SPRS score is a self-assessment estimate over all 110 controls per the NIST SP 800-171 DoD Assessment Methodology v1.2.1 — not an official SPRS submission.
By Family
| Family | Controls | Met | Partial | Gap | Not Started | Score | SPRS Pts Lost |
|---|
| Family | ID | Wt | Requirement | Microsoft Stack | HIPAA | Status | Owner | Notes | Evidence | Review cycle |
|---|
Recurring access-control review checklist. Add items for each review cycle.
| # | Item | Status | Reviewer | Notes | Date Completed |
|---|
Track gaps, assign owners, set target dates, and monitor remediation progress.
| # | Control ID | Weakness / Gap | Owner | Remediation Action | Target Date | Status |
|---|
A phased path to compliance, generated from your open POA&M items — sequenced by target date, highest-weight (SPRS) gaps first within each phase.
Where one project closes several requirements at once. These groupings are deliberately cross-family — a single MFA rollout, for example, satisfies requirements in both 3.5 (Identification & Authentication) and 3.7 (Maintenance). Use this to plan work by effort rather than by control number.
Note: these clusters are editorial groupings by this tool to help sequence work — they are not defined by NIST, and a control appearing in two clusters is intentional. Always confirm scope against your own environment and contractual requirements.
HIPAA Security Rule overlap
If you're a covered entity or business associate, much of your 800-171 work also serves the HIPAA Security Rule (45 CFR Part 164, Subpart C). This shows which HIPAA standards your controls touch — and, just as importantly, which ones they don't.
Indicative only — not audit-grade equivalence. Derived by chaining NIST SP 800-171 Rev 2 Appendix D (171→800-53) with NIST SP 800-66 Rev 2 (HIPAA→800-53); CFR citations and names verified against the regulation text. Mappings run one way: implementing an 800-171 control may help satisfy a HIPAA standard, not the reverse (e.g. MFA satisfies §164.312(d), but HIPAA does not require MFA). Entries marked ~ are weak, catch-all, or analogy-based — the whole 3.4 Configuration Management family routes through Risk Management because the Security Rule has no configuration-management standard. Verify against your own obligations.
| HIPAA standard | Citation | 800-171 controls that support it | Met |
|---|
Frequently asked questions
Is my data saved? Where?
Do I need an account or to sign in?
How do I back up or move my data to another computer?
Will I lose my work?
Can I use the online tracker and still download my saved data?
What are the [a], [b], [c] items under each control?
Does being 800-171 compliant make me HIPAA compliant?
How does the review cycle / audit frequency work?
I can't remember the control number — how do I find it?
What is the Overlap tab for?
Is the SPRS score official?
Do you collect any of my data?
Can I run this on my own network or air-gapped?
Which framework version is this based on?
How do I suggest a feature or report a problem?
Is it really free?
Privacy & your data
Your data, plainly.
- No account, ever. No sign-up, no login, no email required. Open it and start.
- No backend for your data. Everything you enter — control statuses, notes, owners, evidence, POA&M items — is saved only in your own browser's local storage, on your device. It is never uploaded, transmitted, or stored on any server we control. We cannot see it.
- You own it. Use Export (.xlsx / JSON) to back up your work or move it between machines, and Import to restore it. That's the only way your data ever leaves your browser — because you chose to save a file.
- Back up regularly. Because nothing is stored on a server, clearing your browser's site data (or using Reset) erases your progress. Export a copy periodically.
- Analytics. The hosted site (ansrd.io) uses Vercel Web Analytics — cookieless, no personal data, aggregate page counts only. It cannot see or transmit anything you enter in the tracker. No advertising trackers, no third-party cookies.
- Run it yourself. It's static and open source. Clone it from GitHub and run it entirely inside your own environment — even fully air-gapped. Self-hosted, it makes no external requests at all.
- Verify it yourself. Open your browser's DevTools → Network tab and watch: your assessment data never posts anywhere.
SPRS score: calculated per the NIST SP 800-171 DoD Assessment Methodology v1.2.1 (Annex A weights). It is a self-assessment estimate, not an official SPRS submission, and this tool does not grant CMMC certification. Weights for 3.5.3 (MFA) and 3.13.11 (FIPS crypto) apply built-in partial credit; 3.12.4 (SSP) is a prerequisite rather than a scored item.
Assessment objectives: the
[a] [b] [c] determination statements under each control are summarized from the publicly available NIST SP 800-171A — refer to the official publication for authoritative wording. Marking objectives rolls the control up automatically (all applicable objectives Met → Met; some Met → Partial; none Met → Gap); objectives marked N/A are excluded. SPRS scoring remains per-control per the DoD methodology — it is not calculated per objective.
HIPAA crosswalk: indicative only, and one-way — implementing an 800-171 control may help satisfy a HIPAA Security Rule standard, not the reverse. Derived by chaining NIST SP 800-171 Rev 2 Appendix D (171→800-53) with NIST SP 800-66 Rev 2 (HIPAA→800-53); CFR citations and standard names verified against the regulation text. Entries flagged ~ are weak or catch-all. Being 800-171 compliant does not make you HIPAA compliant — contingency planning (§164.308(a)(7)) in particular has no 800-171 counterpart. Reflects the Security Rule as currently codified; HHS's January 2025 NPRM would change several of these. Consult counsel and your own risk analysis.
Implementation clusters: editorial groupings by this tool to help sequence work — not defined by NIST. Controls intentionally appear in more than one cluster.
Microsoft-stack mapping: indicative mapping to Microsoft Defender, Intune, Entra ID, and Purview, informed by the Microsoft Product Placemat for CMMC 2.0, the Microsoft Technical Reference Guide for CMMC Level 2, and Microsoft Learn CMMC configuration guidance. Coverage depends on licensing and configuration — a mapped product supports, but does not by itself satisfy, a requirement.