The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

ScalePad ControlMap for CMMC: Pricing, Fit, and Where CUI Must Stay Out

By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance · Last verified September 2026

ControlMap is ScalePad's compliance software for managed service providers (MSPs). Its CMMC tools cover Levels 1 and 2 — assessment, SPRS score, security plan, POA&Ms, and evidence export — and come only on the Pro plan, listed at $299 per client per month. It can't certify you, skips Level 3, and ScalePad says keep CUI out, even in GovCloud.

If you searched for a ControlMap CMMC review, start here: nobody has published an independent hands-on test, and we didn't run one either. What we did was check ScalePad's Cybersecurity Maturity Model Certification (CMMC) claims against the rule, its current prices, and its own help pages. The feature list holds few surprises. Two things do: where ControlMap lands in your assessment scope even with no CUI in it, and a "FedRAMP Moderate Equivalency" badge that ScalePad's own help center quietly undercuts.

A few terms, once:

  • CUI is controlled unclassified information: sensitive government information your contract makes you protect.
  • SPRS is the Supplier Performance Risk System, where your self-assessment score goes.
  • An SSP is your system security plan.
  • A POA&M is a plan of action and milestones: a dated list of fixes.
  • GRC stands for governance, risk, and compliance software.

CMMC status, checked September 24, 2026. The Department of War — the name official sites now use alongside Department of Defense (DoD) — suspended CMMC Phase II on July 13, 2026. Phase II had been set to begin November 10, 2026. Phase I self-assessment requirements remain, and during the suspension new solicitations may require only Level 1 (Self) or Level 2 (Self), per the Department's implementing procedures. No replacement date has been announced. For a GRC buyer, that makes the self-assessment and SPRS workflow the part that matters right now. See what changed and what still binds you.

This page is for you if you're an MSP or virtual chief information security officer (vCISO) deciding whether to run defense clients' CMMC work in ControlMap. It's also for you if you're a defense contractor whose MSP just said they'll run yours in it.

It's not the right page if:

  • You need a place to store CUI. Start with secure enclaves or GCC High.
  • You're comparing GRC tools in general. See CMMC GRC software.
  • You're an MSP asking what CMMC requires of your own business. See CMMC requirements for MSPs.

Three quick checks before you go further:

  1. Does your contract or your prime's flow-down include Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, or do you receive files marked CUI? If neither, you may only handle Federal Contract Information (FCI). See FCI vs. CUI.
  2. Does the paperwork name a CMMC level and assessment type? Look for DFARS 252.204-7021 or 252.204-7025.
  3. Will your MSP run the program in its ControlMap account, or will your own staff?

Keep those answers handy. They decide most of what follows.

ControlMap for CMMC at a glance

ControlMap is a cloud compliance platform that ScalePad sells to MSPs and prices per client. For CMMC it covers Levels 1 and 2, but the CMMC-specific tools come only on the Pro plan. It holds your program's paperwork, status, and links to evidence — not your CUI.

Question Short answer Where this comes from — —
Question Short answer Where this comes from
What is it?Cloud GRC software for MSPs to run compliance programs across many clients, one "tenant" per clientScalePad pricing page, company-stated
Who owns it?ScalePad, which bought ControlMap on March 6, 2023ScalePad announcement
CMMC levelsLevels 1 and 2. Not Level 3.ControlMap help center, updated Sept. 11, 2026
CMMC toolsObjective-level assessment mapped to NIST SP 800-171A, SPRS calculator, SSP builder, POA&M tracking, shared responsibility matrix, evidence export by objective, CUI tagsSame, company-stated
Plan you needPro, listed at $299 per client per month. Essentials ($99) doesn't include the CMMC-specific SSP and SPRS tools.Pricing page, checked Sept. 24, 2026
HostingAmazon Web Services (AWS) in the U.S., Canada, EU, or Australia, or a separate AWS GovCloud region with different pricingSupported regions, company-stated
Can CUI go in it?No. ScalePad says not to upload CUI or other sensitive assessment data in any region.Help center
FedRAMPScalePad doesn't claim FedRAMP authorization (FedRAMP now calls it "certification") for ControlMap. It announced an equivalency effort in April 2025 and hasn't announced completion.ScalePad pages we read
Security auditsSOC 2 Type II (report under a nondisclosure agreement), a public SOC 3 report, and an ISO 27001 certificate, covering ScalePadScalePad security page, company-stated
Does it certify you?No software does. ScalePad's own FAQ says so too.32 CFR Part 170; ScalePad CMMC page
Best fitMSPs running Level 1 or Level 2 programs for several defense clients, with CUI kept in an approved environmentOur judgment from the facts above
Not the first buy ifYou don't know where your CUI lives, you need somewhere to store CUI, you need Level 3, or your controls aren't built yetOur judgment from the facts above

