Your assessment content saves automatically in this browser and is not uploaded as application data. Limited usage telemetry is collected separately as described in Privacy. Set each control's status in the Control Tracker; use Export to back it up. See Privacy & Your Data.
Scope & findings: This tool does not determine or validate your official CMMC assessment scope — define it under the official CMMC Scoping Guides before relying on these readiness results. The Met / Partial / Gap / Not Started labels are internal readiness and workflow indicators, not official CMMC findings — official Level 2 findings are MET / NOT MET / NOT APPLICABLE per the CMMC Level 2 Assessment Guide.
CMMC Level 1 is assessed against the 15 safeguarding requirements of FAR 52.204-21 for the protection of Federal Contract Information (FCI). Each requirement is evaluated through its assessment objectives (from the CMMC Level 1 Assessment Guide) and rolls up to a finding of MET, NOT MET, or N/A; Not started is an internal pre-assessment state, not a CMMC finding. Level 1 requires an annual self-assessment and annual affirmation, entered into SPRS. There is no SPRS numerical score at Level 1 (the −203 to 110 methodology applies to Level 2 / NIST SP 800-171), and CMMC Level 1 POA&Ms are not permitted (this does not stop you from keeping internal corrective-action or operational remediation plans). The Readiness % below counts MET and documented-N/A requirements as satisfied; it is an application-generated indicator, not an official CMMC or SPRS score.
⚠ 3.12.4 (System Security Plan) is not Met. Per the DoD methodology, without an SSP an assessment cannot be completed — the SSP is a prerequisite, not a point deduction.
By Family
Family
Controls
Met
Partial
Gap
Not Started
Score
SPRS Pts Lost
Family
ID
Wt
Requirement
Microsoft Stack
HIPAA
Status
Owner
Notes
Evidence
Review cycle
Recurring access-control review checklist. Add items for each review cycle.
#
Item
Status
Reviewer
Notes
Date Completed
CMMC Level 1 POA&Ms are not permitted. Level 1 requirements are assessed MET / NOT MET / N/A across the 15 FAR 52.204-21 requirements; every requirement must be MET (or a documented N/A) for Level 1. A NOT MET requirement is an unresolved gap to remediate before Level 1 is met — track it in the Control Tracker, not here. This restriction applies to the formal CMMC POA&M only; you can still keep internal corrective-action or operational remediation plans. The POA&M tab here is a Level 2 (NIST SP 800-171) feature; switch the level selector to Level 2 to use it.
Track gaps, assign owners, set target dates, and monitor remediation progress. This is an internal planning aid. For a formal CMMC Level 2 assessment, POA&M eligibility is limited — only certain requirements may be placed on a POA&M, a minimum assessment score is required for a conditional status, and POA&M items must be closed out within 180 days (see 32 CFR §170.21). Not every deficiency is eligible for a formal CMMC POA&M.
#
Control ID
Weakness / Gap
Owner
Remediation Action
Target Date
Status
The roadmap is a Level 2 feature. It is generated from formal CMMC POA&M items, which are not permitted at CMMC Level 1 (keeping internal corrective-action plans is still fine). At Level 1, remediate any NOT MET requirement directly in the Control Tracker until all 15 FAR 52.204-21 requirements are MET or a documented N/A.
A phased path to compliance, generated from your open POA&M items — sequenced by target date, highest-weight (SPRS) gaps first within each phase.
Where one project closes several requirements at once. These groupings are deliberately cross-family — a single MFA rollout, for example, satisfies requirements in both 3.5 (Identification & Authentication) and 3.7 (Maintenance). Use this to plan work by effort rather than by control number.
Note: these clusters are editorial groupings by this tool to help sequence work — they are not defined by NIST, and a control appearing in two clusters is intentional. Always confirm scope against your own environment and contractual requirements.
HIPAA Security Rule overlap
If you're a covered entity or business associate, much of your 800-171 work also serves the HIPAA Security Rule (45 CFR Part 164, Subpart C). This shows which HIPAA standards your controls touch — and, just as importantly, which ones they don't.
Indicative only — not audit-grade equivalence. Derived by chaining NIST SP 800-171 Rev 2 Appendix D (171→800-53) with NIST SP 800-66 Rev 2 (HIPAA→800-53); CFR citations and names verified against the regulation text. Mappings run one way: implementing an 800-171 control may help satisfy a HIPAA standard, not the reverse (e.g. MFA satisfies §164.312(d), but HIPAA does not require MFA). Entries marked ~ are weak, catch-all, or analogy-based — the whole 3.4 Configuration Management family routes through Risk Management because the Security Rule has no configuration-management standard. Verify against your own obligations.
