Common Cyber

Managed Compliance Operations

Compliance decays quietly. Someone changes a system, the person who owned a control leaves, the evidence goes stale, and nobody notices until an assessor asks.

Why is compliance an annual obligation?

Under the CMMC program as currently written, Level 1 self-assessments and affirmations recur annually. Level 2 self-assessment requires a new assessment every three years, with an affirmation in SPRS every year in between.

Between those points the environment changes. Systems are replaced, the person who owned a control leaves, evidence goes stale. The assessment has to be true on the day it is made, not on the day the project ended.

Managed Compliance Operations keeps controls, evidence, and ownership operating between assessments, so the next assessment and affirmation are supported by evidence that is current rather than reconstructed.

Level 2 self-assessment status

Why does compliance degrade?

Systems change. People move. Evidence ages. Recurring work gets deprioritized. Six months after a project ends, the posture that was built starts coming apart.

What activities are sustained?

We keep the program alive between assessments — monitoring, evidence collection, control review, vulnerability and patch oversight, issue tracking, change review, and reporting.

Can you transition from another provider?

Yes. Organizations can enter managed compliance after implementing internally, with us, or with someone else. We start from what is in place, not from what was planned.

What outcomes does the service support?

Visible ownership, current evidence, a clear view of open risk, and a posture that holds up when someone checks.

What remains your responsibility?

You retain legal, executive, and contractual accountability for your compliance posture.

Common Cyber provides operating support and evidence discipline but does not assume your authority, representations, or obligations. Any Microsoft environment supporting CUI remains subject to technical and contractual determination, including whether GCC, GCC High, or another authorized offering is required.

Frequently asked questions

Is managed compliance the same as managed IT?

No. Common Cyber sustains compliance controls, evidence, and oversight; it is not positioned as a general IT provider.

Does Common Cyber assume accountability for compliance?

No. The customer retains legal, executive, and contractual accountability for its compliance posture.

Are service tiers available?

Service levels are defined in general terms around the validated boundary, required recurring activities, and reporting needs. No standard price is published.

How often does a CMMC self-assessment have to be repeated?

Level 1 self-assessments and affirmations recur annually. Level 2 self-assessment requires a new assessment every three years, with an annual affirmation in between. These are set by the CMMC program and by your contract, not by Common Cyber.

Does managed compliance keep us ready for the next self-assessment?

It is designed to. The service keeps controls operating, evidence current, and ownership assigned between assessments. Your organization performs the self-assessment and your Affirming Official submits the affirmation.

Discuss Ongoing Compliance Operations