ControlMap may be the right documentation tool without being the thing you need first. The right CMMC path depends on your required level, whether you handle FCI or CUI, your assessment type, where your CUI lives, and your contract timeline. The contract clause sets your level, not a checklist. A general product profile can't settle those for you. So use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right kind of help before you request quotes. That help might be GRC software run by your MSP, readiness help from a Registered Practitioner Organization (RPO), a CUI enclave, or a Managed Security Service Provider (MSSP). And do not submit CUI, drawings, or sensitive contract details.

ScalePad's CMMC claims, checked against the record

ControlMap's help center is careful and mostly accurate. Some of ScalePad's marketing isn't. Three claims need a closer look:

  • A FedRAMP "equivalency" badge that rests on mapped controls, not a finished assessment.
  • "From scope to certified" language.
  • A new auto-answer feature that can look like evidence when it isn't.

Here is each claim next to the rule behind it.

What ScalePad says What the rule or record shows Our read Ask for this — — —
What ScalePad says What the rule or record shows Our read Ask for this
A "FedRAMP Moderate Equivalency" badge: ScalePad's SOC 2 and ISO 27001 controls have been "mapped" to a FedRAMP Moderate equivalency assessment (CMMC for MSPs page). An April 2025 post is titled FedRAMP Authorization Coming to ControlMap, though its text describes equivalency.A cloud service that holds covered defense information must meet security requirements equivalent to the FedRAMP Moderate baseline, plus the clause's incident duties (DFARS 252.204-7012(b)(2)(ii)(D)). DoD's December 21, 2023 memo expects a FedRAMP-recognized third-party assessment organization (3PAO) and a body of evidence.Mapping controls to an assessment isn't passing one. No assessor is named, and no completion is announced. And ScalePad's help center still says keep CUI out — the only situation where equivalency matters.The written status of the effort: finished or not, which 3PAO, and whether you can review the body of evidence. Until then, run ControlMap CUI-free.
GovCloud hosting, which ScalePad recommends "when necessary" for CMMC or FedRAMP workA hosting region isn't the app's authorization. ScalePad's current help center says a region alone doesn't make a workload FedRAMP authorized, CMMC compliant, or fit for CUI.The current help text is right. Older ScalePad copy — still visible in search snippets — said commercial AWS "is FedRAMP Moderate" and GovCloud "FedRAMP High."In writing: what a GovCloud tenant changes and what it costs
"The engagement motion, from scope to certified" and "Audit-done is a promise" (overview)CMMC status comes from a self-assessment and affirmation, a CMMC Third-Party Assessment Organization (C3PAO), or a DCMA DIBCAC assessment (32 CFR Part 170). ScalePad's own CMMC FAQ says ControlMap doesn't certify clients.Marketing overstates. The FAQ and help center are accurate.References from clients who reached a Final Level 2 status while using it
ControlMap "aligns directly with DoD/DoW expectations and assessor requirements," trusted by "hundreds of MSPs supporting thousands of clients"No public data backs the count or the alignmentCompany-stated; can't be checkedA sample export your intended assessor reviews (see the test sheet below)
SPRS score calculatorThe CMMC rule subtracts 5, 3, or 1 point per unmet requirement, with partial credit only for multifactor authentication and non-FIPS encryption (32 CFR 170.24).Useful math, only as true as the answers behind itRun our worked example below and check the result
POA&M management "where permitted"32 CFR 170.21 limits which gaps can go on a POA&M. ScalePad says customers stay responsible for deciding eligibility.It tracks POA&Ms. We couldn't confirm that it blocks ineligible items.A demo that tries to put an ineligible item on a POA&M
"Tech Stacks" auto-answer CMMC objectives from your product list (Sept. 1, 2026 release)A requirement is MET only when every objective is satisfied "based on evidence," in final form, not draft (32 CFR 170.24(b)(1)). Owning a product isn't evidence it's set up right.A drafting time-saver. A risk if anyone treats an auto-answer as MET. ScalePad says auto-answers are labeled and reversible.Can you filter auto-answers and require evidence before MET?
Reports "export in DIBCAC and eMASS formats"A file format isn't an assessment result. Assessors judge the evidence behind each objective.Company-statedA sanitized sample export reviewed by your intended assessor
"You can use your own auditor," and ScalePad "can connect you with auditor partners" (pricing FAQ)Only an authorized C3PAO performs a Level 2 certification assessment, and C3PAOs must follow the Cyber AB's conflict-of-interest rules (32 CFR 170.9(b)(2)).For CMMC, an "auditor partner" must be a C3PAO listed on the Cyber AB Marketplace and independent of whoever prepared youIs the partner a C3PAO? Is there a referral fee?
"40+" integrations on the pricing page, "83+ evidence automation integrations" on the overview page—The two counts don't match. What matters is whether it connects to your systems in your region.A written, region-specific integration list
Copilot AI (beta, Pro plan) uses only data in that client's environment, not shared across clients (April 2026 update)Your evidence is security data, so it matters which AI service sees itCompany-stated. The AI provider and processing location aren't published.The AI provider, where data is processed, and how to switch Copilot off

