CMMC Phase 2 begins November 10, 2026

CMMC. RMF. FedRAMP.
One evidence engine.

ComplianceScout turns live evidence from your identity, cloud, and security stack into assessor-ready SSPs, POA&Ms, and OSCAL packages — with a tamper-evident ledger behind every control.

30-day free trial · No credit card required · Full access from day one

OSCAL
SSP import · package export
60+
evidence connectors
16+
frameworks, CMMC to SOC 2

Built for the package, not the checklist.

Checkbox platforms get you organized for an assessment. ComplianceScout produces the package your assessor and your Authorizing Official actually consume — and keeps it true afterward.

RMF & ATO Automation

Draft SSPs against NIST 800-53 Rev 5, CMMC L1/L2, or FedRAMP Low & Moderate baselines. Run pre-assessment dry runs that test your control claims against live evidence, generate SAP, SAR, and POA&M, and export the full package as OSCAL — then publish it to eMASS, CSAM, or RegScale over their documented APIs.

Tamper-Evident Evidence

Every piece of connector-collected evidence carries a SHA-256 payload hash, and every log-ingestion sync is sealed with a Merkle root. Verify chain integrity on demand and export evidence bundles for your assessor — not screenshots in a shared folder.

Continuous Monitoring

The Monitor step, automated: Separation of Duties detection, a real-time audit log of every user action, and AI anomaly reasoning keep your package current between assessments — with plain-English explanations and suggested remediations.

Start free. Scale on demand.

Every new account gets 30 days of full-platform access. When your trial ends, our team walks you through provisioning a production account.

Free Trial

30 days

Full access to every feature from day one. No credit card required.

CMMC L1 & L2, NIST 800-53 Rev 5, FedRAMP baselines
SSP drafting & POA&M generation
OSCAL export: SSP, SAP, SAR, POA&M
eMASS / CSAM / RegScale publishing
Tamper-evident evidence ledger
All 60+ connectors
SoD rules & AI anomaly detection
Start free trial →

Enterprise

Custom

Fully provisioned account with dedicated onboarding and SLA guarantees.

Everything in Trial, plus:
Dedicated onboarding engineer
Custom framework mappings & SoD rules
Unlimited identities & tenants
SSO / SCIM provisioning
Priority SLA & support
Custom data retention
Contact sales →

Evidence collects itself.

No agents. No code changes. Connect your identity providers, cloud, and security tools via OAuth or API key — controls start scoring against live evidence within minutes.

Okta
Azure AD / Entra ID
Google Workspace
AWS IAM
GitHub
GitLab
Microsoft Teams
Slack
CrowdStrike
SentinelOne
Rapid7
Qualys
Tenable
Splunk
Datadog
PagerDuty
HashiCorp Vault
AWS Secrets Manager
Azure Key Vault
Jamf Pro
ServiceNow
Salesforce
Workday
BambooHR
Jira
Confluence
Zoom
Snowflake

OAuth & API key auth

Connect with a single click via OAuth or paste an API key. No network changes, no firewall rules, no agents.

Event-driven detection

Sub-second ingestion on connectors with native event push, scheduled polling on the rest. Detectors fire as events arrive — not on a daily batch.

Push to Jira, Slack & Splunk

Route violations and alerts to the tools your team already uses. Configure routing rules per severity level.

Get started in under 10 minutes.

No professional services required. Follow these four steps and your controls will be scoring against live evidence before your next coffee break.

01

Create your account

Sign up for a free 30-day trial. Your tenant is provisioned instantly — no waiting for a sales call.

02

Connect an identity provider

Authorize ComplianceScout to read your Okta, Azure AD, or Google Workspace directory. Read-only access, no agents.

03

Pick your framework

Select CMMC Level 1 or 2, NIST 800-53 Rev 5, a FedRAMP baseline, or any of 16+ frameworks. Controls score automatically against the evidence your connectors are already collecting.

04

Generate the package

Draft the SSP, generate a POA&M for every gap, and export the package as OSCAL — ready for your assessor, or published straight to eMASS or CSAM via their documented APIs.

Frequently asked questions

When do I actually need CMMC?
The CMMC acquisition rule (48 CFR) took effect November 10, 2025, and contracting officers can already require Level 1 and 2 self-assessments. Phase 2 begins November 10, 2026, when third-party Level 2 certification can be required as a condition of award for contracts involving CUI. Your enforceable date is set by your solicitation or prime flow-down — most contractors should be assessment-ready before their next award cycle.
Do you support OSCAL?
Yes. Import OSCAL SSPs, export SSP, SAP, SAR, and POA&M as OSCAL JSON, and publish artifacts to eMASS, CSAM, or RegScale over their documented APIs. Machine-readable authorization packages are mandated for FedRAMP providers beginning September 30, 2026, and DoD assessors increasingly expect them.
Which compliance frameworks do you support?
CMMC Level 1 & 2, NIST SP 800-53 Rev 5, NIST 800-37 RMF, FedRAMP Low & Moderate baselines, DFARS 252.204-7012, SOC 2 Type II, ISO 27001, HIPAA, GDPR, PCI DSS, DORA, CIS Controls, and more. Custom framework mappings available on Enterprise.
Do you store CUI or my user data?
ComplianceScout reads identity, configuration, and log evidence from your connected systems to score controls — not your contract documents or CUI files. We never store passwords or sensitive personal data beyond what's needed for detection.
What happens when the trial ends?
Access is locked when the 30-day trial ends. Your data is retained for 30 more days — purchase a plan in that window and your account is restored exactly as you left it. After the grace period, all account data is permanently deleted (we send a warning email first).
Is the platform itself certified?
SOC 2 Type II audit is in progress; the platform is not yet FedRAMP authorized. We operate on enterprise infrastructure with encryption at rest and in transit, RBAC, MFA enforcement, and a tamper-evident evidence ledger.