The CMMC suspension, data residency, GCC High, SPRS math, POA&M rules, upgrades, and administration — answers about running the program that protects the CUI in your environment, inside your own Microsoft 365 tenant.
On July 13, 2026, the Department suspended CMMC Phase II, the third-party assessment mandates that had been scheduled for November, and opened a 60-day program review. What is under review is the program that verifies CUI handling, not the duty to handle CUI properly. The suspension did not touch the Phase 1 self-assessment requirements or your DFARS 252.204-7012 clause: the CUI in your environment still has to be safeguarded to NIST SP 800-171, cyber incidents still have to be reported to the Department within 72 hours, and your self-assessed SPRS score still has to be current and affirmed for awards and option exercises. Older contracts may still cite DFARS 252.204-7019 and -7020, the clauses that carried this requirement until they were restructured in February 2026. Self-attestation backed by evidence is the compliance requirement today, and if the review brings certification back in some form, a well-run program is ready for it.
Keep your 800-171 program running and use the window to close gaps. Verify that your SPRS score is current and accurate, finish objective-level assessment, put ineligible gaps on a remediation plan rather than a POA&M, and keep your evidence fresh. Treating the pause as a stopping point only creates work later, because the CUI is still in your environment and the requirements that govern how you protect it have not gone away.
No, unless an administrator turns on the one optional integration, and even then the queries stay inside your own Microsoft cloud. Your program records describe exactly how you protect CUI, which is why they deserve the same handling discipline as the CUI itself. The core system calls only your own SharePoint site, acting as the signed-in user with that user's permissions. The optional integration, which is off by default, adds read-only Microsoft Graph queries against your own Microsoft 365 environment. Leave it disabled and nothing leaves your tenant.
Every list item keeps its full version history, recording who changed what and when, and changes made through the hub also append automatic entries to a formal Change Log. Nothing is hidden or quietly removed, so the record of how your CUI protection reached its current state is always available.
No. The product stores no credentials anywhere. The optional monitor runs on the signed-in user's own identity, using read-only permissions that an administrator approves once.
Yes. The platform runs in Microsoft 365 Commercial, GCC, GCC High, and DoD environments with the same features. Because the core product makes no external calls, there is no commercial-cloud endpoint that could break in a sovereign environment.
Because nothing has been assessed yet. Every requirement starts at Not Started and deducts its full DoW-assigned weight, so the score begins at the methodology's floor of −203. That is the DoD Assessment Methodology's own arithmetic: 110 minus the sum of the weights. As you record the implementation status of each requirement, the score rises toward 110, using the same arithmetic a government assessor would apply.
Yes. The scoring engine implements the DoD Assessment Methodology v1.2.1 and 32 CFR 170.24 exactly: the 1, 3, and 5 point weights, the two partial-credit conditions (3.5.3 for MFA and 3.13.11 for non-FIPS encryption), the 3.12.4 SSP prerequisite, and the 88-point conditional threshold. The catalog and weights are built directly from the official NIST and DoW publications and verified with every release.
This is a federal rule rather than a product setting. 32 CFR 170.21 allows only 1-point requirements onto a POA&M, with one conditional exception at 3.13.11, and excludes six requirements outright. The panel shows you the governing citation. A gap in your safeguards that is not POA&M-eligible has to be remediated; until it is, the requirement continues to count against your score.
You can. They are normal SharePoint lists and the hub reads live data, so a direct edit shows up immediately. We recommend working through the hub because it enforces rules that raw list edits bypass, including N/A justifications, POA&M eligibility, workflow transitions, and automatic change-logging.
You do, using ordinary SharePoint group membership on your existing Entra identities: Owners have full control, Contributors edit all module data, and Readers view and acknowledge policies. There is no separate user store and no separate login to manage.
The Compli.ai delivery team re-runs the deployment. The catalog text and weights refresh and the app upgrades in place, while your statuses, notes, verdicts, POA&Ms, documents, and settings are never overwritten. Updates are designed so your assessment data always survives an upgrade. If the Department's review rewrites requirements or scoring, that change ships the same way, without touching the work you have already recorded.
Yes. The assessment type is a first-class setting, and the program the hub builds gives you the record either track needs to show how CUI is protected: control statuses, objective verdicts, evidence tied to each objective, policy acknowledgements, and change history. Today that supports a defensible self-attestation. If certification mandates return after the review, the same record is what a third-party assessor would examine.
A Microsoft 365 tenant with SharePoint Online, which most defense contractors already run. There is no per-seat GRC license server, no Azure resources to stand up, and no vendor backend to depend on. Packaging and pricing are scoped to each engagement, so talk to the team about your environment.
Yes. Upload your logo during onboarding and it becomes the hub's logo for everyone in your organization. Like everything else, it stays inside your tenant.