What the software does, and what people still do

ControlMap organizes the work. It holds requirements, answers, owners, dates, policies, and links to evidence, and it turns them into an SSP, a score, and a POA&M. People still do the rest:

  • Set up the controls.
  • Answer honestly.
  • Fix the gaps.
  • Keep evidence current.

A senior official at the contractor still signs the affirmation. If you're weighing software against outside help, see CMMC software vs. a CMMC consultant.

Can you put CUI in ControlMap — and where does it land in your CMMC scope?

No CUI goes in ControlMap. ScalePad's help center says not to upload CUI or other sensitive assessment data in any hosting region, GovCloud included. But a CUI-free ControlMap still almost certainly lands inside your assessment scope. The CMMC rule puts any outside cloud service that holds Security Protection Data in scope as a Security Protection Asset. That data includes configuration evidence, gap lists, and security-plan detail.

Here's how the rule works. 32 CFR 170.19(c)(2), Table 4 sorts every outside provider — an External Service Provider (ESP) — by two questions:

  1. Is it a cloud service?
  2. Does it hold CUI, Security Protection Data (SPD), or neither?

The definition of SPD includes "data related to the configuration or vulnerability status of in-scope assets" and passwords to the in-scope environment.

If ControlMap holds… What the rule says What you do — —
If ControlMap holds… What the rule says What you do
CUI — say, a marked drawing uploaded as evidenceA cloud provider holding CUI must meet the FedRAMP requirements in DFARS 252.204-7012Don't. ScalePad names no FedRAMP authorization and no completed third-party equivalency assessment, and it tells you to keep CUI out. Keep it in your enclave and link to it.
Security Protection Data but no CUI — configuration evidence, POA&M gap details, an SSP describing how systems are set upThe cloud service is in your assessment scope and is assessed as a Security Protection Asset, only against the Level 2 requirements relevant to what it does (Table 3)List ControlMap in your asset inventory, SSP, and network diagram. Get ScalePad's service description and customer responsibility matrix (CRM). Expect questions about who can sign in, multifactor authentication, account removal, and logs.
Neither — only generic policies and training materialIt doesn't meet the CMMC definition of an ESPLow exposure
And your MSP runs it for youAn MSP that isn't a cloud provider but holds SPD is also in your scope as a Security Protection AssetDocument the MSP in your SSP and get the MSP's own CRM (170.19(c)(2)(ii))

That second row is our reading of the rule text. The rule doesn't name GRC tools, and your assessor makes the final call. ScalePad reads it the same way. Its CMMC FAQ for MSPs says a tool that handles only Security Protection Data doesn't need FedRAMP but is assessed as a Security Protection Asset inside the client's scope.

