FAQ
Frequently asked questions
Straight answers about what CyberComply does, which frameworks it supports, and what software can and cannot do for a compliance program.
Product
Product
What is CyberComply?
CyberComply is a governance, risk, and compliance software platform. It gives an organization one environment for compliance frameworks, requirements, controls, assessments, evidence, policies, risks, remediation, documentation, and reporting. It is a product of Armada Cyber Defense LLC.
Is CyberComply only for CMMC?
No. CyberComply is a multi-framework GRC platform. It has particularly strong capabilities for organizations in the U.S. federal and Defense Industrial Base ecosystem, but the same environment supports other frameworks including NIST SP 800-171, NIST CSF, NIST SP 800-53, ISO 27001, SOC 2, HIPAA, and PCI DSS.
Assessment & Certification
Assessment & Certification
Does CyberComply certify my organization?
No. CyberComply is software that supports readiness and compliance management. It does not issue certifications, and using it does not by itself guarantee regulatory compliance, certification, authorization, or a successful assessment.
Does CyberComply replace a C3PAO?
No. Formal CMMC assessment and certification are performed by authorized third-party assessment organizations. That is a separate activity from the software-supported readiness and compliance management CyberComply provides.
Can CyberComply help prepare for CMMC assessments?
Yes, as preparation. CyberComply organizes scope, requirements, assessment objectives, evidence, findings, remediation, and documentation so the program is ready for review. The assessment itself is conducted separately by an authorized assessment organization.
Frameworks
Frameworks
Can CyberComply support multiple frameworks?
Yes. Organizations can manage several frameworks in the same environment. CyberComply helps identify related requirements and reuse applicable evidence, while each framework retains its own status and accountability. Satisfying a requirement in one framework does not make an organization compliant with another.
Can evidence be associated with multiple requirements?
Yes. Where the same artifact validly supports more than one requirement, it can be associated with each of them rather than duplicated. The association is a decision your team makes and records.
Multi-tenant
Multi-tenant
Can consultants use CyberComply with multiple clients?
Yes. Consultants can work across separate client environments with role-based access, which supports centralized oversight without mixing client data.
Can MSPs and MSSPs use CyberComply?
Yes. Service providers can manage compliance programs across multiple customer environments, with separation between customers and a view across the portfolio for the roles that need it.
CyberGap
CyberGap
What is CyberGap?
CyberGap is a free assessment and gap-analysis entry point for organizations that want to evaluate their current compliance posture before moving into the full CyberComply GRC environment.
What is the difference between CyberGap and CyberComply?
CyberGap covers the assessment and gap-identification part of the journey. CyberComply is the broader GRC environment where remediation, documentation, evidence, risk, and ongoing maintenance are managed after the gaps are known.
Documentation
Documentation
Does CyberComply support SSPs and POA&Ms?
CyberComply helps organize the information needed to develop and maintain a System Security Plan, and tracks deficiencies through a structured Plan of Action & Milestones with corrective actions, owners, target dates, and evidence of closure.
Getting started
Getting started
How do I request a demonstration?
Use the demo request form. Tell us about your organization, your primary framework, and your timeline, and the Armada team will follow up to arrange a demonstration.
CyberComply is a software platform that assists organizations in managing governance, risk, compliance, documentation, and readiness activities. Using CyberComply does not by itself guarantee regulatory compliance, certification, authorization, or a successful assessment.
Ready to bring your compliance program together?
See how CyberComply can help centralize requirements, evidence, risks, remediation, documentation, and assessment readiness.
