Readiness Tracker Beta
✓ Saved locally
0%
ANSRd Readiness Indicator
110
SPRS Score (est.) ⓘ
0
Met
0
Partial
0
Gap
0
Not Started
110
Controls in Scope

SPRS score is a self-assessment estimate over all 110 controls per the NIST SP 800-171 DoD Assessment Methodology v1.2.1 — not an official SPRS submission.

Scope & findings: This tool does not determine or validate your official CMMC assessment scope — define it under the official CMMC Scoping Guides before relying on these readiness results. The Met / Partial / Gap / Not Started labels are internal readiness and workflow indicators, not official CMMC findings — official Level 2 findings are MET / NOT MET / NOT APPLICABLE per the CMMC Level 2 Assessment Guide.

By Family

FamilyControlsMetPartialGapNot StartedScoreSPRS Pts Lost
FamilyIDWtRequirementMicrosoft StackHIPAAStatusOwnerNotesEvidenceReview cycle

Recurring access-control review checklist. Add items for each review cycle.

#ItemStatusReviewerNotesDate Completed

Track gaps, assign owners, set target dates, and monitor remediation progress. This is an internal planning aid. For a formal CMMC Level 2 assessment, POA&M eligibility is limited — only certain requirements may be placed on a POA&M, a minimum assessment score is required for a conditional status, and POA&M items must be closed out within 180 days (see 32 CFR §170.21). Not every deficiency is eligible for a formal CMMC POA&M.

#Control IDWeakness / GapOwnerRemediation ActionTarget DateStatus

A phased path to compliance, generated from your open POA&M items — sequenced by target date, highest-weight (SPRS) gaps first within each phase.

Where one project closes several requirements at once. These groupings are deliberately cross-family — a single MFA rollout, for example, satisfies requirements in both 3.5 (Identification & Authentication) and 3.7 (Maintenance). Use this to plan work by effort rather than by control number.

Note: these clusters are editorial groupings by this tool to help sequence work — they are not defined by NIST, and a control appearing in two clusters is intentional. Always confirm scope against your own environment and contractual requirements.

HIPAA Security Rule overlap

If you're a covered entity or business associate, much of your 800-171 work also serves the HIPAA Security Rule (45 CFR Part 164, Subpart C). This shows which HIPAA standards your controls touch — and, just as importantly, which ones they don't.

Indicative only — not audit-grade equivalence. Derived by chaining NIST SP 800-171 Rev 2 Appendix D (171→800-53) with NIST SP 800-66 Rev 2 (HIPAA→800-53); CFR citations and names verified against the regulation text. Mappings run one way: implementing an 800-171 control may help satisfy a HIPAA standard, not the reverse (e.g. MFA satisfies §164.312(d), but HIPAA does not require MFA). Entries marked ~ are weak, catch-all, or analogy-based — the whole 3.4 Configuration Management family routes through Risk Management because the Security Rule has no configuration-management standard. Verify against your own obligations.

