Compliance Center
The Compliance Center groups the platform’s compliance tooling: framework self-assessments, control tracking, evidence management, and regulatory checking.
What’s inside
Section titled “What’s inside”- CMMC self-assessment tooling and control-state tracking.
- SPRS scoring using the DoD methodology.
- FedRAMP documentation and OSCAL export.
- FAR/DFARS real-time clause checking against a real clause catalog.
- POA&M, evidence management, and continuous monitoring for keeping a program current.
What this is not
Section titled “What this is not”The tools here support your company’s compliance program. GovConHouse’s own security posture, subprocessor list, and trust documentation live at compliance.govconhouse.com. For the full division of responsibility, see Shared Responsibility.
Tool summary
Section titled “Tool summary”- CMMC: self-assessment tooling and control-state tracking.
- SPRS: scoring using the DoD methodology.
- FedRAMP: documentation and OSCAL export.
- FAR/DFARS: clause checking against a real clause catalog.
- GRC: program-level governance, risk, and compliance tracking.
- NIST Controls: the NIST SP 800-53 control catalog with per-control status.
- CUI Scanner: document scanning for Controlled Unclassified Information.
- Denied Parties: screening against denied-party and sanctions lists.
- POA&M: plan of action and milestones tracking.
- Evidence Management: assessment artifacts mapped to the controls they support.
- Continuous Monitoring: ongoing control monitoring between assessments.
- Compliance Scorecard: one posture number per framework.
- Third-Party Risk: vendor and partner risk tracking.
- Compliance Policies: versioned policies mapped to controls.
Related
Section titled “Related”Try this in the platform