The family tree
The main view lists all 14 NIST SP 800-171 families — Access Control through System and Information Integrity — as a collapsible tree. Each family expands into its requirements, and each requirement into its individual security requirements. Status and evidence icons cascade upward, so a single not-implemented security requirement is visible from the family level without opening anything.
Setting statuses
Every security requirement takes one of five implementation statuses:
| Status | Meaning |
|---|---|
| Implemented | The requirement is fully met. |
| Partially Implemented | Some, but not all, of the requirement is met. |
| Not Implemented | The requirement is not met. |
| Not Applicable | The requirement doesn't apply to your environment — record the justification in your notes; assessors will ask for it. |
| Not Started | The default — you haven't evaluated it yet. |
Statuses drive everything downstream: the rollup icons, your SPRS score, which items land in the POA&M, and what your SSP says about each control.
Icon meanings
The tree and requirement pages use a small icon vocabulary:
- Green check circle — implemented.
- Red minus circle — not implemented (any not-implemented security requirement inside a family or requirement surfaces here).
- Amber pause circle — partially implemented.
- Minus — not applicable.
- Hammer — the family or requirement has remaining work.
- Paperclip — evidence has been attached.
- No icon — not started.
Markdown notes
Each security requirement has a free-form notes field with full markdown support — describe how the requirement is implemented, reference the systems involved, or record your N/A justification. These notes become the body of your generated SSP, so writing them as you go means the SSP is largely done when you are.
ODP values (Rev 3)
NIST SP 800-171 Rev 3 introduces organization-defined parameters — values like time periods and frequencies that your organization sets. On Rev 3 requirements the app lets you record your chosen ODP values inline, so your documentation captures the parameter alongside the implementation status.
Switching between Rev 2 and Rev 3
CMMC assesses against Rev 2 today, but NIST has finalized Rev 3, and the app covers both. The revision switch in the top navigation toggles between them and smart-jumps to the matching control in the other revision. Rev 2 controls that were withdrawn in Rev 3 render with a "Withdrawn Into…" alert linking to their replacements, so you can document against today's baseline while seeing exactly where each control is headed.
Search
The search dropdown in the navigation looks up any requirement by identifier or title, jumping straight to its page — useful once you're deep in remediation and working from a POA&M list rather than top to bottom.