HIPAA standardCitation800-171 controls that support itMet

Frequently asked questions

Is my data saved? Where?
Yes — in your browser's local storage, on your device only. It persists across reloads and restarts. Your assessment content is not sent to ANSRd's application servers and we can't see it. (The hosted site does collect limited, non-assessment usage telemetry via Vercel Analytics — see Privacy.)
Do I need an account or to sign in?
No. No account, no email, no sign-up. Just open it and start.
How do I back up or move my data to another computer?
Use Export (.xlsx or JSON) to download a file, then Import on the other machine to restore it. This is also your backup — do it regularly, since clearing your browser data will erase your progress.
Will I lose my work?
Your work stays until you clear your browser's site data (or use Reset). To be safe, export a backup periodically.
Can I use the online tracker and still download my saved data?
Yes. Work in the app, then use Export (.xlsx / JSON) any time to save a copy. Import brings it back.
What are the [a], [b], [c] items under each control?
Those are the assessment objectives from NIST SP 800-171A — the individual determination statements an assessor checks for each requirement. Expand a control in the Control Tracker to mark each one Met / Not Met / N/A. The control's overall status rolls up automatically: all applicable objectives Met → Met, some Met → Partial, none Met → Gap. Objectives marked N/A are excluded from the rollup. Note that SPRS scoring stays per-control per the DoD methodology — it isn't scored per objective.
Does being 800-171 compliant make me HIPAA compliant?
No. There's substantial overlap — the Overlap tab shows which HIPAA Security Rule standards your 800-171 work supports — but 800-171 leaves real HIPAA gaps. The biggest is contingency planning (§164.308(a)(7): disaster recovery, emergency mode operation, criticality analysis), which 800-171 Rev 2 has no family for. Business associate contract content (§164.314) and documentation availability (§164.316(b)(2)(ii)) are also uncovered. The crosswalk is also one-way: implementing MFA satisfies §164.312(d), but HIPAA doesn't require MFA. Treat it as a planning aid, not a compliance claim.
How does the review cycle / audit frequency work?
Every control has a suggested review frequency — Monthly, Quarterly or Annual — based on how operational it is (vulnerability scanning is monthly; the SSP is annual). These are suggestions, not requirements, and you can change any of them to Monthly, Quarterly, Semi-annual, Annual, Continuous or As needed. Set a Last Reviewed date and the tracker computes the next due date and flags anything overdue or due within 30 days. The dashboard summarises how many reviews are overdue, and you can filter the tracker by review state. NIST doesn't prescribe most of these intervals — your own policy and contract do.
I can't remember the control number — how do I find it?
Press ⌘K (or Ctrl+K), or click Search in the top bar, and type what you remember in plain language. It understands the shorthand people actually use — MFA finds the multifactor controls, antivirus finds the malicious-code ones, VPN finds remote access, USB finds portable storage, screen lock finds session lock. It searches control text, all 320 assessment objectives, the Microsoft mapping, HIPAA citations and cluster names, and tells you which one matched. Hit ↵ to jump straight to that control.
What is the Overlap tab for?
Two things. Implementation clusters group controls that one project usually closes together — a single MFA rollout covers requirements in both 3.5 and 3.7, so you can plan by effort instead of control number. (These groupings are ours, not NIST's.) HIPAA overlap shows which HIPAA Security Rule standards your 800-171 controls support, plus the requirements they don't cover.
Is the SPRS score official?
No. It's a self-assessment estimate calculated per the NIST SP 800-171 DoD Assessment Methodology (Annex A weights). It is not an official SPRS submission, and this tool does not grant CMMC certification. Always confirm against the official methodology and your contractual requirements.
Do you collect any of my data?
Your assessment content — control answers, notes, owners, evidence references, POA&M items — stays in your browser and is not uploaded to ANSRd's application servers. The hosted site uses Vercel Analytics to collect limited, non-assessment usage telemetry: page/route visits, approximate geography, device/browser/OS information, referrers, and anonymous interaction-event counts. Analytics never includes your assessment content. See Privacy for details.
Can I run this on my own network or air-gapped?
Yes. It's static and open source (github.com/ansrdio/ansrd). Clone it and serve the folder — it works fully offline with no external calls.
Which framework version is this based on?
NIST SP 800-171 Rev 2 — the baseline for CMMC Level 2 under DoD Class Deviation 2024-O0013. (Intentionally not Rev 3.)
How do I suggest a feature or report a problem?
Open an issue on GitHub: github.com/ansrdio/ansrd/issues.
Is it really free?
Yes — free, open source, no sign-up, no ads, no upsell.

Privacy & your data

Your data, plainly.

