Assessment & Evidence

Risk Register Risk Identification · Scoring · Mitigation Tracking

CMMC requires organizations to periodically assess risk to operations, assets, and individuals. The Risk Register provides a structured format for identifying, scoring, and tracking risks across your CUI environment. With the dated history that assessors require as evidence of periodic review.

RA Domain requirements satisfied
Likelihood × Impact scoring
Linked To POA&M items
The problem this solves
Risk assessment is one of the requirements contractors most frequently satisfy on paper but not in practice. A risk assessment document created during the initial compliance effort and never touched again does not satisfy the periodic assessment requirement. And assessors know it. They look at document revision dates, assessment history, and whether risks have been updated to reflect changes in the environment. An undated, unrevised risk register is a finding even if the document exists.

How Risk Identification Works

Each risk entry captures the risk description, the affected systems or domains, a likelihood rating, an impact rating, and a calculated composite risk score. Pre-built risk categories align to the 14 CMMC domains so your assessment covers the full scope of your CUI environment systematically rather than ad hoc.

Risks can be entered manually or surfaced from your open POA&M items. Requirements that are not yet met represent concrete, documented gaps that qualify as organizational risks. Linking POA&M items to risk register entries creates a traceable connection between your compliance gaps and your risk posture, which is exactly the kind of integrated documentation that supports a clean assessment.

Dashboard Requirements Evidence POA&M Reports
1TEN Risk Register listing identified risks with likelihood, impact, and status

Risk Scoring and Periodic Assessment Evidence

The Risk Register's scoring matrix produces a calculated risk level for each entry. High, Medium, or Low. Based on likelihood and impact ratings. The composite score drives prioritization, surfacing which risks require immediate mitigation and which can be accepted or monitored.

Every assessment cycle is dated and preserved in the register history. When an assessor examines RA.L2-3.11.1, the evidence they require is proof that risk assessment happened, that it was documented, and that it occurred more than once. The register's revision history provides exactly that. A timestamped record of each assessment cycle with the risks identified, scores assigned, and mitigations tracked.

Dashboard Requirements Evidence POA&M Reports
1TEN risk detail view with assessment, treatment plan, and linked requirements
Dashboard Requirements Evidence POA&M Reports
1TEN risk acceptance record documenting approved risk decisions and sign-off

What You See Inside

  • *Risk entry form capturing description, affected domain, threat source, likelihood (1–5), and impact (1–5)
  • *Calculated composite risk score and automatic High/Medium/Low classification
  • *Pre-built risk categories organized by CMMC domain for systematic coverage
  • *Mitigation strategy field with responsible owner, target date, and status tracking
  • *Risk acceptance workflow for risks where mitigation is not feasible. Documented acceptance with rationale
  • *Direct link from POA&M items to risk register entries. Compliance gaps reflected as formal risks
  • *Dated assessment cycles with full history. Each review cycle timestamped and preserved
  • *Open risk count displayed on the Assessment Summary dashboard with link to register
  • *Risk register section included in SSP Export. Assessors receive the full register as part of the System Security Plan

Practices Satisfied

Practice IDDescription
RA.L2-3.11.1 Periodically assess the risk to organizational operations, organizational assets, and individuals resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.
RA.L2-3.11.2 Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.
RA.L2-3.11.3 Remediate vulnerabilities in accordance with risk assessments.
CA.L2-3.12.2 Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.

What this replaces

  • *A risk register document created once during the initial compliance effort and never updated. Common finding, immediately visible to assessors from the revision date
  • *Spreadsheet risk registers with no dated assessment history. No way to demonstrate that periodic assessment actually occurred
  • *Compliance gaps tracked in the POA&M with no connection to the risk register. Two separate documents that tell inconsistent stories
  • *Risk acceptance decisions made verbally with no documentation. Assessors cannot verify accepted risks are intentional rather than overlooked
  • *Risk mitigations tracked in a separate project plan with no link back to the formal risk register entry

Related Modules

POA&M Tracker
Open POA&M items link directly to risk register entries. Compliance gaps are reflected as formal risks with mitigation timelines.
Assessment Summary
Open risk count appears on the Assessment Summary dashboard. High-severity open risks are surfaced alongside compliance gaps.
SSP Export
The risk register is included in the SSP Export output. Assessors receive the full register as part of the System Security Plan package.
Compliance Calendar
Periodic risk assessment reviews are scheduled and tracked in the Compliance Calendar to ensure the review cadence satisfies RA.L2-3.11.1.
See Risk Register in action.

Every module ships on the 1TEN appliance. No configuration required. Schedule 30 minutes and see it running with your organization's data.

Request a demo