Case Study · CMMC Level 2

A Complete Level 2 Evidence
Package in 18 Hours

The documentation workstream that takes most contractors weeks to months took one sub-50-person technology company 18 hours — with a human approving every evidence-to-control link.

7 min read · Published June 2026

CMMC Level 2 preparation has a workstream that consumes more calendar time than almost any other: documentation and evidence. Building the artifact package an assessor will actually examine — policies, procedures, and evidence mapped to all 110 NIST SP 800-171 requirements — routinely takes weeks to months of senior staff or consultant time. It's the line item that quietly extends every CMMC timeline and breaks most CMMC budgets.

This case study covers an engagement where that workstream took 18 hours.

The organization

The client is a federal-focused technology company with fewer than 50 employees — squarely in the profile of the roughly 70% of the defense industrial base that qualifies as a small business. Like most small contractors, it had real security practices and real existing documentation, but nothing organized the way a C3PAO examines it: evidence scattered across systems, policies written for operations rather than mapped to control requirements, and no staff to spare for a months-long documentation project.

What the 18 hours covered

The engagement ran entirely inside PRISM, Risk Aperture's compliance assessment platform, across three phases:

PhaseWhat happenedWho did the work
1. Evidence uploadThe company's existing documentation — policies, procedures, architecture documents, operational records — was uploaded into PRISM. The platform's AI document analysis assessed each artifact against Level 2 requirements and classified status: compliant, partial, or policy-only.Client uploads; Iris AI analyzes
2. Template generationFor requirements with missing or insufficient documentation, PRISM generated the needed policies and procedures from its template library — customized to the organization by the AI engine. The client drafted nothing.Iris AI generates and customizes
3. Review & approvalEvery evidence-to-control link was reviewed and approved by a human before being finalized. Nothing entered the assessment package on AI judgment alone.Human in the loop, always
18 hrs
Total time for the complete Level 2 evidence workstream
110
NIST SP 800-171 requirements covered in the evidence package
100%
Of evidence-to-control links reviewed and approved by a human

Why the human-in-the-loop design matters

An evidence package is a set of claims you'll defend in front of an assessor. AI that silently asserts compliance is a liability in that room — which is why PRISM is built conservative by design. The AI does the information processing: reading documents, mapping them to requirements, drafting what's missing, proposing the links. A person makes every final call. The output isn't "the AI says you're compliant"; it's "your team approved this mapping, with the analysis done for them instead of by them."

That division of labor is precisely why the timeline collapses. The weeks-to-months in a traditional documentation engagement aren't spent on judgment — they're spent on reading, cross-referencing, formatting, and drafting. Those are the hours the AI absorbs. The judgment, which was always the valuable part, is what the 18 hours mostly consisted of.

What this engagement was — and wasn't

Precision matters in CMMC claims, so to be clear about scope: the 18 hours covered the documentation and evidence workstream — the package preparation that traditionally consumes weeks to months (stage 4 in our timeline guide). It did not include infrastructure remediation, which depends on an organization's starting posture, and it is not the C3PAO assessment itself, which only an authorized third party can perform.

That scoping is exactly why the result generalizes. Remediation time varies enormously between organizations; evidence-preparation time traditionally varies mainly with how much documentation exists and how many staff hours can be thrown at it. Making that workstream a function of AI processing plus human review — instead of staff availability — is what changes the planning math for any contractor, regardless of posture.

What it means for your budget and timeline

Two of the standard CMMC planning numbers change when the evidence workstream compresses:

There's a second-order effect, too: assessors price on friction, and a clean, consistently-mapped evidence package is the opposite of friction. Arriving at the C3PAO engagement with every control linked to reviewed evidence shortens the assessment and the back-and-forth around it.

Engagement figures are from a completed PRISM customer engagement, current as of June 2026. Evidence-preparation results depend on the volume and quality of an organization's existing documentation; the 18-hour figure reflects this engagement and is presented as a demonstrated outcome, not a guarantee. Industry baseline durations and cost ranges per our timeline and cost guides.

See the 18-Hour
Workflow Live

Bring your own documents to a PRISM demo and watch the AI analysis, template generation, and review workflow run on your actual evidence.