Release 3.34.0

Validated Compliance Status and Control-Level Evidence

Task completion and audit-ready compliance aren't always the same thing, and being able to show both clearly matters when clients face an audit. Validated Compliance Status gives each one its own place in Cynomi, tracking formal control validation separately from task-driven progress so you can present a client's compliance posture with more precision.

TPRM Revenue Intel Compliance

What’s in This Release

  • Validated Compliance Status on every control, tracked alongside task-driven progress
  • A Notes field and file attachments at the control level
  • An expanded CMMC Level 2 System Security Plan report
  • A restructured third-party vendor risk report you can share as it is

Validated Compliance Status, Separate from Task Progress

Cynomi now distinguishes Potential Score, which is driven by task execution, from Validated Score, which reflects formal sign-off. Both are tracked on every framework, and you set a Validated Status directly on each control. The result surfaces in the control view, on the Compliance dashboard, and in the Compliance report, so execution and sign-off stay visible together rather than in two different exports.

This applies across every framework in Cynomi, including CMMC, SOC 2, ISO 27001, and HIPAA. A control can be fully implemented in practice and still unvalidated, or validated and awaiting the last of its supporting work, and both states now have somewhere to live.

This gives you the appropriate compliance view for different operational, auditor, and executive conversations.

Why this matters

The two scores serve different purposes in audit preparation and compliance conversations. Potential Score helps communicate task-driven operational progress, while Validated Score provides a view based on confirmed control implementation for auditor and executive conversations.

Control-Level Notes and Evidence Attachments

Some evidence belongs to a task, and some belongs to the control itself. A policy document, a screenshot, a configuration record. Each control now carries a free-text Notes field and direct file attachments, so you can record how a control is met and attach what proves it in the same place, alongside the task roll-up you already had.

The distinction is clear. The task plan still reflects Potential Score, while notes, evidence, and Validated Status carry what a formal audit or an internal review needs. Everything an assessment asks for sits on the control it belongs to.

Richer CMMC Level 2 System Security Plan Reports

Assessors increasingly expect a System Security Plan to explain each control rather than list its identifier. The SSP Control Implementation report has been expanded to carry each control’s short description, example evidence, its Validated Status, and additional supporting information, which makes the export closer to a finished document and further from a starting point.

The CMMC Level 2 Controls table has also been refined, with renamed columns that make the framework easier to navigate and the right data quicker to find. For partners running Department of Defense supply chain work, the practical effect is that more of the SSP comes out of the platform and less of it gets written afterwards.

Sharper Third-Party Vendor Risk Reports

The vendor risk report in third-party risk management has been restructured into a more focused snapshot of each vendor’s posture, with dedicated Impact Assessment and Security Assessment pages that surface the key concerns from the assessment alongside the overall risk summary. It now carries enough context to stand on its own, so you can send it to the vendor or to the client to agree on gaps and resolution paths without writing a separate summary for each.

Client users can now also view security assessment summaries for shared, linked-MSP vendors. That gives a client visibility into vendor posture without a Service Provider having to pull the report for them every time.

Also in This Release

  • The Service Provider account-level Solutions section is now called Revenue Intel, which better reflects how partners use it. The capability lives on the Revenue Insights page on cynomi.com
  • Solutions can be grouped into reusable Bundles, with multiple bundles per solution, and bundle labels appear beside related tasks in the task table and in CSV exports
  • Estimated Effort is available as a configurable column in the task table, for planning and prioritizing remediation work from the table itself
  • Framework content has been refreshed, keeping control wording and references aligned with the latest published guidance across the framework library

What This Changes for Audit Work

Audit readiness has always demanded more than a task list, and partners have filled the gap with spreadsheets, side documents, and a lot of recall. Validating controls independently, documenting how each one is met, attaching the evidence beside it, and exporting an SSP that already reads like a deliverable moves that work into the platform where the rest of the program lives. Across a book of regulated clients, that is fewer parallel systems to keep true, and one more way Cynomi connects security work to compliance outcomes.

Frequently Asked Questions

What is the difference between Potential Score and Validated Score?

Potential Score is driven by task execution and reflects operational work completed. Validated Score is based on confirmed control implementation, using the Validated Status you set on each control. Both are tracked on every framework and shown side by side.

Which frameworks does Validated Compliance Status apply to?

Every framework in Cynomi, including CMMC, SOC 2, ISO 27001, and HIPAA.

Where do I record how a control is met?

On the control itself. Each control now has a free-text Notes field and supports direct file attachments, so policies, screenshots, and configuration records sit with the control rather than rolling up only from linked tasks.

What changed in the CMMC Level 2 SSP report?

The SSP Control Implementation report now includes each control's short description, example evidence, Validated Status, and additional supporting information. The CMMC Level 2 Controls table has renamed columns for easier navigation.

What happened to the Solutions section?

At the Service Provider account level it is now called Revenue Intel. Solutions can also be grouped into reusable Bundles, and bundle labels appear beside related tasks in the task table and in CSV exports.

Which Cynomi release do these changes ship in?

Release 3.34.0, May 2026. It covers compliance validation, control-level documentation, CMMC reporting, third-party vendor risk reporting, Revenue Intel, and task management.

The Security Growth Platform
for Service Providers

Discover how Cynomi can help you standardize delivery, accelerate onboarding, and scale your CISO advisory services.