Track your compliance posture against a framework
Before you begin
Be clear about what this is. It's a self-assessment register — a structured place to record and defend your own position on each control. It is not an audit result, and the page says so above the numbers every time it loads. If you need an attestation, you still need an assessor; what this gives you is the evidence trail to hand them, and a defensible answer when a federal prime asks where you stand in the middle of a bid.
Decide which framework you're answering for first. The control sets overlap but the language and the obligations don't.
Steps
- Go to Admin & Settings → Governance → Compliance Posture.
- Choose your framework. There are five: FedRAMP Moderate, SOC 2, CMMC Level 1, CMMC Level 2, and CMMC Level 3. FedRAMP Moderate, SOC 2, CMMC Level 1 and CMMC Level 3 come to 423 seeded controls between them; CMMC Level 2 adds the 110 NIST SP 800-171 requirements, which are read from the same source the NIST control register uses rather than duplicated here.
- Work the control table. Each row is one control with its current position and any evidence already recorded against it.
- Click Record on a control you haven't answered yet, or Edit on one you're revising.
- Set the Position. If you choose implemented or not applicable, a narrative is required — the system won't let you assert a position without saying why. If you choose inherited, you have to name what it's inherited from.
- Fill in the responsible role, who reviewed it, and the date last reviewed. This is the part most registers skip and the part an assessor asks about first: a control with no named reviewer and no review date is an assertion, not a position.
- Save the position and move to the next control.
- Re-walk the register on a cycle. The review dates are what tell you which positions have gone stale.
What happens next
The register becomes the working document you bring to an assessment rather than something assembled the month before one. Because each position carries its own narrative, responsible role, and review date, a control that was answered eighteen months ago by someone who has since left is visible as exactly that.
Where the record lives
Positions, narratives, reviewers and review dates are kept under Admin & Settings → Governance → Compliance Posture, per control and per framework. The self-assessment disclaimer renders with them, so a screenshot of this page can't be mistaken for an audit finding by whoever it gets forwarded to.
Troubleshooting
You want to attach an evidence file to a control: evidence pointers are added through the API today, not through this form — the page states this where you'd expect the upload control to be. The table shows evidence already recorded against a control; it doesn't create it.
The control count doesn't match a number you were quoted: check which frameworks are in scope. 423 is the four directly-seeded frameworks. CMMC Level 2's 110 requirements are real and reachable but are counted in the NIST register they come from.
A position won't save: implemented and not-applicable both require a narrative, and inherited requires a source. These are enforced rather than encouraged, because an unexplained position is the one that fails under questioning.
Still stuck?
Send this straight to support (it goes directly to support@groundworkai.io).