August 2026
We're constantly working to make compliance even easier. This article summarizes recent launches by month. For the full marketing changelog, see the Product Updates page.
New features and updates
Notifications Hub in early access
The Notifications Hub is available in Early Access and brings important updates from across Secureframe into one place.
You can see failing tests, overdue tasks, mentions, audit activity, vendor updates, and other items that need attention. Each notification links to the related resource so teams can respond without searching across the platform.
Learn more: Notifications Hub.
Custom Fields now generally available
Custom Fields are generally available for Complete plan customers.
Admins can create custom fields for Personnel and Tasks, including support in task create/edit, filtering, Task Center columns, reporting, and a usage dashboard.
Learn more: Using Custom Fields in Secureframe.
Simplified employee onboarding setup
Employee Onboarding setup is organized into modular sections for policies, background checks, training, and Secureframe device management.
Clearer descriptions and empty states help with first-time setup and ongoing maintenance as your organization grows.
Learn more: Setting Up Employee Onboarding (Admin Guide).
Choose your personnel source of truth
If you have multiple personnel integrations, you can choose which connected system is the source of truth for personnel data.
You can also see which administrator connected each integration, which helps with ownership and troubleshooting.
Learn more: Editing & Merging Personnel Records.
July 2026
New features and updates
Smarter prioritization for vulnerability management
The vulnerability dashboard includes an interactive graph so you can drill into findings by severity, override risk levels for your environment, and dismiss findings individually or in bulk with a documented justification that stays in your audit record.
Learn more: Vulnerability Management.
VDI 2.0: Pooled multi-session desktops and roaming profiles
Virtual desktops can run from a shared pool so each user's files and settings follow them to an available desktop. That can mean fewer machines, lower Azure spend, and a faster experience.
When provisioning a new desktop, the estimated VDI cost is shown.
Learn more: Secureframe Virtual Desktops.
FIPS-Encrypted USB Allowlist for Defense endpoints
Defense customers can define which USB storage devices are allowed on computers managed through Secureframe Federal MDM. USB storage is off by default and enabled only after an admin approves a specific device.
Learn more: Secureframe Federal MDM: USB Device Allowlist.
WIF connections for GCP and Azure
GCP and Azure integrations can connect with Workload Identity Federation, which issues short-lived tokens instead of static credentials.
Learn more: Google Cloud Platform (GCP) and Microsoft Azure Cloud.
Granular check selection for GitHub integrations
When configuring a GitHub integration or individual repo, you can select specific check names instead of relying only on a broad workflow slug.
Learn more: Github.
Consistent policy editing and cleaner document exports
Policies use the same editor as the rest of Secureframe. Word and PDF exports preserve table formatting and nested lists as authored.
Learn more: Create and or Edit policies.
June 2026
New features and updates
Multi-select policies on compliance tests
You can link multiple policies to a single test and see when a draft policy is why a test is failing. Publishing a policy automatically re-runs the paired acknowledgement test.
Learn more: Linking a published Policy to a Policy Test.
Reopen and delete completed access reviews
You can reopen a completed review or a single application, fix what needs fixing, and remove test runs or errors from the Complete tab without losing the audit trail.
Learn more: User Access Reviews (UAR).
Faster Office 365 directory syncs
Personnel and access data updates daily. Syncs pull only what changed since the last run, which reduces sync time and Microsoft Graph API quota pressure. No configuration is required.
May 2026
New features and updates
Automatically scope your CMMC compliance program
The Scoping Module walks you through guided questions to determine which requirements apply. Requirements that do not apply can be marked out of scope with audit-ready justifications, irrelevant tests disabled, and policy and SSP language tailored to your answers.
Learn more: CMMC Scoping.
Defense Navigator provides clearer path to CMMC readiness
Defense Navigator guides you step by step through CMMC readiness, from setup and personnel responsibilities to CUI enclave configuration, training, and documentation. New steps unlock after prerequisites are met.
Learn more: Defense Navigator.
Automate GCC High configuration for CMMC
For Microsoft GCC High, Secureframe can automate many CMMC-related configurations, including multifactor authentication, conditional access, audit logging, sharing restrictions, and CUI segregation settings. Where APIs do not allow full automation, Secureframe provides step-by-step manual guidance.
