compli.ai
Tenant-resident compliance for the defense industrial base

Compli.ai runs CMMC and NIST SP 800-171 compliance inside your own Microsoft 365 tenant.

Compli.ai is compliance software for defense contractors that hold Controlled Unclassified Information. Your CUI inventory, SSP, POA&M, SPRS score, and evidence live in a SharePoint site in your tenant, so the records that describe how you protect CUI never leave your Microsoft 365 boundary.

Who it is for

Compli.ai is built for defense contractors bound by DFARS 252.204-7012.

That clause requires you to implement the 110 requirements of NIST SP 800-171 wherever you hold CUI, and CMMC self-assessments require a current score and affirmation in SPRS. Compli.ai gives your compliance lead and IT team one place to scope the CUI you hold, assess all 320 objectives, track open POA&M items, and keep the score current.

The Department of War (DoW) suspended CMMC Phase II on July 13, 2026, and opened a 60-day review of the program. DFARS 252.204-7012 and Phase 1 self-assessments, with their affirmations in SPRS, remain in force, so that work continues.

The tenant-resident difference

Your compliance records stay inside your Microsoft 365 boundary.

A typical GRC service stores your SSP, POA&M, and evidence in the vendor's cloud, which adds a vendor to your assessment scope. Compli.ai keeps those records in SharePoint lists in your tenant, where your Microsoft 365 access controls, retention policies, and audit logging already apply.

No new vendor in your scope

The core system makes no external calls and keeps no vendor database, so there is no outside service to scope or to answer DFARS 252.204-7012 flow-down questions about.

The same features in every Microsoft cloud

Compli.ai runs with the same features in Commercial, GCC, GCC High, and DoD tenants, so it works in whichever Microsoft 365 cloud already holds your CUI.

Records you control directly

Your program history stays in your own SharePoint site under your retention rules, readable without going through a vendor's export feature.

Explore the platform

Each of these pages covers one part of Compli.ai in detail.

How it works

Compli.ai runs from a dedicated SharePoint site in your tenant. Upgrades update the app in place and never overwrite your statuses, notes, POA&Ms, or documents.

Read the product overview

The modules

Sixteen modules cover the program from CUI identification and the Controls Matrix through POA&M, evidence, internal audit, and supply chain.

Tour the modules

SPRS scoring and POA&M

Your SPRS score updates as you assess, from the −203 floor up to 110, and the POA&M rules in 32 CFR 170.21, including the 88-point conditional threshold, are enforced as you go.

How the score is calculated

Security and data residency

The core system keeps no vendor database and no stored credentials, and it uses your existing Microsoft 365 sign-in. The optional Environment Monitor stays off until your admin approves it.

Review the security model

Common questions

The FAQ covers the Phase II suspension, GCC High, SPRS math, POA&M rules, upgrades, and administration.

Read the FAQ

Practitioner guides

Our consultants write plain-English guides to the SSP, the POA&M, SPRS scoring, and the NIST SP 800-171 self-assessment.

Browse resources

Talk with our team about your CUI program.

In a 30-minute demo we will show Compli.ai running in a working tenant, answer your security team's questions, and scope a quote to your environment.