Readiness Tracker
✓ Saved locally
0%
Readiness Score
110
SPRS Score (est.)
0
Met
0
Partial
0
Gap
0
Not Started
110
Controls in Scope

SPRS score is a self-assessment estimate over all 110 controls per the NIST SP 800-171 DoD Assessment Methodology v1.2.1 — not an official SPRS submission.

By Family

FamilyControlsMetPartialGapNot StartedScoreSPRS Pts Lost
FamilyIDWtRequirementMicrosoft StackHIPAAStatusOwnerNotesEvidenceReview cycle

Recurring access-control review checklist. Add items for each review cycle.

#ItemStatusReviewerNotesDate Completed

Track gaps, assign owners, set target dates, and monitor remediation progress.

#Control IDWeakness / GapOwnerRemediation ActionTarget DateStatus

A phased path to compliance, generated from your open POA&M items — sequenced by target date, highest-weight (SPRS) gaps first within each phase.

Where one project closes several requirements at once. These groupings are deliberately cross-family — a single MFA rollout, for example, satisfies requirements in both 3.5 (Identification & Authentication) and 3.7 (Maintenance). Use this to plan work by effort rather than by control number.

Note: these clusters are editorial groupings by this tool to help sequence work — they are not defined by NIST, and a control appearing in two clusters is intentional. Always confirm scope against your own environment and contractual requirements.

HIPAA Security Rule overlap

If you're a covered entity or business associate, much of your 800-171 work also serves the HIPAA Security Rule (45 CFR Part 164, Subpart C). This shows which HIPAA standards your controls touch — and, just as importantly, which ones they don't.

Indicative only — not audit-grade equivalence. Derived by chaining NIST SP 800-171 Rev 2 Appendix D (171→800-53) with NIST SP 800-66 Rev 2 (HIPAA→800-53); CFR citations and names verified against the regulation text. Mappings run one way: implementing an 800-171 control may help satisfy a HIPAA standard, not the reverse (e.g. MFA satisfies §164.312(d), but HIPAA does not require MFA). Entries marked ~ are weak, catch-all, or analogy-based — the whole 3.4 Configuration Management family routes through Risk Management because the Security Rule has no configuration-management standard. Verify against your own obligations.

HIPAA standardCitation800-171 controls that support itMet

Frequently asked questions

Is my data saved? Where?
Yes — in your browser's local storage, on your device only. It persists across reloads and restarts. It's never sent to a server, and we can't see it.
Do I need an account or to sign in?
No. No account, no email, no sign-up. Just open it and start.
How do I back up or move my data to another computer?
Use Export (.xlsx or JSON) to download a file, then Import on the other machine to restore it. This is also your backup — do it regularly, since clearing your browser data will erase your progress.
Will I lose my work?
Your work stays until you clear your browser's site data (or use Reset). To be safe, export a backup periodically.
Can I use the online tracker and still download my saved data?
Yes. Work in the app, then use Export (.xlsx / JSON) any time to save a copy. Import brings it back.
What are the [a], [b], [c] items under each control?
Those are the assessment objectives from NIST SP 800-171A — the individual determination statements an assessor checks for each requirement. Expand a control in the Control Tracker to mark each one Met / Not Met / N/A. The control's overall status rolls up automatically: all applicable objectives Met → Met, some Met → Partial, none Met → Gap. Objectives marked N/A are excluded from the rollup. Note that SPRS scoring stays per-control per the DoD methodology — it isn't scored per objective.
Does being 800-171 compliant make me HIPAA compliant?
No. There's substantial overlap — the Overlap tab shows which HIPAA Security Rule standards your 800-171 work supports — but 800-171 leaves real HIPAA gaps. The biggest is contingency planning (§164.308(a)(7): disaster recovery, emergency mode operation, criticality analysis), which 800-171 Rev 2 has no family for. Business associate contract content (§164.314) and documentation availability (§164.316(b)(2)(ii)) are also uncovered. The crosswalk is also one-way: implementing MFA satisfies §164.312(d), but HIPAA doesn't require MFA. Treat it as a planning aid, not a compliance claim.
How does the review cycle / audit frequency work?
Every control has a suggested review frequency — Monthly, Quarterly or Annual — based on how operational it is (vulnerability scanning is monthly; the SSP is annual). These are suggestions, not requirements, and you can change any of them to Monthly, Quarterly, Semi-annual, Annual, Continuous or As needed. Set a Last Reviewed date and the tracker computes the next due date and flags anything overdue or due within 30 days. The dashboard summarises how many reviews are overdue, and you can filter the tracker by review state. NIST doesn't prescribe most of these intervals — your own policy and contract do.
I can't remember the control number — how do I find it?
Press ⌘K (or Ctrl+K), or click Search in the top bar, and type what you remember in plain language. It understands the shorthand people actually use — MFA finds the multifactor controls, antivirus finds the malicious-code ones, VPN finds remote access, USB finds portable storage, screen lock finds session lock. It searches control text, all 320 assessment objectives, the Microsoft mapping, HIPAA citations and cluster names, and tells you which one matched. Hit ↵ to jump straight to that control.
What is the Overlap tab for?
Two things. Implementation clusters group controls that one project usually closes together — a single MFA rollout covers requirements in both 3.5 and 3.7, so you can plan by effort instead of control number. (These groupings are ours, not NIST's.) HIPAA overlap shows which HIPAA Security Rule standards your 800-171 controls support, plus the requirements they don't cover.
Is the SPRS score official?
No. It's a self-assessment estimate calculated per the NIST SP 800-171 DoD Assessment Methodology (Annex A weights). It is not an official SPRS submission, and this tool does not grant CMMC certification. Always confirm against the official methodology and your contractual requirements.
Do you collect any of my data?
No. Your assessment data never leaves your browser. The hosted site uses cookieless, aggregate analytics (page counts only) — nothing that identifies you or touches your tracker contents.
Can I run this on my own network or air-gapped?
Yes. It's static and open source (github.com/ansrdio/ansrd). Clone it and serve the folder — it works fully offline with no external calls.
Which framework version is this based on?
NIST SP 800-171 Rev 2 — the baseline for CMMC Level 2 under DoD Class Deviation 2024-O0013. (Intentionally not Rev 3.)
How do I suggest a feature or report a problem?
Open an issue on GitHub: github.com/ansrdio/ansrd/issues.
Is it really free?
Yes — free, open source, no sign-up, no ads, no upsell.