Think of ControlMap as the binder of inspection reports for the vault, not the vault. The binder never holds the gold. But it does hold the lock notes and the list of weak spots, so the rule asks you to lock the binder too.

A hypothetical to make it concrete. Say you run a small MSP with five defense clients. You connect ControlMap to each client's Microsoft 365 tenant and endpoint tool, and you write their SSPs in it. Nothing in it is CUI. Under Table 4, ControlMap and your MSP both still appear in each client's assessment scope as Security Protection Assets. That means:

  • Five SSPs that each name ControlMap and your MSP.
  • ScalePad's responsibility matrix plus your own.
  • Sign-in and logging evidence for each tenant, ready for an assessor.

Here's how to sort what goes in and what stays out:

Item Put it in ControlMap? Why — —
Item Put it in ControlMap? Why
Policies and procedures with no system detailsYesNeither CUI nor SPD
SSP narrative that describes how systems are configuredYes, if it holds no CUI — and treat it as SPDConfiguration detail is SPD
Asset inventory with CUI tags (names and tags only)YesLabels, not the CUI itself
Automatically collected configuration evidenceYes, if you accept the Security Protection Asset treatmentSPD
POA&M items and gap notesYes, as SPD. Limit who can see them.Vulnerability status is SPD
Screenshots of CUI folders, file lists, or email subjectsNo. Crop, sanitize, or link.They can reveal CUI
CUI-marked drawings, specs, or contract documentsNever. Link to your enclave.CUI
Export-controlled technical data (ITAR or EAR)NeverCUI, plus export rules. See CMMC for ITAR companies.
Passwords or keys to in-scope systemsNever, as evidenceSPD by definition, and bad practice

One wrinkle. ScalePad's instruction covers "CUI or other sensitive assessment data," but it doesn't define the second part — and the product is built to hold SSPs and POA&Ms. Ask ScalePad in writing what "sensitive assessment data" means, then write your own rule for what your team may upload.

ControlMap Scope Checker

This checker runs in your browser and stores nothing. Don't enter CUI, drawings, contract numbers, or system details.

CUI-marked files or excerpts uploaded as evidence (drawings, specs, contract documents)
Screenshots or exports that could show CUI (folder lists, file names, email subjects)
Automated evidence pulled from in-scope systems (Microsoft 365 / GCC High, Entra ID, endpoint tools, AWS)
Configuration screenshots or baselines of in-scope systems
POA&M items, gap notes, or scan findings
Passwords, API keys, or other credentials to in-scope systems
Policies or procedures with no system-specific details
SSP narrative describing how in-scope systems are set up
Hosting region
Who runs ControlMap?

No free-text fields.

What GovCloud changes — and what it doesn't

A GovCloud tenant changes where your data sits, what you pay, and which integrations work. It doesn't change the "no CUI" instruction, and it doesn't make ControlMap itself FedRAMP authorized. ScalePad's help center says both.

In a GovCloud tenant What ScalePad documents —
In a GovCloud tenant What ScalePad documents
Price"Pricing differs for this region". The difference isn't published.
SetupThe region is chosen when the account is created. Serving clients in two regions takes a second MSP account and login.
ScalePad's PSA and RMM integrationNot available to GovCloud partners (help article). PSA (professional services automation) and RMM (remote monitoring and management) are the tools MSPs use for tickets and device management.
Lifecycle ManagerConnects through a separate API-key integration that runs three weekly checks — warranty, asset inventory, and antivirus (help article, updated Sept. 3, 2026)
Other integrationsNot listed by region. Verify each one you need.
CUIStill not allowed

If that table showed you the real question is where CUI lives — not which dashboard to buy — settle that first. It changes what you should buy, and in what order.

See whether you need software, an enclave, or both →

What does ControlMap cost for CMMC?

ScalePad publishes its list prices, which many directory listings still get wrong. The CMMC-specific tools come only on Pro, at $299 per client per month. That's $3,588 a year per defense client before any MSP service fee. Software is usually the small line in a CMMC budget.

