RiskWatch
RiskWatch International · Founded 1993 · Annapolis, MD, USA
Construction TVRA platform with pre-mapped ASIS, CPTED, NIST 800-53 PE, and OSHA 1926 libraries in one tenant.
Summary
RiskWatch ships a physical security assessment platform with pre-mapped libraries for ASIS Facility Physical Security Control Standards, CPTED, NIST 800-53 PE-1 through PE-23, NIST 800-171 r3 §3.10 for CUI-handling federal-construction primes, OSHA 29 CFR 1926 Subparts C and M where site access intersects with worker safety, OSHA 1910 General Industry for the permanent-facility side of multi-business general contractors, CMMC 2.0 Level 2 PE domain, C-TPAT MSC for cross-border modular and prefab moves, ISO 28000 for project-site supply chain security, and PCI DSS where on-site retail or visitor-payment scope exists. Crime-data overlay from four feeds (Cap Index CRIMECAST, Security Gauge, GlobalIncidentMap, World Aware) maps each lay-down yard and active-phase site against NICB equipment-theft hotspot data. Customers include ENR top-400 general contractors, owner-builders running multiple active projects, federal-construction primes handling CUI under DFARS 252.204-7012, and energy-and-utilities construction-services firms. The product has been in the field since 1993.
Strengths
- Pre-built ASIS Facility Physical Security Control Standards, CPTED, NIST 800-53 PE-1 through PE-23, and OSHA 29 CFR 1926 Subparts C and M libraries in one tenant; auditor-export packs accepted by CCIP / OCIP wrap-up carriers
- Pre-built NIST 800-171 r3 §3.10 and CMMC 2.0 Level 2 PE domain libraries for federal-construction primes handling CUI under DFARS 252.204-7012 with Phase 2 enforcement effective November 10 2026
- Crime-data overlay from four independent feeds aligned to NICB and Equipment Watch construction-theft hotspot baselines; every likelihood score traces back to its source and last-updated date
- Browser-based mobile TVRA that works offline at active phases, lay-down yards, and rural heavy-civil sites; syncs when cellular returns; findings are not lost
- Project Risk Cycle with per-phase cadence, recommendation register, and proof-of-close at active-phase and lay-down-yard granularity; tracks site security posture across the project lifecycle
- 30-day free trial with no credit card and full platform access, the only TVRA-first vendor on this list offering it for construction buyers
- Single-tenant deployment with US-only data residency for federal-construction primes under ITAR § 120.55 or EAR § 734.18(a)(5) handling controlled technical data
- Multi-project rollup dashboards at site, region, and enterprise level with year-over-year trend lines for top-100 ENR portfolios
Weaknesses
- Not a VMS or access control system or remote-monitoring tower; integrates with LiveView, Verkada, Brivo, Genetec, Eagle Eye, Avigilon, Milestone via APIs and bulk imports rather than deep native connectors at the level a mega-project with 200+ cameras may want
- No native EHS-incident or OSHA 300 / 300A / 301 logbook module; pair with HSI Donesafe, Intelex, VelocityEHS, or EcoOnline for that workload (see /top-10-risk-management-software-for-construction/)
- No native subcontractor prequalification engine at ISN / Avetta / Veriforce depth; we ingest prequalification data via API but do not run the prequalification workflow
- No native CCIP / OCIP wrap-up insurance claims module; pair with Riskonnect or Origami Risk for builders-risk and wrap-up claims handling
- Public pricing is partial; Starter $18K/yr and Professional $36K/yr bands are published on this page, but Enterprise is quote-only because single-tenant deployment topology and federal-construction data residency vary materially
- Brand awareness in construction physical security specifically on G2 and Capterra sits below 100 reviews, lower than Verkada or Genetec in absolute terms
ENR top-400 general contractors, owner-builders, federal-construction primes, and energy-and-utilities construction-services firms running 3+ active projects who need one tenant for project-site TVRA, lay-down yard assessment, evidence capture, and CCIP / OCIP wrap-up carrier reporting.
Single-site residential builders and small specialty subcontractors that only need a few cameras and badge readers and have no separate TVRA or wrap-up insurance requirement; Verkada or Brivo is the better fit there.
Key features
- Pre-built libraries for ASIS Facility Physical Security Control Standards, CPTED, NIST 800-53 PE, NIST 800-171 r3 §3.10, CMMC 2.0 PE, OSHA 29 CFR 1926 Subparts C and M, OSHA 1910 General Industry
- Pre-built libraries for C-TPAT MSC, ISO 28000/28001, ISO 31000, NFPA 1600, PCI DSS, NIST 800-30
- Crime-data overlay from Cap Index CRIMECAST, Security Gauge, GlobalIncidentMap, World Aware mapped against NICB and Equipment Watch construction-theft hotspots
- Browser-based mobile site walks that work offline at active phases, lay-down yards, and rural heavy-civil sites
- Project Risk Cycle with per-phase cadence, recommendation register, and proof-of-close at active-phase and lay-down-yard granularity
- Multi-project rollup dashboards at site, region, and enterprise level with year-over-year trend lines
- CCIP / OCIP wrap-up carrier audit-export packs
- Single-tenant deployment with customer-owned data residency option
- 30-day free trial, no credit card, full platform access
Integrations
25+ native. Notable: Microsoft Entra ID (SAML SSO), Okta, Microsoft 365 / SharePoint, Cap Index CRIMECAST, Genetec, Lenel S2, Avigilon, Milestone, Verkada, Brivo, Eagle Eye (API + bulk import), Jira / ServiceNow, Custom REST API.
Target size
100 to 25,000 employees · US · Canada · EU · UK · AU