compli.ai
Compli.ai

CMMC compliance software that runs your whole CUI program, from inventory to SPRS score.

When a defense contract puts Controlled Unclassified Information in your environment, DFARS 252.204-7012 makes safeguarding it your obligation. Compli.ai runs the program behind that obligation inside a SharePoint site you already own and defend: the inventory of what CUI you hold and how it reaches you, all 110 NIST SP 800-171 requirements, 320 assessment objectives, live Department of War (DoW) SPRS scoring, and the federally defined POA&M rules. There is no new SaaS vendor in your scope, and it works identically in Commercial, GCC, GCC High, and DoD clouds.

110 + 320
Requirements and assessment objectives for protecting CUI, seeded in-tenant
0
External calls made by the core system
4 clouds
Commercial · GCC · GCC High · DoD
July 2026 update

CMMC Phase II is suspended, and the CUI obligation it verifies remains in force.

On July 13, 2026, DoW suspended CMMC Phase II, the third-party assessment mandates that were set to begin November 10, and opened a 60-day review of the program. CMMC, at 32 CFR Part 170, is how the Department verifies that a contractor handles CUI properly, and it is not the source of that duty. DFARS 252.204-7012 still requires you to safeguard covered defense information and report an incident within 72 hours. Phase 1 self-assessment requirements still apply, and awards and option exercises still require a current SPRS score and affirmation. Implementing NIST SP 800-171, the standard for protecting CUI in nonfederal systems, remains a condition of doing business with the Department.

Self-attestation, backed by evidence you can defend, is the compliance motion right now. The review window is the time to close the gaps in how you protect CUI rather than wait for the outcome.

The problem

The records that describe how you protect CUI deserve CUI-grade handling.

Your CUI inventory names what you hold and where it lives. Your SSP implementation statements describe exactly how your defenses work. Your POA&M lists the places where that protection is still incomplete, and your evidence library maps the environment around it. Taken together, that material is a map of your CUI and the controls standing in front of it. When it lives in a third-party GRC SaaS, three problems follow:

Your assessment scope grows

A new external service now stores the records that describe your CUI environment and its open weaknesses, which means you have to answer the DFARS 252.204-7012 flow-down questions about it.

GCC High gets harder

Tools that call out to commercial CDNs and external APIs do not belong in a sovereign-cloud enclave built to hold CUI, and often cannot even reach one.

Your audit trail is not fully yours

The record of how you protected CUI lives in another vendor's database, under their retention terms and behind their export feature, rather than in a system you control.

Because the program runs inside the same boundary that already holds and defends your CUI, there is no new external service to scope and no flow-down questions about a SaaS vendor to answer.

The platform

The platform covers the whole program: know your CUI, protect it to 800-171, prove it.

CUI inventory and flows

Record what CUI you hold, where it lives, and how it reaches you, with each data asset carrying its CUI Registry category, storing system, ingress channel, and flow narrative. A systems inventory maps the boundary around it, and both feed your SSP's data-flow section.

Tour the modules

Controls Matrix

Track all 110 requirements with a verdict on each of the 320 objectives, alongside SSP implementation statements, ownership, and enforced justification for anything marked not applicable.

Live SPRS scoring

Your score is computed as you assess, following the DoD Assessment Methodology v1.2.1 and the CMMC scoring rule at 32 CFR 170.24: partial-credit rules, the SSP prerequisite, and the 88-point conditional threshold. This is the score you keep current and affirm in SPRS as your attestation that your CUI safeguards are in place.

How the math works

POA&M with the rules built in

The platform enforces 32 CFR 170.21 eligibility at item creation, tracks milestones and vendor check-ins, and runs the 180-day closeout countdown, so every safeguard you have not finished carries a dated plan.

See the rules

Assessment-ready evidence

Upload artifacts in the hub, tag them to requirements and 800-171A objectives, and track their freshness and expiration, so your self-attestation rests on current proof. The optional Environment Monitor captures read-only posture from Intune, Entra ID, Secure Score, and Conditional Access as evidence with one click, and it stays off until your admin enables it.

Security model

Governed policy library

A governed documentation library tracks lifecycle states, maps policies to controls, flags family coverage gaps, and runs one-click workforce acknowledgement campaigns.

Delivery

The delivery team handles deployment, typically in an afternoon.

Compli.ai's delivery team deploys and maintains the platform for each tenant. They stand up the SharePoint site, seed the official NIST and DoW catalog, and publish the hub. Upgrades re-run the same setup: the catalog text refreshes and the app updates in place, while your statuses, notes, POA&Ms, and documents are never overwritten. Pair the deployment with a readiness assessment from our team to turn the review window into a closed list of the gaps in how you protect CUI.

Microsoft 365 Commercial
GCC
GCC High
DoD

See the program running on a live tenant.

Book a demo and we will walk your team through a live tenant, from a new deployment starting at −203 to a finished CUI program that is ready to self-attest.