affected assets, satisfying the periodic and event-driven scanning in 3.11.2.

Remediation Tracking Workflow

Assign, track, and verify vulnerability remediation with due dates and owner accountability. Closed findings link back to the risk assessment that triggered them, proving 3.11.3 compliance end-to-end.

Risk Assessment Templates

Pre-built assessment templates aligned to NIST SP 800-30 guide your team through threat identification, vulnerability analysis, and risk determination. Complete assessments export as assessment-ready artifacts.

Continuous Risk Monitoring Dashboard

A real-time dashboard aggregates open risks, unresolved vulnerabilities, and overdue remediations into a single view. Trend lines show whether your risk posture is improving or degrading over time.

Common Tools for RA Compliance

These tools are commonly used by defense contractors to satisfy RA requirements. During your C3PAO assessment, you'll document exactly which tools satisfy each control.

What C3PAO Assessors Verify

Assessors will ask for your risk assessment documentation and verify it covers your CUI-handling systems. They'll request vulnerability scan results and ask about your remediation cadence. High and critical vulnerabilities that remain unaddressed are a significant finding — expect assessors to verify patch currency.

Why This Domain Matters
Risk assessment isn't a checkbox exercise. It's the mechanism that connects your vulnerability scans, your POA&Ms, and your remediation priorities into a defensible compliance posture.

Related Domains

Air-gapped. On-premises.

1TEN is a GRC platform built for the security posture CMMC demands. No cloud. No subscriptions. No data leaving your environment.

Request a Demo