Turn a recurring audit chore into a repeatable system.
A free, practical tracker for small and mid-sized regulated healthcare organizations and Defense Industrial Base (DIB) contractors that have to meet NIST 800-171 and CMMC requirements — without a large internal security team.
Free · no signup · 110 controls · runs in your browser, data stays on your device.
One system, four views into the same work.
Most small teams rebuild their compliance tracking from scratch every audit cycle. This keeps it in one place, so each cycle starts where the last one ended.
Map every control
All 110 NIST 800-171 requirements, by family. Set status, assign an owner, note how it's implemented, and point to where the evidence lives.
See readiness at a glance
An auto-calculated rollup: met, partial, and gap counts by family, a readiness score — and a DoD Assessment Methodology (SPRS) self-assessment score with official per-control weights, from −203 to 110.
Run the recurring review
A repeatable checklist for the access-control review that auditors expect every period. Run it, log the date and reviewer, file the evidence.
Track what's left
A plan of action and milestones for every gap — owner, remediation step, target date, and status — auto-sequenced into a phased compliance roadmap. Plus a Microsoft-stack mapping (Defender, Intune, Entra ID, Purview) for every control, and a CMMC Level 1 / Level 2 view.
Status you can read in a glance.
Each control carries a clear status. The dashboard does the counting for you.
| ID | Requirement | Status |
|---|---|---|
| 3.1.1 | Limit system access to authorized users and devices | Met |
| 3.3.1 | Create and retain system audit logs | Partial |
| 3.5.3 | Use multifactor authentication for access | Met |
| 3.6.3 | Test the incident response capability | Gap |
| 3.12.4 | Develop and update the system security plan | Partial |
Five steps, every review period.
The tracker is built to be re-opened, not rebuilt. Each cycle moves controls forward and leaves an evidence trail.
Built for the teams without a security department.
Larger enterprises buy GRC platforms. Smaller regulated organizations often track this in scattered spreadsheets and email. This is for them.
I work in healthcare, and I built this to run my own NIST 800-171 / CMMC readiness — it's the tool I actually use. It isn't healthcare-specific, though: anyone working toward 800-171 or CMMC is welcome to use it.
Download it and start your first cycle.
A single spreadsheet file. Open it, read the first tab, and begin. No account and nothing to install.
Or use the in-browser version — no download needed, state saved locally. Export/import (.xlsx or JSON) makes per-client files easy for consultants and MSPs.
What this is — and isn't.
This tracker supports compliance work; it does not by itself make an organization compliant or certified. It organizes the status, ownership, and evidence tracking that a real readiness program requires. Control text is summarized from the publicly available NIST SP 800-171 Rev.2 — always refer to the official NIST publication and your own contractual requirements for authoritative wording. The SPRS score is a self-assessment estimate calculated per the NIST SP 800-171 DoD Assessment Methodology, not an official SPRS submission. Keep sensitive data in your secured systems and reference its location in the tracker rather than storing it in a shared copy.