Skip to main content

2026 Product & Feature Updates

Written by Brady Price

August 2026

We're constantly working to make compliance even easier. This article summarizes recent launches by month. For the full marketing changelog, see the Product Updates page.

New features and updates

Notifications Hub in early access

The Notifications Hub is available in Early Access and brings important updates from across Secureframe into one place.

You can see failing tests, overdue tasks, mentions, audit activity, vendor updates, and other items that need attention. Each notification links to the related resource so teams can respond without searching across the platform.

Learn more: Notifications Hub.

Custom Fields now generally available

Custom Fields are generally available for Complete plan customers.

Admins can create custom fields for Personnel and Tasks, including support in task create/edit, filtering, Task Center columns, reporting, and a usage dashboard.

Simplified employee onboarding setup

Employee Onboarding setup is organized into modular sections for policies, background checks, training, and Secureframe device management.

Clearer descriptions and empty states help with first-time setup and ongoing maintenance as your organization grows.

Choose your personnel source of truth

If you have multiple personnel integrations, you can choose which connected system is the source of truth for personnel data.

You can also see which administrator connected each integration, which helps with ownership and troubleshooting.


July 2026

New features and updates

Smarter prioritization for vulnerability management

The vulnerability dashboard includes an interactive graph so you can drill into findings by severity, override risk levels for your environment, and dismiss findings individually or in bulk with a documented justification that stays in your audit record.

VDI 2.0: Pooled multi-session desktops and roaming profiles

Virtual desktops can run from a shared pool so each user's files and settings follow them to an available desktop. That can mean fewer machines, lower Azure spend, and a faster experience.

When provisioning a new desktop, the estimated VDI cost is shown.

FIPS-Encrypted USB Allowlist for Defense endpoints

Defense customers can define which USB storage devices are allowed on computers managed through Secureframe Federal MDM. USB storage is off by default and enabled only after an admin approves a specific device.

WIF connections for GCP and Azure

GCP and Azure integrations can connect with Workload Identity Federation, which issues short-lived tokens instead of static credentials.

Granular check selection for GitHub integrations

When configuring a GitHub integration or individual repo, you can select specific check names instead of relying only on a broad workflow slug.

Learn more: Github.

Consistent policy editing and cleaner document exports

Policies use the same editor as the rest of Secureframe. Word and PDF exports preserve table formatting and nested lists as authored.


June 2026

New features and updates

Multi-select policies on compliance tests

You can link multiple policies to a single test and see when a draft policy is why a test is failing. Publishing a policy automatically re-runs the paired acknowledgement test.

Reopen and delete completed access reviews

You can reopen a completed review or a single application, fix what needs fixing, and remove test runs or errors from the Complete tab without losing the audit trail.

Faster Office 365 directory syncs

Personnel and access data updates daily. Syncs pull only what changed since the last run, which reduces sync time and Microsoft Graph API quota pressure. No configuration is required.


May 2026

New features and updates

Automatically scope your CMMC compliance program

The Scoping Module walks you through guided questions to determine which requirements apply. Requirements that do not apply can be marked out of scope with audit-ready justifications, irrelevant tests disabled, and policy and SSP language tailored to your answers.

Learn more: CMMC Scoping.

Defense Navigator provides clearer path to CMMC readiness

Defense Navigator guides you step by step through CMMC readiness, from setup and personnel responsibilities to CUI enclave configuration, training, and documentation. New steps unlock after prerequisites are met.

Learn more: Defense Navigator.

Automate GCC High configuration for CMMC

For Microsoft GCC High, Secureframe can automate many CMMC-related configurations, including multifactor authentication, conditional access, audit logging, sharing restrictions, and CUI segregation settings. Where APIs do not allow full automation, Secureframe provides step-by-step manual guidance.

SSP implementation statements now write themselves

When you create an SSP, Secureframe can populate implementation statements from your scoping decisions and connected integrations. You can review and accept suggested updates individually or in bulk.

Updated CMMC Level 2 framework

CMMC Level 2 includes revised control mappings, refreshed policies, and new automated tests for federal environments such as GCC High, Google Workspace, Federal MDM, and Virtual Desktop deployments.

Virtual Desktop enhancements

Windows 11 virtual desktops can include Microsoft 365 apps pre-installed and support Common Access Card (CAC) authentication, with smart card redirection and the required DoD certificate chain configured automatically.

Maintain accurate policies across every environment

Conditional Tokens let policy sections appear or disappear based on conditions you define, such as connected integrations or applicable frameworks.

Know exactly when your evidence expires, before it's a problem

Upload Test evidence expiry is based on when work was performed, not only when a file was uploaded. Expired evidence is flagged rather than auto-archived, default review intervals apply automatically, and due date guidance shows when updated evidence is required.

Filter personnel by integration

You can configure email filtering rules at the individual integration level, not only across the whole organization.

Simpler policy re-acceptance

When you update a policy that requires acknowledgment, you can reset existing acceptances as part of saving the policy. Employees are notified and prompted to re-acknowledge.


April 2026

New features and updates

New Org Picker experience

The updated Org Picker makes switching organizations faster. You can see your role and team size per organization, use favorites for frequent orgs, and sign out from the picker.

Updated Personnel Accounts and Devices tables

Accounts and Devices tables in Personnel have improved sorting, filtering, and navigation so you can see systems and devices tied to each user more quickly.

Learn more: Managing Personnel.


March 2026

New features and updates

User Access Reviews (GA)

User Access Reviews (UAR) are generally available for Secureframe Comply Complete customers.

Teams can schedule recurring or one-time reviews, evaluate access at the application level, and document approve, revoke, or follow-up decisions. Bulk actions and CSV uploads help cover apps without native integrations, with exportable summary views for audit evidence.

Enhanced Risk Management experience in ComplyAI

The ComplyAI workflow guides users to complete required fields like risk description and owner before generating AI recommendations, then highlights the next step.

Auditors now have a dedicated view

Auditors have a dedicated view within Personnel so their experience better matches how they use the platform.

Automatic invite flexibility for personnel

Admins can choose whether to automatically invite users without a start date, so onboarding better matches your process.


February 2026

New features and updates

Smart user mentions in comments

Smart User Mentions let customers and auditors tag each other in comments. Mentioned users get an email with the comment and a link back to Secureframe. In the Audit Module, links go to the exact test and comment.

Audit completion workflow

Auditors and admins can upload multiple reports in a completion modal, keep report feedback in-platform with @mentions, mark when the final report is received, and mark the audit complete.

Employee onboarding in French, German, and Spanish

Employee onboarding workflows, including policy acknowledgments and training steps, are available in French, German, and Spanish.

Integration enhancements: Azure, Microsoft Sentinel, Datadog, and ServiceNow

Azure now pulls user data for Access tab visibility. Government Microsoft Sentinel is supported. Datadog and ServiceNow syncing and monitoring validation are improved.


January 2026

New features and updates

New statuses in Audit Module

Met replaces Accepted to better reflect how requirements are satisfied, especially for federal standards like CMMC.

A new Not Met status shows when a requirement has not been fulfilled. In Review lets auditors show when a test is actively being evaluated.

Updated audit progress bar

The Audit Module progress bar tracks progress toward 100% Met so you can see readiness at a glance.

Improved audit log visibility

Audit Log updates include links to jump directly to changed items from the log table.

When linking audit firms, progressive search finds firms with an Auditor Partner Console (APC) as you type.


Looking for 2025 Updates?

See the full summary of 2025 product updates: 2025 Product & Feature Updates.

Did this answer your question?