Learn more: Government clouds (GCC High, GovCloud).
SSP implementation statements now write themselves
When you create an SSP, Secureframe can populate implementation statements from your scoping decisions and connected integrations. You can review and accept suggested updates individually or in bulk.
Learn more: Building and Managing a System Security Plan (SSP).
Updated CMMC Level 2 framework
CMMC Level 2 includes revised control mappings, refreshed policies, and new automated tests for federal environments such as GCC High, Google Workspace, Federal MDM, and Virtual Desktop deployments.
Virtual Desktop enhancements
Windows 11 virtual desktops can include Microsoft 365 apps pre-installed and support Common Access Card (CAC) authentication, with smart card redirection and the required DoD certificate chain configured automatically.
Learn more: Secureframe Virtual Desktops.
Maintain accurate policies across every environment
Conditional Tokens let policy sections appear or disappear based on conditions you define, such as connected integrations or applicable frameworks.
Learn more: Create and or Edit policies.
Know exactly when your evidence expires, before it's a problem
Upload Test evidence expiry is based on when work was performed, not only when a file was uploaded. Expired evidence is flagged rather than auto-archived, default review intervals apply automatically, and due date guidance shows when updated evidence is required.
Learn more: Understanding Upload Tests: Intervals, Evidence Validity, Due Dates, and Tolerance Windows.
Filter personnel by integration
You can configure email filtering rules at the individual integration level, not only across the whole organization.
Learn more: Email domain filters.
Simpler policy re-acceptance
When you update a policy that requires acknowledgment, you can reset existing acceptances as part of saving the policy. Employees are notified and prompted to re-acknowledge.
April 2026
New features and updates
New Org Picker experience
The updated Org Picker makes switching organizations faster. You can see your role and team size per organization, use favorites for frequent orgs, and sign out from the picker.
Updated Personnel Accounts and Devices tables
Accounts and Devices tables in Personnel have improved sorting, filtering, and navigation so you can see systems and devices tied to each user more quickly.
Learn more: Managing Personnel.
March 2026
New features and updates
User Access Reviews (GA)
User Access Reviews (UAR) are generally available for Secureframe Comply Complete customers.
Teams can schedule recurring or one-time reviews, evaluate access at the application level, and document approve, revoke, or follow-up decisions. Bulk actions and CSV uploads help cover apps without native integrations, with exportable summary views for audit evidence.
Learn more: User Access Reviews (UAR).
Enhanced Risk Management experience in ComplyAI
The ComplyAI workflow guides users to complete required fields like risk description and owner before generating AI recommendations, then highlights the next step.
Auditors now have a dedicated view
Auditors have a dedicated view within Personnel so their experience better matches how they use the platform.
Automatic invite flexibility for personnel
Admins can choose whether to automatically invite users without a start date, so onboarding better matches your process.
February 2026
New features and updates
Smart user mentions in comments
Smart User Mentions let customers and auditors tag each other in comments. Mentioned users get an email with the comment and a link back to Secureframe. In the Audit Module, links go to the exact test and comment.
Audit completion workflow
Auditors and admins can upload multiple reports in a completion modal, keep report feedback in-platform with @mentions, mark when the final report is received, and mark the audit complete.
Employee onboarding in French, German, and Spanish
Employee onboarding workflows, including policy acknowledgments and training steps, are available in French, German, and Spanish.
Integration enhancements: Azure, Microsoft Sentinel, Datadog, and ServiceNow
Azure now pulls user data for Access tab visibility. Government Microsoft Sentinel is supported. Datadog and ServiceNow syncing and monitoring validation are improved.
January 2026
New features and updates
New statuses in Audit Module
Met replaces Accepted to better reflect how requirements are satisfied, especially for federal standards like CMMC.
A new Not Met status shows when a requirement has not been fulfilled. In Review lets auditors show when a test is actively being evaluated.
Updated audit progress bar
The Audit Module progress bar tracks progress toward 100% Met so you can see readiness at a glance.
Improved audit log visibility
Audit Log updates include links to jump directly to changed items from the log table.
Progressive auditor search
When linking audit firms, progressive search finds firms with an Auditor Partner Console (APC) as you type.
Looking for 2025 Updates?
See the full summary of 2025 product updates: 2025 Product & Feature Updates.
