Regola Cyber is the 1st C3PAO to Achieve CMMC Using PreVeil


Final Score:

110/110


Regola was seeking to pass the DoD’s C3PAO DIBCAC assessment to become an authorized CMMC 3rd Party Assessor (C3PAO). As an early adopter, Regola was the first company to go up for a DIBCAC assessment using PreVeil.

We believe in security first, compliance second, so there’s strong alignment between how we, PreVeil, and the DoD approach security under the Zero Trust framework.”

Nathan Regola, Ph.D., J.D.

Principal Consultant


As a boutique security consulting firm with a focus in the federal space, Regola Cyber had in-house compliance expertise. But they needed a way to protect and share assessment data, which assessors treat like Controlled Unclassified Information (CUI). They choose PreVeil for 3 reasons:

  • Simpler approach to compliance: “It often takes 6+ months to configure legacy solutions–we were up and running on PreVeil in days.”
  • Time savings on maintenance: “We save time due to fewer software patches, but more importantly, as a result, there’s less documentation & explaining risk decisions.”
  • Significant cost savings: “PreVeil offers significant savings vs legacy solutions because there is no costly deployment, migration, or configuration.

They achieved a perfect 110/110 score on their C3PAO DIBCAC Assessment (in their first attempt).