Plan List price (checked Sept. 24, 2026) What it means for CMMC — —
Plan List price (checked Sept. 24, 2026) What it means for CMMC
Free$0 per clientNo CMMC tools. Capped at 10 policies, 10 risks, and 10 evidence items per client.
Essentials$99 per client per month, 3-client minimumOne framework per client. The CMMC-specific SSP and SPRS tools aren't included. Ask whether the CMMC framework itself is available here.
Pro$299 per client per monthCMMC and NIST tools, SSP and SPRS reports, audit support, multi-framework crosswalks, client portal, Copilot

Here's the list-price math. It's our arithmetic, not a quote.

Defense clients on Pro Per month Per year — —
Defense clients on Pro Per month Per year
1$299$3,588
3$897$10,764
5$1,495$17,940
10$2,990$35,880

The five-client MSP from the hypothetical above would pay $1,495 a month at list for the software alone.

What the public price doesn't tell you:

  • GovCloud premium. Pricing differs for that region, and the difference isn't published.
  • Minimums and terms. ScalePad states a 3-client minimum for Essentials and says packages start with one tenant. It doesn't state a Pro minimum, so don't assume one.
  • Contract details. Billing term, renewal increases, and cancellation terms aren't on the page.
  • Onboarding and services. Neither is priced publicly.
  • Your MSP's fee. A contractor pays the MSP, not ScalePad. The MSP's service fee is set by the MSP. See what managed CMMC compliance costs.

Keep the buckets separate so nothing gets counted twice: software, MSP or vCISO labor, your own staff time, fixes and new tools, and any required assessment. For the whole picture, see our CMMC Level 2 cost guide.

What ControlMap's SPRS score does — and doesn't — tell you

ControlMap's calculator applies the CMMC rule's weighted scoring to your answers. Scores run from 110 down to −203. The number is only as true as the answers behind it. And a good score isn't the same as an eligible CMMC status — the POA&M rules decide that.

A hypothetical to test it. Say you run a 40-person machine shop working toward Level 2 (Self). Your MSP marks three requirements NOT MET in ControlMap:

  • AC.L2-3.1.1, limit system access to authorized users. A former employee's account is still active. That's 5 points.
  • SC.L2-3.13.11, CUI encryption. Encryption is on but not FIPS-validated, which costs 3 points instead of 5.
  • PE.L2-3.10.3, escort visitors. Visitors walk the shop floor alone. That's 1 point.
Step Math Result Rule — — —
Step Math Result Rule
Score110 − 5 − 3 − 1101 — what the calculator should show32 CFR 170.24
80% test101 ÷ 110 = 0.92Passes (0.8 needed)170.21(a)(2)(i)
3.13.11 on a POA&M?Allowed exception when encryption is on but not FIPS-validatedYes170.21(a)(2)(ii)
3.1.1 on a POA&M?Worth 5 points; only 1-point items are allowedNo170.21(a)(2)(ii)
3.10.3 on a POA&M?Excluded by nameNo170.21(a)(2)(iii)(D)
Conditional Level 2 (Self)?Every POA&M item must be eligibleNot yet170.21(a)(2)

Fix 3.1.1 and 3.10.3, and the score becomes 107 with one eligible POA&M item. That can support a Conditional Level 2 (Self) status, with 180 days to close the last item. See our guide to conditional status and POA&M closeout.

So a 101 is a real score. It still doesn't qualify for a CMMC status. If ControlMap shows a different number for these answers, or lets you put 3.1.1 on a POA&M without a warning, you've learned something important in a demo instead of an assessment.

Watch the new auto-answers too. ScalePad's Tech Stacks feature fills in CMMC objectives based on the products you list. Assessors don't score products. They score evidence, and the rule requires that evidence be final, not draft. Treat every auto-answer as a draft until someone attaches proof.

One more line that matters. ControlMap produces an SPRS report. Your company enters the result in SPRS, and a senior official affirms it — every year. The person who signs answers for the number, not the software. See what an SPRS score means, the annual affirmation, and what happens when an SPRS score is wrong.