HIPAA standard
Citation
800-171 controls that support it
Met
Frequently asked questions
Is my data saved? Where?
Yes — in your browser's local storage, on your device only. It persists across reloads and restarts. Your assessment content is not sent to ANSRd's application servers and we can't see it. (The hosted site does collect limited, non-assessment usage telemetry via Vercel Analytics — see Privacy.)
Do I need an account or to sign in?
No. No account, no email, no sign-up. Just open it and start.
How do I back up or move my data to another computer?
Use Export (.xlsx or JSON) to download a file, then Import on the other machine to restore it. This is also your backup — do it regularly, since clearing your browser data will erase your progress.
Will I lose my work?
Your work stays until you clear your browser's site data (or use Reset). To be safe, export a backup periodically.
Can I use the online tracker and still download my saved data?
Yes. Work in the app, then use Export (.xlsx / JSON) any time to save a copy. Import brings it back.
What are the [a], [b], [c] items under each control?
Those are the assessment objectives from NIST SP 800-171A — the individual determination statements an assessor checks for each requirement. Expand a control in the Control Tracker to mark each one Met / Not Met / N/A. The control's overall status rolls up automatically: all applicable objectives Met → Met, some Met → Partial, none Met → Gap. Objectives marked N/A are excluded from the rollup. Note that SPRS scoring stays per-control per the DoD methodology — it isn't scored per objective.
Does being 800-171 compliant make me HIPAA compliant?
No. There's substantial overlap — the Overlap tab shows which HIPAA Security Rule standards your 800-171 work supports — but 800-171 leaves real HIPAA gaps. The biggest is contingency planning (§164.308(a)(7): disaster recovery, emergency mode operation, criticality analysis), which 800-171 Rev 2 has no family for. Business associate contract content (§164.314) and documentation availability (§164.316(b)(2)(ii)) are also uncovered. The crosswalk is also one-way: implementing MFA satisfies §164.312(d), but HIPAA doesn't require MFA. Treat it as a planning aid, not a compliance claim.
How does the review cycle / audit frequency work?
Every control has a suggested review frequency — Monthly, Quarterly or Annual — based on how operational it is (vulnerability scanning is monthly; the SSP is annual). These are suggestions, not requirements, and you can change any of them to Monthly, Quarterly, Semi-annual, Annual, Continuous or As needed. Set a Last Reviewed date and the tracker computes the next due date and flags anything overdue or due within 30 days. The dashboard summarises how many reviews are overdue, and you can filter the tracker by review state. NIST doesn't prescribe most of these intervals — your own policy and contract do.
I can't remember the control number — how do I find it?
Press ⌘K (or Ctrl+K), or click Search in the top bar, and type what you remember in plain language. It understands the shorthand people actually use — MFA finds the multifactor controls, antivirus finds the malicious-code ones, VPN finds remote access, USB finds portable storage, screen lock finds session lock. It searches control text, all 320 assessment objectives, the Microsoft mapping, HIPAA citations and cluster names, and tells you which one matched. Hit ↵ to jump straight to that control.
What is the Overlap tab for?
Two things. Implementation clusters group controls that one project usually closes together — a single MFA rollout covers requirements in both 3.5 and 3.7, so you can plan by effort instead of control number. (These groupings are ours, not NIST's.) HIPAA overlap shows which HIPAA Security Rule standards your 800-171 controls support, plus the requirements they don't cover.
Is the SPRS score official?
No. It's a self-assessment estimate calculated per the NIST SP 800-171 DoD Assessment Methodology (Annex A weights). It is not an official SPRS submission, and this tool does not grant CMMC certification. Always confirm against the official methodology and your contractual requirements.
Do you collect any of my data?
Your assessment content — control answers, notes, owners, evidence references, POA&M items — stays in your browser and is not uploaded to ANSRd's application servers. The hosted site uses Vercel Analytics to collect limited, non-assessment usage telemetry: page/route visits, approximate geography, device/browser/OS information, referrers, and anonymous interaction-event counts. Analytics never includes your assessment content. See Privacy for details.
Can I run this on my own network or air-gapped?
Yes. It's static and open source (github.com/ansrdio/ansrd). Clone it and serve the folder — it works fully offline with no external calls.
Which framework version is this based on?
NIST SP 800-171 Rev 2 — the baseline for CMMC Level 2 under DoD Class Deviation 2024-O0013. (Intentionally not Rev 3.)
Yes — free, open source, no sign-up, no ads, no upsell.
Privacy & your data
Your data, plainly.
