When a defense contract puts Controlled Unclassified Information in your environment, DFARS 252.204-7012 makes safeguarding it your obligation. Compli.ai runs the program behind that obligation inside a SharePoint site you already own and defend: the inventory of what CUI you hold and how it reaches you, all 110 NIST SP 800-171 requirements, 320 assessment objectives, live Department of War (DoW) SPRS scoring, and the federally defined POA&M rules. There is no new SaaS vendor in your scope, and it works identically in Commercial, GCC, GCC High, and DoD clouds.
On July 13, 2026, DoW suspended CMMC Phase II, the third-party assessment mandates that were set to begin November 10, and opened a 60-day review of the program. CMMC, at 32 CFR Part 170, is how the Department verifies that a contractor handles CUI properly, and it is not the source of that duty. DFARS 252.204-7012 still requires you to safeguard covered defense information and report an incident within 72 hours. Phase 1 self-assessment requirements still apply, and awards and option exercises still require a current SPRS score and affirmation. Implementing NIST SP 800-171, the standard for protecting CUI in nonfederal systems, remains a condition of doing business with the Department.
Self-attestation, backed by evidence you can defend, is the compliance motion right now. The review window is the time to close the gaps in how you protect CUI rather than wait for the outcome.
Your CUI inventory names what you hold and where it lives. Your SSP implementation statements describe exactly how your defenses work. Your POA&M lists the places where that protection is still incomplete, and your evidence library maps the environment around it. Taken together, that material is a map of your CUI and the controls standing in front of it. When it lives in a third-party GRC SaaS, three problems follow:
A new external service now stores the records that describe your CUI environment and its open weaknesses, which means you have to answer the DFARS 252.204-7012 flow-down questions about it.
Tools that call out to commercial CDNs and external APIs do not belong in a sovereign-cloud enclave built to hold CUI, and often cannot even reach one.
The record of how you protected CUI lives in another vendor's database, under their retention terms and behind their export feature, rather than in a system you control.
Because the program runs inside the same boundary that already holds and defends your CUI, there is no new external service to scope and no flow-down questions about a SaaS vendor to answer.
Record what CUI you hold, where it lives, and how it reaches you, with each data asset carrying its CUI Registry category, storing system, ingress channel, and flow narrative. A systems inventory maps the boundary around it, and both feed your SSP's data-flow section.
Tour the modulesTrack all 110 requirements with a verdict on each of the 320 objectives, alongside SSP implementation statements, ownership, and enforced justification for anything marked not applicable.
Your score is computed as you assess, following the DoD Assessment Methodology v1.2.1 and the CMMC scoring rule at 32 CFR 170.24: partial-credit rules, the SSP prerequisite, and the 88-point conditional threshold. This is the score you keep current and affirm in SPRS as your attestation that your CUI safeguards are in place.
How the math worksThe platform enforces 32 CFR 170.21 eligibility at item creation, tracks milestones and vendor check-ins, and runs the 180-day closeout countdown, so every safeguard you have not finished carries a dated plan.
See the rulesUpload artifacts in the hub, tag them to requirements and 800-171A objectives, and track their freshness and expiration, so your self-attestation rests on current proof. The optional Environment Monitor captures read-only posture from Intune, Entra ID, Secure Score, and Conditional Access as evidence with one click, and it stays off until your admin enables it.
Security modelA governed documentation library tracks lifecycle states, maps policies to controls, flags family coverage gaps, and runs one-click workforce acknowledgement campaigns.
Compli.ai's delivery team deploys and maintains the platform for each tenant. They stand up the SharePoint site, seed the official NIST and DoW catalog, and publish the hub. Upgrades re-run the same setup: the catalog text refreshes and the app updates in place, while your statuses, notes, POA&Ms, and documents are never overwritten. Pair the deployment with a readiness assessment from our team to turn the review window into a closed list of the gaps in how you protect CUI.
Book a demo and we will walk your team through a live tenant, from a new deployment starting at −203 to a finished CUI program that is ready to self-attest.