Who ControlMap fits — and who should look elsewhere

ControlMap fits MSPs that run Level 1 or Level 2 programs for several defense clients and can keep CUI outside the tool. It's a weaker fit if:

  • You need Level 3.
  • You want somewhere to store CUI.
  • You're a single contractor who wants software without an MSP.
  • Your real gap is building controls, not tracking them.
Your situation Fit What decides it — —
Your situation Fit What decides it
MSP with several Level 1–2 defense clients, already on ScalePadStrong candidatePer-client pricing, multi-tenant setup, the Lifecycle Manager link
MSP adding CMMC to SOC 2, HIPAA, or ISO workStrong candidateCrosswalks reuse answers across frameworks (Pro)
Contractor whose MSP runs ControlMap for youReasonableThe MSP's CMMC skill matters more than the tool. Settle who owns your records.
Contractor buying for itself, no MSPCheck firstScalePad markets and prices it for MSPs. We found no published plan for a single company, so ask.
Consultant or RPO serving several contractorsPossibleKeep readiness work separate from any formal assessment
FCI only, Level 1Pro may be more than you needLevel 1 is 15 requirements, scored all-or-nothing, with no POA&Ms. A Level 1 checklist may do.
Contract names Level 3Not a fitLevel 3 isn't supported
Evidence full of drawings and CUIOnly with strict link-out habitsCUI stays in your enclave
Must run in GovCloud with specific integrationsConditionalVerify every integration in that region

What ControlMap doesn't replace

ControlMap organizes the program and the evidence. It doesn't build your environment, set up your controls, decide your scope, store your CUI, or perform an assessment. When the real gap is one of those, buying software first puts the order backward.

If what you actually need is… ControlMap's role What you need instead Our guide — — —
If what you actually need is… ControlMap's role What you need instead Our guide
Someone to find where CUI lives and set scopeCan record the answerReadiness help from an RPOWho to hire first · Scoping guide
A safe place for CUINone — CUI stays outA CUI enclave or GCC HighManaged enclaves · GCC High
Controls built and run day to dayTracks the workYour IT team, MSP, or MSSPIs my MSP CMMC-ready?
A formal Level 2 certificationPrepares evidenceAn authorized C3PAO, when a contract requires itRPO vs. C3PAO
A different kind of GRC tool—CMMC-first or broader platforms, unrankedFutureFeed · Totem · Vanta · Drata · Hyperproof · Paramify
Just the documents, on a tight budget—Templates plus disciplined upkeepSSP template · POA&M template

If you're the contractor and your MSP proposed ControlMap, check that software plus an MSP is the right kind of help for your level, environment, and timeline before you sign.

Map the right next step before you buy →

How to test ControlMap before you commit

No web page — including this one — can tell you whether ControlMap's output will satisfy your assessor. Only a sample export in that assessor's hands can. The good news: you can get one before you sign, and a dozen live tests will show whether the tool models CMMC's rules or just tracks tasks. Use made-up data for all of them.

Test in the demo It passes when Warning sign — —
Test in the demo It passes when Warning sign
Load the CMMC Level 2 framework110 requirements and 320 assessment objectives, labeled NIST SP 800-171 Revision 2Revision 3 labels, or missing objectives. See Rev. 2 vs. Rev. 3.
Enter the worked example aboveSPRS shows 101A different number with no explanation
Put 3.1.1 on a POA&MFlagged as ineligible (5 points)Accepted silently
Put 3.10.3 on a POA&MFlagged as excluded by nameAccepted silently
Mark one Level 1 requirement NOT METNo passing result and no POA&M optionIt lets you pass or defer it
Add a product to Tech StacksAuto-answers are labeled, and evidence can be required before METAuto-answers count as MET with no evidence
Export the SSPBoundary, asset categories, all 110 narratives, a service-provider and CRM section, version and dateA framework dump with blanks
Export evidence by objectiveArtifact, date, and owner for each objective; external links open for a reviewerBroken links or no dates
Attach a made-up file tagged CUIA warning, or guidance to link insteadNo guardrail — then your written rules must be the guardrail
Connect your real stack in your target regionIntegrations work against your GCC High tenant, GovCloud accounts, and RMMCommercial-cloud only
Ask how the score gets into SPRSA report, plus a clear answer on who enters it in SPRSVague talk of "automatic submission"
Check tenant accessMultifactor sign-in, roles, and a log of who viewed evidenceShared logins
Export one client's full recordEverything comes out in usable formatsThe record is locked to the MSP account
Open Copilot settingsThe AI provider, data location, and an off switch are documentedUnknown data path

Send this before the demo:

We're evaluating ControlMap for CMMC work and need to check it against our scope. Please send, or arrange a secure review of, the items below. We will not send CUI, drawings, contract numbers, or sensitive system details by email.

