{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.compli.ai/"},{"@type":"ListItem","position":2,"name":"CMMC for SharePoint","item":"https://www.compli.ai/cmmc-for-sharepoint"},{"@type":"ListItem","position":3,"name":"Modules","item":"https://www.compli.ai/cmmc-sharepoint-modules"}]}
compli.ai
Module tour

Compli.ai organizes its CMMC compliance tools into a dedicated module for each part of handling CUI.

Handling Controlled Unclassified Information properly means three things: knowing what CUI you hold and how it reaches you, protecting it to NIST SP 800-171, and being able to prove that protection to the Department of War (DoW). The GRC Hub gives each of those jobs its own module, all behind one page in your own SharePoint site.

CUI Identification

Everything downstream depends on this inventory: what CUI you hold, where it lives, and how it reaches you. Each data asset records its classification, CUI Registry category, storing system, ingress channel (email, government portal, prime portal, removable media, and so on), and a CUI flow narrative. Rows missing an ingress channel are flagged so the record is complete before an assessor asks, and the flows feed your SSP's data-flow section.

Systems & Boundary

Once you know where CUI lives, the boundary around it can be drawn honestly. Inventory the systems that sit inside your assessment boundary and map the interconnections that populate your SSP's data-flow table. Each system also carries per-system implementation detail on the controls it supports, so the boundary and how it meets each requirement are documented in one place.

Dashboard

The dashboard shows the state of your CUI protection at a glance: the live SPRS score (which turns green once you reach the 88-point conditional threshold), an authorization status ring, a family readiness heatmap across all 14 control families, this month's authorization-cycle checklist, open POA&M items with the 180-day countdown, risk registers, calendar status, audit results, and the latest change records.

Controls Matrix

This is where CUI protection gets specified and assessed. All 110 requirements are filterable by family, status, and text, and each one carries its implementation status, rationale notes (required for any Not Applicable), the SSP implementation statement in your own words, responsibility, owner, and last-assessed date. Under each control sit its SP 800-171A objectives, each with its own Met or Not Met verdict.

POA&M

This is where you plan remediation for the gaps in your safeguards, with the federal eligibility rules built in. You can create items only where federal rules allow, because 32 CFR 170.21 eligibility is enforced and the governing citation is shown alongside each item. Items carry milestones, resources, owners, and vendor dependency check-ins. When you reach Conditional status, the 180-day closeout clock counts down on both the dashboard and the POA&M page.

Security Documentation

The policies that tell your people how CUI is handled live in a governed library that tracks document IDs, lifecycle states (Draft → In Review → Approved → Published), mapped controls, owners, and review dates, with overdue reviews flagged in red. A family coverage map exposes documentation gaps, and the tailoring card turns onboarding answers into copyable tokens so every policy references the same agreed facts.

Evidence

Proof that the safeguards are real, in a form an assessor, or your own attestation reviewer, can navigate with confidence. Upload files straight into your tenant's Evidence library and tag each one to requirements and individual assessment objectives. Freshness is tracked per artifact, and because the Controls Matrix deep-links here, pulling up the evidence for 3.5.3 is a single, pre-filtered click.

Internal Audit

A recurring test program that confirms the controls protecting your CUI are still working. It arrives pre-seeded with quarterly new-user and terminated-user access testing, quarterly change-management testing, an annual penetration test and review, and semi-annual user access reviews. Record the tester, findings, and a Pass or Fail result, and the Generate quarter action rolls the program forward to the next period.

Calendar Events

The recurring work of running the program lives where people already look. Events are grouped by quarter with overdue flags, and because the calendar is a native SharePoint events list, the same schedule overlays directly into Outlook.

Shared Responsibility Matrix

A per-control view of who owns which safeguard across you, Microsoft, and any other providers in the boundary where your CUI sits. Generate a Microsoft 365 baseline drawn from Microsoft's own documentation, refine it to match how your program actually works, and export the full matrix to CSV for your assessor or your file.

Supply Chain

For primes managing a subcontractor chain that handles CUI, this rolls up each sub's posture from summary packages they share with you: SPRS scores, implementation status, and POA&M health. You get the picture across your suppliers with no access to their environments.

Change Log

Formal change management runs the full workflow from Draft → Submitted → Approved → Implemented → Verified, with a required security impact analysis on every change and automatic approver stamping, so a change to a system inside your boundary is reviewed before it lands. Changes you make through the hub, such as evidence uploads, status changes, and monitor toggles, are logged for you automatically.

Acknowledgement Report

Track who has read what across the workforce that handles your CUI. Pick a policy and paste in a list of emails, and the hub creates a pending acknowledgement for each person, with one-click acknowledgement for the workforce and per-policy completion bars backed by a who-signed-when table. The result is ready-made evidence for the awareness & training family.

Environment Monitor

An opt-in, read-only view into your own Microsoft cloud, covering Intune device inventory and compliance, Entra users and MFA registration, audit and sign-in activity, Secure Score, and Conditional Access. Every section has a Save as evidence action that captures what you are looking at into the Evidence library, tagged to the controls it supports.

Client Onboarding

A six-step wizard covering company, contacts and roles, contracts and scope, environment, Microsoft 365, and documentation. The contracts and scope step is where the CUI obligation in your agreements gets written down. The Microsoft 365 step lets you apply Microsoft's documented responsibility for the controls your program inherits or shares with Microsoft 365, prefilled from Microsoft's own compliance documentation. What you enter becomes your organization profile, your policy tailoring tokens, and your hub branding, so you can upload your logo and it replaces the compli.ai wordmark on the hub for everyone.

Settings & access

Administration stays native to SharePoint. Authorization status, assessment type (self-assessment or third-party certification), key dates, and the conditional-window start all live in Settings. User management is plain SharePoint group membership, with Owners, Contributors, and Readers mapped to your existing Entra identities.

See the modules live.

Every screen above exists in our demo tenant — a two-quarter “well-run program” you can click through with us.