Working Through an Assessment

The family tree

The main view lists all 14 NIST SP 800-171 families — Access Control through System and Information Integrity — as a collapsible tree. Each family expands into its requirements, and each requirement into its individual security requirements. Status and evidence icons cascade upward, so a single not-implemented security requirement is visible from the family level without opening anything. For the whole assessment on one screen, there's also the evidence heatmap.

The family tree with per-family status rollups and the live SPRS score
Status rolls up from security requirement → requirement → family.

Setting statuses

Every security requirement takes one of five implementation statuses:

Status Meaning
Implemented The requirement is fully met.
Partially Implemented Some, but not all, of the requirement is met.
Not Implemented The requirement is not met.
Not Applicable The requirement doesn't apply to your environment — record the justification in your notes; assessors will ask for it.
Not Started The default — you haven't evaluated it yet.

Statuses drive everything downstream: the rollup icons, your SPRS score, which items land in the POA&M, and what your SSP says about each control.

Icon meanings

The tree and requirement pages use a small icon vocabulary — these are the app's own icons:

  • Implemented — the requirement is fully met and keeps its SPRS points. Families and requirements only roll up green when everything beneath them is met (or not applicable).
  • Not implemented — the requirement isn't met: the control's full point value comes off your SPRS score and it lands in the generated POA&M. A single not-implemented security requirement surfaces all the way up its family, so gaps are never buried.
  • Partially implemented — some of the requirement is in place, but not all of it. For scoring this still deducts the control's full value — except the few controls where the DoD methodology defines partial credit, which the app applies automatically.
  • Not applicable — the requirement doesn't apply to your environment. Nothing is deducted, but write the justification in your notes: N/A claims are exactly what assessors probe.
  • Has work remaining — a rollup-only icon on families and requirements: work underneath has been started but isn't finished, typically a mix of completed and not-yet-started security requirements. Your to-do marker while an assessment is in flight.
  • Evidence attached — at least one artifact backs this requirement, and the icon cascades up to its family. An "implemented" status without this icon is a claim with nothing behind it — the gap the evidence heatmap is built to expose.
  • Not started — the default; no icon is shown. Untouched controls don't deduct anything yet, so your SPRS number only means something once every control has a real status — work toward zero blank rows before treating the score as reportable.

Markdown notes

Each security requirement has a free-form notes field with full markdown support — describe how the requirement is implemented, reference the systems involved, or record your N/A justification. These notes become the body of your generated SSP, so writing them as you go means the SSP is largely done when you are.

ODP values (Rev 3)

NIST SP 800-171 Rev 3 introduces organization-defined parameters — values like time periods and frequencies that your organization sets. On Rev 3 requirements the app lets you record your chosen ODP values inline, so your documentation captures the parameter alongside the implementation status.

Switching between Rev 2 and Rev 3

CMMC assesses against Rev 2 today, but NIST has finalized Rev 3, and the app covers both. The revision switch in the top navigation toggles between them and smart-jumps to the matching control in the other revision. Rev 2 controls that were withdrawn in Rev 3 render with a "Withdrawn Into…" alert linking to their replacements, so you can document against today's baseline while seeing exactly where each control is headed.

The Rev 3 view with the revision switch in the navigation bar
One click moves the whole workspace between Rev 2 and Rev 3.

Press Ctrl+K (Cmd+K on macOS), or click Search in the navigation, to open the search palette from anywhere in the app. One query searches two things at once:

  • The framework — requirement titles, security requirement text, the discussion, assessment objectives, and organization-defined parameters. Results are labeled with where they matched (for example "Matched in the discussion"), and selecting one jumps straight to that requirement.
  • Your evidence — including file contents. The app extracts text from your attached artifacts (PDFs, spreadsheets, CSVs, text files) into a local index, so searching for a phrase finds the policy that contains it, not just files named after it. Selecting an evidence hit opens the evidence table pre-filtered to your query. Like everything else, the index is built and stored entirely on your device.
The global search palette showing requirement matches and an evidence file match for the query 'access control'
One search, two answers: the controls that match, and the evidence you already have.

The same engine powers the inline search on the family pages, so both surfaces rank and navigate identically. It's the fastest way to work once you're deep in remediation and driving from a POA&M list rather than reading top to bottom.