Compliance Scorecard Version 9: Smarter Assessments, Automated Risk Management, and Stronger Audit Readiness
Compliance Scorecard Version 9 introduces major platform upgrades designed to help MSPs manage assessments, risk, insurance, AI governance, and audit readiness more efficiently.
This release strengthens the connection between compliance activity and measurable outcomes. From a redesigned Assessment Scorecard and automated risk workflows to System Security Plan generation and direct cyber insurance integrations, Version 9 gives MSPs more control, better visibility, and clearer documentation across every stage of the compliance lifecycle.
Turn Compliance Activity Into Actionable Risk and Audit Readiness
Version 9 makes it easier to move from identifying a compliance gap to documenting, assigning, mitigating, and reporting it. Assessment findings can now flow directly into the Risk Scorecard and Project Center, while enhanced SPRS reporting, secure evidence hashing, auditor collaboration tools, and System Security Plan generation help MSPs prepare clients for audits with greater confidence.
What's New:
Redesigned Assessment and SPRS Experience: The Assessment Scorecard now features a more intuitive layout that groups related control objectives under each top-level control. MSPs can view SPRS scores directly within CMMC assessments, export assessment versions, access supplemental materials without leaving the assessment, and generate more accurate SPRS reports based on NIST SP 800-171 requirements.
Automated Risk Management: Controls marked as anything other than satisfactory are now automatically added to Risk Findings without creating duplicates. Users can assign likelihood and severity directly from a new Risk Matrix tab and update associated risks when controls are remediated. The visual Risk Matrix also provides a clearer view of how risks are distributed across the client environment.
System Security Plan Generation: MSPs can now create System Security Plans directly within Compliance Scorecard. The guided workflow uses information already stored in the platform, collects any remaining details, and generates downloadable SSP documents individually or as a complete ZIP file.
AI-Powered Compliance Tools: New AI capabilities include policy summaries, policy adoption questions, assessment analysis, and summaries of global policy reference materials. MSPs can control these features through platform settings, edit or regenerate adoption questions, and choose whether AI-generated explanations appear in client-facing workflows.
Direct Cyber Insurance Workflows: The Insurance Scorecard now supports both Ukon Solutions and DataStream. MSPs can complete DataStream questionnaires within the platform and submit structured responses directly to the insurance provider, creating a more connected path between compliance posture and cyber insurance applications.
Stronger Policy Adoption and Client Governance: MSPs now have greater control over client access to Risk Findings, the Risk Register, Risk Matrix, and Project Center. Adoption campaign improvements make it easier to manage contacts, remove non-adopters, navigate between policies, customize AI-generated questions, and prevent archived or deactivated users from receiving reminders.
Audit and Evidence Enhancements: Auditor Reports now support questions, recommendations, comments, invitation tracking, access expiration dates, and invitation revocation. Evidence uploads use secure NIST-approved hashing, and Google Drive can now be configured as an Evidence Locker for assessment documentation.
Project and POAM Improvements: POAM milestones can now connect directly to Project Center tasks, and users can enter task details without leaving the POAM workflow. Manual RACI assignments also allow MSPs to document responsible individuals even when they are not Compliance Scorecard users.
Enhanced Integrations and Platform Experience: Version 9 adds Google Drive evidence storage, Huntress OAuth connectivity, improved Microsoft Graph contact workflows, expanded CSV import fields, client impersonation, stronger feature permissions, and numerous export, notification, dark mode, synchronization, and usability improvements.
For the latest news on our GRC platform for MSPs, check back here regularly.
Tim Golden
Founder & CEO, Compliance Scorecard

