TYSONS CORNER, Va., Sept. 02, 2026 (GLOBE NEWSWIRE) — RegScale, the AI-powered continuous controls monitoring (CCM) platform, today announced it has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2, validating that its security environment meets or exceeds the rigorous requirements for protecting Controlled Unclassified Information (CUI) across the U.S. defense supply chain. The certification strengthens RegScale’s readiness to support U.S. Department of War (DoW) contracts and pursue expanded opportunities across the Defense Industrial Base (DIB).

CMMC Level 2 requires organizations that handle CUI to implement 110 security requirements aligned with NIST SP 800-171 and demonstrate their effectiveness through an independent assessment by a Certified Third-Party Assessment Organization (C3PAO), reinforcing its commitment to upholding the highest security standards essential to earning defense customers’ trust and ensuring 100% compliance regardless of evolving mandates.

Following an independent assessment by A-LIGN where 320 NIST SP 800-171A Rev. 2 objectives were evaluated, RegScale met 110 of 110 security requirements and 14 of 14 CMMC domains. Additionally, zero POA&M items were reported, which means that RegScale’s posture was already found to be extremely robust and exceeding the DoW requirements. These results underscore the rigor of our cybersecurity program and operational discipline required to protect sensitive government information.

“A resilient security program should do more than simply pass an assessment,” said Dale Hoak, CISO of RegScale. “At RegScale, we’ve built a model that continuously proves our controls work, and the results speak to the value of that approach. When controls are continuously monitored, and evidence is generated from the pipeline through production, compliance becomes an outcome of operational excellence in cybersecurity versus an annual fire drill to pass an audit.”

The certification also reflects how RegScale applies the same CCM approach it champions for its highly regulated customers into practice internally. Powered by compliance-as-code architecture, RegScale’s platform provides the foundation to centralize requirements, continuously gather evidence, monitor controls, and give auditors a clear view into its security posture. These capabilities make assessments with auditors more efficient, enabling both RegScale and its customers to adapt to changing requirements while continuing to innovate and advance cyber resilience.

The achievement builds on the company’s track record of meeting rigorous federal and commercial security requirements, including FedRAMP Class D (High) authorization with agency sponsorship from the Department of Homeland Security. RegScale has also secured other independently audited certifications such as SOC 2, Cloud Security Alliance (CSA) STAR designation, and ISO 27001, which was achieved in under 30 days using its own platform. Together, these milestones underscore RegScale’s ability to operate the highest levels of security assurance across both government and commercial markets, meeting some of the most demanding industry standards across increasingly complex compliance environments.

To learn more about RegScale’s CMMC Level 2 certification and its work supporting federal cybersecurity and compliance, read the success story here or visit www.RegScale.com.

About RegScale
RegScale is a Continuous Controls Monitoring (CCM) platform designed to be the operational risk tool for the CISO. Built on a compliance-as-code foundation, RegScale enables extreme automation with an API-first strategy, self-updating paperwork, and powerful AI agents that all but eliminate manual labor and make GRC programs more proactive. Customers save money, accelerate time to market, and reduce risk in their operational environments with RegScale. Heavily regulated organizations, including Fortune 500 enterprises and the federal government, use RegScale and report achieving compliance certifications 90% faster and trimming audit preparation efforts by 60%, strengthening security and reducing costs. Learn more at www.regscale.com.

Media Contact
Sarah Ribacoff for RegScale
sarah@aspironinfluence.com


Primary Logo

About The Author