  • No account, ever. No sign-up, no login, no email required. Open it and start.
  • No backend for your assessment content. Everything you enter — control statuses, notes, owners, evidence references, POA&M items — is saved only in your own browser's local storage, on your device. It is not uploaded to or stored on any ANSRd application server, and we cannot see it.
  • You own it. Use Export (.xlsx / JSON) to back up your work or move it between machines, and Import to restore it. That's the only way your assessment content leaves your browser as application data — because you chose to save a file.
  • Back up regularly. Because your assessment content is not stored on a server, clearing your browser's site data (or using Reset) erases your progress. Export a copy periodically.
  • Analytics (hosted site). ansrd.io uses Vercel Analytics as a service provider for limited website-usage telemetry. This may include page/route usage, approximate geographic information, device/browser/operating-system information, and referrer data, plus anonymous counts of named interaction events (for example assessment_started, control_updated, assessment_exported, workbook_downloaded). These are counts only — they do not contain your control answers, notes, evidence references, or any assessment content. The purpose is to understand whether this public resource is being accessed and which functionality is used. No advertising trackers and no third-party advertising cookies. Run it yourself (see below) for zero external telemetry.
  • Run it yourself. It's static and open source. Clone it from GitHub and run it entirely inside your own environment — even fully air-gapped. Self-hosted, it makes no external requests at all.
  • Verify it yourself. Open your browser's DevTools → Network tab and watch: your assessment data never posts anywhere.
You your device Your browser local storage ✓ saved here No server no assessment data
Your assessment data → your browser's local storage ✓  ·  ✕ not sent to an application server (separate from limited Vercel Analytics usage telemetry)
Free to use — no sign-up, no account. Your assessment content stays in your browser and is not uploaded to ANSRd's application servers. We use Vercel Analytics to collect limited, non-assessment usage telemetry such as page visits, general device/browser information, approximate geographic information, referrers, and anonymous interaction-event counts. We do not send your control answers, evidence references, implementation notes, or other assessment content through analytics. Export / Import lets you back up your work or move it between machines. See Privacy for details.
NIST 800-171 / CMMC Readiness Tracker · v2.11 · Beta · updated September 2026 · Privacy · FAQ · Beta feedback
Disclaimer: Control text is summarized from the publicly available NIST SP 800-171 Rev.2. Always refer to the official NIST publication and your own contractual requirements for authoritative wording. Assessment content is stored locally in your browser's localStorage and is not transmitted as application data; limited website-usage telemetry is collected separately through Vercel Analytics as described in the Privacy section. Export regularly — use Export .xlsx / Export JSON to keep per-client or backup copies; Import restores them.

SPRS score: calculated per the NIST SP 800-171 DoD Assessment Methodology v1.2.1 (Annex A weights). It is a self-assessment estimate, not an official SPRS submission, and this tool does not grant CMMC certification. Weights for 3.5.3 (MFA) and 3.13.11 (FIPS crypto) apply built-in partial credit; 3.12.4 (SSP) is a prerequisite rather than a scored item.

Assessment objectives: the [a] [b] [c] determination statements under each control are summarized from the publicly available NIST SP 800-171A — refer to the official publication for authoritative wording. Marking objectives rolls the control up automatically (all applicable objectives Met → Met; some Met → Partial; none Met → Gap); objectives marked N/A are excluded. SPRS scoring remains per-control per the DoD methodology — it is not calculated per objective.

HIPAA crosswalk: indicative only, and one-way — implementing an 800-171 control may help satisfy a HIPAA Security Rule standard, not the reverse. Derived by chaining NIST SP 800-171 Rev 2 Appendix D (171→800-53) with NIST SP 800-66 Rev 2 (HIPAA→800-53); CFR citations and standard names verified against the regulation text. Entries flagged ~ are weak or catch-all. Being 800-171 compliant does not make you HIPAA compliant — contingency planning (§164.308(a)(7)) in particular has no 800-171 counterpart. Reflects the Security Rule as currently codified; HHS's January 2025 NPRM would change several of these. Consult counsel and your own risk analysis.

Implementation clusters: editorial groupings by this tool to help sequence work — not defined by NIST. Controls intentionally appear in more than one cluster.

Microsoft-stack mapping: indicative mapping to Microsoft Defender, Intune, Entra ID, and Purview, informed by the Microsoft Product Placemat for CMMC 2.0, the Microsoft Technical Reference Guide for CMMC Level 2, and Microsoft Learn CMMC configuration guidance. Coverage depends on licensing and configuration — a mapped product supports, but does not by itself satisfy, a requirement.