  1. The current status of ControlMap's FedRAMP Moderate equivalency effort: complete or not, the assessor's name, and how we can review the body of evidence — or written confirmation that ControlMap must be run CUI-free.
  2. What "other sensitive assessment data" means in your instruction not to upload it.
  3. What a GovCloud tenant changes: data location, who at ScalePad can access it, support staffing, and price.
  4. ControlMap's service description and customer responsibility matrix for CMMC Level 2.
  5. Your SOC 2 Type II report (we'll sign the NDA).
  6. The integrations that work in GovCloud and against Microsoft 365 GCC High.
  7. A sanitized sample SSP export and evidence export by objective, for our intended assessor to review.
  8. Whether Essentials includes the CMMC framework; the Pro tenant minimum; billing term, renewal, and cancellation terms.
  9. Who owns a client's tenant and records, and how a client exports everything if it changes MSPs.
  10. Which AI provider powers Copilot, where data is processed, how long it's kept, and how to turn it off.
  11. Whether any "auditor partner" you refer is a C3PAO listed on the Cyber AB Marketplace, and whether any referral fee is paid.
  12. Whether a single defense contractor can buy and run ControlMap directly, without an MSP.

ControlMap CMMC Demo Sheet

Use made-up files in demos. Don't send CUI, drawings, contract numbers, or system details by email or web form.

Test in the demo It passes when Warning sign — —
Test in the demo It passes when Warning sign
Load the CMMC Level 2 framework110 requirements and 320 assessment objectives, labeled NIST SP 800-171 Revision 2Revision 3 labels, or missing objectives. See Rev. 2 vs. Rev. 3.
Enter the worked example aboveSPRS shows 101A different number with no explanation
Put 3.1.1 on a POA&MFlagged as ineligible (5 points)Accepted silently
Put 3.10.3 on a POA&MFlagged as excluded by nameAccepted silently
Mark one Level 1 requirement NOT METNo passing result and no POA&M optionIt lets you pass or defer it
Add a product to Tech StacksAuto-answers are labeled, and evidence can be required before METAuto-answers count as MET with no evidence
Export the SSPBoundary, asset categories, all 110 narratives, a service-provider and CRM section, version and dateA framework dump with blanks
Export evidence by objectiveArtifact, date, and owner for each objective; external links open for a reviewerBroken links or no dates
Attach a made-up file tagged CUIA warning, or guidance to link insteadNo guardrail — then your written rules must be the guardrail
Connect your real stack in your target regionIntegrations work against your GCC High tenant, GovCloud accounts, and RMMCommercial-cloud only
Ask how the score gets into SPRSA report, plus a clear answer on who enters it in SPRSVague talk of "automatic submission"
Check tenant accessMultifactor sign-in, roles, and a log of who viewed evidenceShared logins
Export one client's full recordEverything comes out in usable formatsThe record is locked to the MSP account
Open Copilot settingsThe AI provider, data location, and an off switch are documentedUnknown data path

If your MSP runs ControlMap for you: five questions

If you're the contractor, your records may live in your MSP's account. Ask these before you start:

  1. Who owns our tenant and the records in it?
  2. Can we export everything — SSP, POA&M, evidence links, history — if we change MSPs? What does that export look like?
  3. Who marks a requirement MET, and what evidence do they need first?
  4. Where are your responsibility matrix and ScalePad's, and are both named in our SSP?
  5. Who signs our annual affirmation? It must be our senior official, not you.

Get the answers into your MSP contract. See switching CMMC providers mid-engagement for why this matters.

What ControlMap CMMC reviews online actually tell you

Most of what you'll find is vendor copy, directory listings, and user reviews. Few of them are about CMMC. User reviews point to ease of use and one-place record keeping. They also report a learning curve, some slowness with large data sets, and sign-in snags. None of that tells you whether the CMMC output will satisfy an assessor.

