What’s in This Release
- Validated Compliance Status on every control, tracked alongside task-driven progress
- A Notes field and file attachments at the control level
- An expanded CMMC Level 2 System Security Plan report
- A restructured third-party vendor risk report you can share as it is
Validated Compliance Status, Separate from Task Progress
Cynomi now distinguishes Potential Score, which is driven by task execution, from Validated Score, which reflects formal sign-off. Both are tracked on every framework, and you set a Validated Status directly on each control. The result surfaces in the control view, on the Compliance dashboard, and in the Compliance report, so execution and sign-off stay visible together rather than in two different exports.
This applies across every framework in Cynomi, including CMMC, SOC 2, ISO 27001, and HIPAA. A control can be fully implemented in practice and still unvalidated, or validated and awaiting the last of its supporting work, and both states now have somewhere to live.
This gives you the appropriate compliance view for different operational, auditor, and executive conversations.
Why this matters
The two scores serve different purposes in audit preparation and compliance conversations. Potential Score helps communicate task-driven operational progress, while Validated Score provides a view based on confirmed control implementation for auditor and executive conversations.
Control-Level Notes and Evidence Attachments
Some evidence belongs to a task, and some belongs to the control itself. A policy document, a screenshot, a configuration record. Each control now carries a free-text Notes field and direct file attachments, so you can record how a control is met and attach what proves it in the same place, alongside the task roll-up you already had.
The distinction is clear. The task plan still reflects Potential Score, while notes, evidence, and Validated Status carry what a formal audit or an internal review needs. Everything an assessment asks for sits on the control it belongs to.
Richer CMMC Level 2 System Security Plan Reports
Assessors increasingly expect a System Security Plan to explain each control rather than list its identifier. The SSP Control Implementation report has been expanded to carry each control’s short description, example evidence, its Validated Status, and additional supporting information, which makes the export closer to a finished document and further from a starting point.
The CMMC Level 2 Controls table has also been refined, with renamed columns that make the framework easier to navigate and the right data quicker to find. For partners running Department of Defense supply chain work, the practical effect is that more of the SSP comes out of the platform and less of it gets written afterwards.
Sharper Third-Party Vendor Risk Reports
The vendor risk report in third-party risk management has been restructured into a more focused snapshot of each vendor’s posture, with dedicated Impact Assessment and Security Assessment pages that surface the key concerns from the assessment alongside the overall risk summary. It now carries enough context to stand on its own, so you can send it to the vendor or to the client to agree on gaps and resolution paths without writing a separate summary for each.
Client users can now also view security assessment summaries for shared, linked-MSP vendors. That gives a client visibility into vendor posture without a Service Provider having to pull the report for them every time.
Also in This Release
- The Service Provider account-level Solutions section is now called Revenue Intel, which better reflects how partners use it. The capability lives on the Revenue Insights page on cynomi.com
- Solutions can be grouped into reusable Bundles, with multiple bundles per solution, and bundle labels appear beside related tasks in the task table and in CSV exports
- Estimated Effort is available as a configurable column in the task table, for planning and prioritizing remediation work from the table itself
- Framework content has been refreshed, keeping control wording and references aligned with the latest published guidance across the framework library
What This Changes for Audit Work
Audit readiness has always demanded more than a task list, and partners have filled the gap with spreadsheets, side documents, and a lot of recall. Validating controls independently, documenting how each one is met, attaching the evidence beside it, and exporting an SSP that already reads like a deliverable moves that work into the platform where the rest of the program lives. Across a book of regulated clients, that is fewer parallel systems to keep true, and one more way Cynomi connects security work to compliance outcomes.