ComplyUp
Zero-trust SaaS for NIST 800-171 and CMMC self-assessments, SSP and POA&M authoring, and SPRS scoring; acquired by Exostar.
What this provider does
ComplyUp is a compliance assessment platform built for DoD contractors and the MSPs / RPOs who serve them. The homepage walks through the NIST 800-171 lifecycle: assess against the 110 requirements, produce an SSP and POA&Ms, generate a SPRS score per the DoD NIST 800-171 assessment methodology, remediate, and monitor. ComplyUp is multi-tenant for service providers, encrypts assessment data client-side (their 'zero trust' design), and was acquired by Exostar, where it is now positioned inside Exostar's CMMC Ready Suite.
What this provider is commonly used for
Self-assessment software for the 110 NIST SP 800-171 requirements with built-in gap analysis (readiness assessment).
[01]Automated SSP and POA&M authoring tied to the assessment results.
[01]SPRS score generation using the DoD NIST SP 800-171 DoD Assessment Methodology so contractors can submit their scores.
[01]Multi-tenant workspaces for MSPs and RPOs to run client engagements with isolated tenants.
[01]
Services the vendor claims
Gaps in this record
Facts that could not be confirmed against a public source on the retrieval date. If you can point to an authoritative source for any of these, we'll update the record.
- ·ComplyUp is software, not a C3PAO; it does not produce certified CMMC assessment results.
- ·Per their banner, ComplyUp has been acquired by Exostar and integrated into Exostar's CMMC Ready Suite; future ownership of the product roadmap sits with Exostar.
- ·Pricing is not published on the page we sourced.