Readiness Tracker
NIST SP 800-171 · CMMC readiness

Turn a recurring audit chore into a repeatable system.

A free, practical tracker for small and mid-sized regulated healthcare organizations and Defense Industrial Base (DIB) contractors that have to meet NIST 800-171 and CMMC requirements — without a large internal security team.

Free · no signup · 110 controls · runs in your browser, data stays on your device.

110
800-171 controls
14
control families
110
max SPRS score
review cycles
What it does

One system, four views into the same work.

Most small teams rebuild their compliance tracking from scratch every audit cycle. This keeps it in one place, so each cycle starts where the last one ended.

Control Tracker

Map every control

All 110 NIST 800-171 requirements, by family. Set status, assign an owner, note how it's implemented, and point to where the evidence lives.

Dashboard + SPRS

See readiness at a glance

An auto-calculated rollup: met, partial, and gap counts by family, a readiness score — and a DoD Assessment Methodology (SPRS) self-assessment score with official per-control weights, from −203 to 110.

Access Review Cycle

Run the recurring review

A repeatable checklist for the access-control review that auditors expect every period. Run it, log the date and reviewer, file the evidence.

POA&M + Roadmap

Track what's left

A plan of action and milestones for every gap — owner, remediation step, target date, and status — auto-sequenced into a phased compliance roadmap. Plus a Microsoft-stack mapping (Defender, Intune, Entra ID, Purview) for every control, and a CMMC Level 1 / Level 2 view.

A look inside

Status you can read in a glance.

Each control carries a clear status. The dashboard does the counting for you.

IDRequirementStatusOwner
3.1.1Limit system access to authorized users and devicesMetIT Lead
3.3.1Create and retain system audit logsPartialSec Analyst
3.5.3Use multifactor authentication for accessMetIT Lead
3.6.3Test the incident response capabilityGapCompliance
3.12.4Develop and update the system security planPartialCompliance
The cycle

Five steps, every review period.

The tracker is built to be re-opened, not rebuilt. Each cycle moves controls forward and leaves an evidence trail.

Set each control's statusMet, partial, gap, or not started — straight from the dropdown.
Record owner and evidenceWho owns it, where the evidence lives, and the date you reviewed it.
Log gaps in the POA&MAnything not met gets an owner and a target date.
Check the dashboardSee your readiness score and which families need attention.
Re-run the access reviewWork the recurring checklist and update the dates.
Who it's for

Built for the teams without a security department.

Larger enterprises buy GRC platforms. Smaller regulated organizations often track this in scattered spreadsheets and email. This is for them.

Small and mid-sized clinics and health plans
Skilled nursing and assisted living providers
Community health centers and FQHCs
Behavioral health and home-health agencies
Medical billing and healthcare service vendors
DIB contractors working toward CMMC Level 1 or 2
Defense subcontractors handling CUI on Microsoft 365
IT teams and MSPs implementing CMMC for clients

I work in healthcare, and I built this to run my own NIST 800-171 / CMMC readiness — it's the tool I actually use. It isn't healthcare-specific, though: anyone working toward 800-171 or CMMC is welcome to use it.

Get the tracker

Download it and start your first cycle.

A single spreadsheet file. Open it, read the first tab, and begin. No account and nothing to install.

Or use the in-browser version — no download needed, state saved locally. Export/import (.xlsx or JSON) makes per-client files easy for consultants and MSPs.

Honest scope

What this is — and isn't.

This tracker supports compliance work; it does not by itself make an organization compliant or certified. It organizes the status, ownership, and evidence tracking that a real readiness program requires. Control text is summarized from the publicly available NIST SP 800-171 Rev.2 — always refer to the official NIST publication and your own contractual requirements for authoritative wording. The SPRS score is a self-assessment estimate calculated per the NIST SP 800-171 DoD Assessment Methodology, not an official SPRS submission. Keep sensitive data in your secured systems and reference its location in the tracker rather than storing it in a shared copy.