CMMC LEVEL 2

Keep CMMC evidence connected to the CUI boundary.

See where CUI lives, what protects it, who can reach it, and which evidence supports each NIST SP 800-171 requirement.

CMMC 2.0 · NIST SP 800-171 · CUI boundary
Scope a CMMC working session

THE ASSESSMENT BOUNDARY

Define the boundary before measuring readiness.

A credible CMMC program ties its 110 security requirements to the systems, users, and data flows that handle CUI. ComplAI puts those relationships in one picture.

  1. 01

    Find and classify CUI across the repositories in scope.

  2. 02

    See assets, identities, vendors, and access paths that touch the boundary.

  3. 03

    Connect each requirement to implementation, evidence, and an owner.

  4. 04

    Keep SSP, POA&M, and assessment evidence current as the environment changes.

ONE ASSESSMENT RECORD

See data, assets, access, and evidence together.

Evidence and control status stay grounded in the environment the assessor will examine — not in a separate compliance folder.

DATA

Know where CUI lives

Classify it, see how it moves, and attach handling rules to real repositories.

ASSETS

Know what supports it

Keep an inventory of endpoints, workloads, services, and boundary components.

USERS

Know who can reach it

See identities, privileges, vendors, and review obligations in the in-scope environment.

ASSESSMENT WORKSPACE VIEWRELATIONSHIP VIEW · EXAMPLE RECORD

See whether the requirement, boundary, and evidence still agree.

reviewablesignal → context → owner
REVIEW STATEExample record
  • Source linked56%
  • Review due28%
  • Owner needed16%
Latest linked changeRepository scope confirmedTrace affected context
RELATIONSHIP SIGNALSFive checkpoints

Five checkpoints compare linked context with review attention. Hover, tap, or use the arrow keys to inspect each checkpoint.

84%linked context
+42 pts
HUMAN REVIEW PATHAccountability retained
  • Requirement ownerassigned
  • Evidence reviewerreview due
  • Remediation ownerowner needed
CHANGE TIMELINENeeds attention
  1. Repository scope confirmedBoundary linked
    EV
  2. Narrative change detectedReview due
    RO
  3. Remediation owner missingAction required
    ?

Illustrative values and event history · not a customer result, authorization decision, assessment result, or readiness score.

COMMON QUESTIONS

Asked before scoping.

Short answers that stay true whatever your boundary looks like.

Does ComplAI certify my company for CMMC?

No. It connects NIST SP 800-171 requirements to evidence, assets, and owners so your team can prepare. Assessors evaluate implementation.

What should we define before measuring readiness?

The assessment boundary: the systems, people, and data flows that store, process, or transmit CUI.

How does ComplAI use NIST SP 800-171?

Each in-scope requirement ties to its implementation, current evidence, and an owner, with SSP and POA&M context kept in the same record.

Is ComplAI itself CMMC certified?

ComplAI's internal environment holds a CMMC Level 2 certification. Product use does not by itself certify a customer environment.

NEXT DECISION

Start with the boundary you have today.

We’ll identify what is known, what is assumed, and what has to be verified before the plan hardens.

Scope a CMMC working session