No account, ever. No sign-up, no login, no email required. Open it and start.
No backend for your assessment content. Everything you enter — control statuses, notes, owners, evidence references, POA&M items — is saved only in your own browser's local storage, on your device. It is not uploaded to or stored on any ANSRd application server, and we cannot see it.
You own it. Use Export (.xlsx / JSON) to back up your work or move it between machines, and Import to restore it. That's the only way your assessment content leaves your browser as application data — because you chose to save a file.
Back up regularly. Because your assessment content is not stored on a server, clearing your browser's site data (or using Reset) erases your progress. Export a copy periodically.
Analytics (hosted site). ansrd.io uses Vercel Analytics as a service provider for limited website-usage telemetry. This may include page/route usage, approximate geographic information, device/browser/operating-system information, and referrer data, plus anonymous counts of named interaction events (for example assessment_started, control_updated, assessment_exported, workbook_downloaded). These are counts only — they do not contain your control answers, notes, evidence references, or any assessment content. The purpose is to understand whether this public resource is being accessed and which functionality is used. No advertising trackers and no third-party advertising cookies. Run it yourself (see below) for zero external telemetry.
Run it yourself. It's static and open source. Clone it from GitHub and run it entirely inside your own environment — even fully air-gapped. Self-hosted, it makes no external requests at all.
Verify it yourself. Open your browser's DevTools → Network tab and watch: your assessment data never posts anywhere.
Your assessment data → your browser's local storage ✓ · ✕ not sent to an application server (separate from limited Vercel Analytics usage telemetry)
Free to use — no sign-up, no account. Your assessment content stays in your browser and is not uploaded to ANSRd's application servers. We use Vercel Analytics to collect limited, non-assessment usage telemetry such as page visits, general device/browser information, approximate geographic information, referrers, and anonymous interaction-event counts. We do not send your control answers, evidence references, implementation notes, or other assessment content through analytics. Export / Import lets you back up your work or move it between machines. See Privacy for details.
Disclaimer: Control text is summarized from the publicly available NIST SP 800-171 Rev.2. Always refer to the official NIST publication and your own contractual requirements for authoritative wording. Assessment content is stored locally in your browser's localStorage and is not transmitted as application data; limited website-usage telemetry is collected separately through Vercel Analytics as described in the Privacy section. Export regularly — use Export .xlsx / Export JSON to keep per-client or backup copies; Import restores them.
SPRS score: calculated per the NIST SP 800-171 DoD Assessment Methodology v1.2.1 (Annex A weights). It is a self-assessment estimate, not an official SPRS submission, and this tool does not grant CMMC certification. Weights for 3.5.3 (MFA) and 3.13.11 (FIPS crypto) apply built-in partial credit; 3.12.4 (SSP) is a prerequisite rather than a scored item.
Assessment objectives: the [a] [b] [c] determination statements under each control are summarized from the publicly available NIST SP 800-171A — refer to the official publication for authoritative wording. Marking objectives rolls the control up automatically (all applicable objectives Met → Met; some Met → Partial; none Met → Gap); objectives marked N/A are excluded. SPRS scoring remains per-control per the DoD methodology — it is not calculated per objective.
HIPAA crosswalk: indicative only, and one-way — implementing an 800-171 control may help satisfy a HIPAA Security Rule standard, not the reverse. Derived by chaining NIST SP 800-171 Rev 2 Appendix D (171→800-53) with NIST SP 800-66 Rev 2 (HIPAA→800-53); CFR citations and standard names verified against the regulation text. Entries flagged ~ are weak or catch-all. Being 800-171 compliant does not make you HIPAA compliant — contingency planning (§164.308(a)(7)) in particular has no 800-171 counterpart. Reflects the Security Rule as currently codified; HHS's January 2025 NPRM would change several of these. Consult counsel and your own risk analysis.
Implementation clusters: editorial groupings by this tool to help sequence work — not defined by NIST. Controls intentionally appear in more than one cluster.
Microsoft-stack mapping: indicative mapping to Microsoft Defender, Intune, Entra ID, and Purview, informed by the Microsoft Product Placemat for CMMC 2.0, the Microsoft Technical Reference Guide for CMMC Level 2, and Microsoft Learn CMMC configuration guidance. Coverage depends on licensing and configuration — a mapped product supports, but does not by itself satisfy, a requirement.
Searches control text, the 320 assessment objectives, Microsoft mapping, HIPAA and clusters · ↑↓ to move · ↵ to open · esc to close
Reset everything?
This clears all statuses, notes, owners, evidence, and POA&M entries and resets every control to Not Started. This can't be undone.