As of September 24, 2026, G2 lists 51 reviews of ControlMap. Most of the reviews shown disclose a seller invitation and a small incentive, and most discuss SOC 2 or ISO 27001 rather than CMMC. What reviewers say, attributed to them:

  • Likes: Several praise centralizing policies, evidence, and risks, and reusing answers across frameworks. One CMMC-focused reviewer (April 2024) liked writing responses at the sub-objective level and said it eased preparation for a DIBCAC joint surveillance audit. A reviewer who identifies as a Defense Industrial Base vCISO (May 2026) said it compared favorably on price with FutureFeed, IntelliGRC, and Vanta.
  • Dislikes:
  • Setup and a learning curve.
  • Slower loading with large data sets.
  • Integration gaps.
  • A single sign-on problem for users who belong to both an MSP tenant and their own organization's tenant (reported in 2024).

Two quick corrections to what you'll see in directories. Listings that call ControlMap's pricing "custom" or "not public" are out of date: ScalePad publishes list prices. And any listing that repeats ScalePad's FedRAMP or "certified" wording should be read against the claims table near the top of this page.

How we built this profile

We read ScalePad's current product, pricing, security, and help pages and checked each CMMC claim against 32 CFR Part 170 and DFARS 252.204-7012, dating every check. We didn't test the product, see private documents, review a contract, or talk to customers.

The strongest facts here are the ones ScalePad states plainly:

  • which levels ControlMap supports
  • where the CMMC tools sit in the price list
  • what data it tells you not to upload

The weakest are the ones public pages can't settle:

  • direct-purchase terms
  • live calculation quality
  • export usability
  • GovCloud pricing
  • who owns records when an MSP changes

Those belong in your demo and your contract, and the test sheet above puts them there.

What we verified — September 24, 2026

  • Read from primary sources:
  • Company-stated, not independently verified:
  • features
  • hosting details
  • security attestations
  • integration counts
  • Copilot data handling
  • the "FedRAMP Moderate Equivalency" claim
  • Could not verify:
  • ControlMap's FedRAMP Marketplace status
  • the status and assessor of the equivalency effort
  • GovCloud pricing
  • whether the POA&M workflow blocks ineligible items
  • the Pro tenant minimum
  • tenant ownership terms
  • Copilot's AI provider
  • any customer's assessment result

Frequently asked questions

Is ControlMap FedRAMP authorized?

ScalePad doesn't claim that on the pages we read. It announced an effort toward FedRAMP Moderate equivalency in April 2025, and a ScalePad page now shows an equivalency badge based on mapped controls, but no completed assessment is announced. Equivalency only matters for a cloud service that holds CUI, and ScalePad says ControlMap shouldn't.

Does ControlMap use NIST SP 800-171 Revision 2 or Revision 3?

Revision 2, which is what the current CMMC rule uses for Level 2's 110 requirements. NIST has published Revision 3, but DoD hasn't adopted it for CMMC. See Rev. 2 vs. Rev. 3.

Does ControlMap submit my score to SPRS?

ScalePad describes an SPRS report, not a submission. Your company enters the result in SPRS, and a senior official affirms it. Ask the vendor to show, live, how a score moves from ControlMap into SPRS and who does it.

Can a defense contractor buy ControlMap directly?

ScalePad markets and prices ControlMap for MSPs, with one tenant per client. We found no published plan for a single company buying for itself, so ask ScalePad. Most contractors will meet it through their MSP.

If my MSP runs ControlMap, who owns my compliance records?

We couldn't find that stated publicly. Put export rights for your SSP, POA&M, and evidence links into your MSP contract before work starts. Then test an export while the relationship is good.

Still not sure which CMMC path fits your company? Use The Defense Compliance Report's Find My CMMC Path tool to see which path and kind of help fit your contract, CUI, environment, and timeline — before you hire anyone.

Sources

Checked September 24, 2026, unless noted.

Rules and official records

Company sources (company-stated)

User reviews (usability themes only)

Our related guides

  • Do I still need CMMC? What the 2026 suspension changed
  • CMMC external service provider requirements
  • CMMC cloud service provider requirements
  • FedRAMP equivalency for cloud providers
  • CMMC shared responsibility matrix
  • How the Find My CMMC Path router works

About The Defense Compliance Report

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.

We're not affiliated with the Cyber AB, DoD, DCMA DIBCAC, NIST, or any U.S. government agency. This page is educational research, not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP) or a qualified federal-contracts attorney. Read our Editorial & Advertising Policy and methodology.

Map my CMMC path →