Privacy & your data

Your data, plainly.

  • No account, ever. No sign-up, no login, no email required. Open it and start.
  • No backend for your data. Everything you enter — control statuses, notes, owners, evidence, POA&M items — is saved only in your own browser's local storage, on your device. It is never uploaded, transmitted, or stored on any server we control. We cannot see it.
  • You own it. Use Export (.xlsx / JSON) to back up your work or move it between machines, and Import to restore it. That's the only way your data ever leaves your browser — because you chose to save a file.
  • Back up regularly. Because nothing is stored on a server, clearing your browser's site data (or using Reset) erases your progress. Export a copy periodically.
  • Analytics. The hosted site (ansrd.io) uses Vercel Web Analytics — cookieless, no personal data, aggregate page counts only. It cannot see or transmit anything you enter in the tracker. No advertising trackers, no third-party cookies.
  • Run it yourself. It's static and open source. Clone it from GitHub and run it entirely inside your own environment — even fully air-gapped. Self-hosted, it makes no external requests at all.
  • Verify it yourself. Open your browser's DevTools → Network tab and watch: your assessment data never posts anywhere.
You your device Your browser local storage ✓ saved here No server nothing uploaded
Your data → your browser's local storage ✓  ·  ✕ never to a server
Free to use — no sign-up, no account. Your assessment data stays in your browser and is never uploaded to or stored on our servers; we can't see it. Export / Import lets you back it up or move it yourself. We use privacy-friendly, cookieless analytics that collect no personal data — only anonymous visit counts.
NIST 800-171 / CMMC Readiness Tracker · v2.8 · updated July 2026 · Privacy · FAQ
Disclaimer: Control text is summarized from the publicly available NIST SP 800-171 Rev.2. Always refer to the official NIST publication and your own contractual requirements for authoritative wording. All data stays in your browser's localStorage — nothing is transmitted to any server. Export regularly — use Export .xlsx / Export JSON to keep per-client or backup copies; Import restores them.

SPRS score: calculated per the NIST SP 800-171 DoD Assessment Methodology v1.2.1 (Annex A weights). It is a self-assessment estimate, not an official SPRS submission, and this tool does not grant CMMC certification. Weights for 3.5.3 (MFA) and 3.13.11 (FIPS crypto) apply built-in partial credit; 3.12.4 (SSP) is a prerequisite rather than a scored item.

Assessment objectives: the [a] [b] [c] determination statements under each control are summarized from the publicly available NIST SP 800-171A — refer to the official publication for authoritative wording. Marking objectives rolls the control up automatically (all applicable objectives Met → Met; some Met → Partial; none Met → Gap); objectives marked N/A are excluded. SPRS scoring remains per-control per the DoD methodology — it is not calculated per objective.

HIPAA crosswalk: indicative only, and one-way — implementing an 800-171 control may help satisfy a HIPAA Security Rule standard, not the reverse. Derived by chaining NIST SP 800-171 Rev 2 Appendix D (171→800-53) with NIST SP 800-66 Rev 2 (HIPAA→800-53); CFR citations and standard names verified against the regulation text. Entries flagged ~ are weak or catch-all. Being 800-171 compliant does not make you HIPAA compliant — contingency planning (§164.308(a)(7)) in particular has no 800-171 counterpart. Reflects the Security Rule as currently codified; HHS's January 2025 NPRM would change several of these. Consult counsel and your own risk analysis.

Implementation clusters: editorial groupings by this tool to help sequence work — not defined by NIST. Controls intentionally appear in more than one cluster.

Microsoft-stack mapping: indicative mapping to Microsoft Defender, Intune, Entra ID, and Purview, informed by the Microsoft Product Placemat for CMMC 2.0, the Microsoft Technical Reference Guide for CMMC Level 2, and Microsoft Learn CMMC configuration guidance. Coverage depends on licensing and configuration — a mapped product supports, but does not by itself satisfy, a requirement.