The CMMC Self-Assessment & Compliance Tracker is a private, offline-first workspace for NIST SP 800-171 self-assessments. You work through each security requirement, record an implementation status and notes, attach evidence, and watch your SPRS score update live — then generate a markdown System Security Plan and a CSV POA&M with one click. All of your data stays in local storage on your device: no servers, no accounts, no telemetry.
Two ways to run it
| Browser (free) | Desktop (licensed) | |
|---|---|---|
| Where | app.getcmmc.consulting — installable as a PWA | Native app for Windows, macOS, and Linux (download) |
| Scope | The 17 CMMC Level 1 practices (FAR 52.204-21) and their Rev 3 equivalents are fully editable; all other requirements are visible but read-only | All 110 NIST SP 800-171 requirements editable, plus SPRS scoring |
| Cost | Free — no account, no license | Yearly subscription; every subscription starts with a 14-day free trial |
| Reports & exports | Always complete | Always complete |
Reports and exports — the SSP, POA&M, evidence, and full database export — are never gated on either tier, so your data is never trapped.
Find what you need
- Getting Started — install the app, activate a license, and take the guided tour.
- Working Through an Assessment — families, requirements, statuses, notes, and the Rev 2 ↔ Rev 3 toggle.
- Your SPRS Score — how the live score is calculated and what the estimated Rev 3 score means.
- Assessment Guidance — the built-in Rev 2 assessor guidance and evidence checklists.
- Evidence Management — attaching, previewing, sharing, and exporting evidence.
- Reports & Exports — SSP and POA&M generation, database export/import, and the evidence map.
- Licensing, Trial & Billing — how the 14-day trial works, activating your key, and managing your subscription.
- Offline & Air-Gapped Use — running the app on machines that can never go online.
- Troubleshooting & FAQ — data storage, backups, updates, and common issues.
Getting help
The app is self-serve, but you're not on your own. Email support@getcmmc.consulting with questions, or book a free consultation if you want a Lead Certified CMMC Assessor to help you interpret your results. The source code is available on GitHub under the Elastic License 2.0.