NIST CSF · RMF · SP 800-53 · SP 800-30

Your Risk Posture Deserves
Better Than a Spreadsheet

Professional cybersecurity assessment tools built on authoritative NIST frameworks. Free to use, no account required, assessment data never leaves your browser.

The GRC Tooling Problem

The frameworks are solid. The tooling isn't.

NIST has published authoritative guidance for every aspect of cybersecurity risk management. The problem isn't the frameworks. It's working through them without spending a fortune or losing your mind.

Spreadsheet Sprawl

Homegrown Excel templates can hold your scoring data, but they lack built-in gap analysis, maturity gauges, and comparative trend tracking. Every new engagement starts with reformatting the same spreadsheet. Version control falls apart. Sharing results requires manual cleanup. The framework logic lives in someone's head, not the tool.

Enterprise Platforms Are Overkill

Full GRC platforms cost thousands of dollars per year and require substantial onboarding before a single assessment can be run. They're built for compliance programs at scale, not for practitioners who need to perform a focused NIST CSF gap analysis or work through an RMF authorization package without a three-month implementation project.

Cloud Tools Raise Data Concerns

Assessment data is often sensitive: system names, control gaps, unmitigated risks, authorization status. Uploading that data to a SaaS platform creates real questions about who has access, how it's stored, and what the vendor does with it. For organizations handling CUI, classified-adjacent information, or sensitive internal security posture data, that's a non-starter.

Framework Depth Gets Lost

Generic risk tools summarize frameworks into high-level categories that lose the authoritative detail that makes NIST useful. The CSF's 106 subcategories, SP 800-53's control enhancements, SP 800-30's threat taxonomy: these structures exist for a reason. Tools that abstract them into simplified dropdown menus remove the substance without replacing it with anything.

Why Risk Posture Tools

Practical tools, properly built.

Each tool is purpose-built for its framework, not a generic form wrapped in marketing. Free to use, with Pro features for practitioners who need to save, share, and report.

Assessment Data Never Leaves Your Browser

All assessment processing happens in your browser. Your assessment data is never transmitted to a server, stored in a cloud database, or accessible to anyone but you. It is stored only in this browser on your device and stays there between visits until you clear your browser data. Use Pro's JSON export to back it up or move it to another device.

Framework-Authoritative

Every control, subcategory, and reference maps directly to the published NIST source document. The CSF tool covers all 106 subcategories across all 6 functions. The RMF tool walks every step of SP 800-37. No abstraction layers, no framework summaries, just the actual framework, in full. Where a tool computes a score (such as the SP 800-30 risk rating), the methodology is transparent and documented in-tool.

No Account, No Setup

Open any tool and start assessing immediately. There's no registration, no configuration, no onboarding email to wait for. All tools are fully functional without any account. Paid features unlock by verifying your purchase email, with no password or profile to manage.

Save & Compare (Pro)

Pro subscribers can save point-in-time JSON snapshots of any assessment, import them to resume work in a future session, and compare maturity scores across multiple assessments over time. Export to CSV (opens in any spreadsheet app such as Excel or Google Sheets) or generate print-ready reports for stakeholder presentations and ATO package assembly.

The Suite

Tools for every major NIST framework.

Each tool covers its framework completely, from the broadest organizational functions down to individual control implementation details.

NIST RMF Assessment
SP 800-37 Rev 2
Walk all 7 RMF steps, Prepare through Monitor, with FIPS 199, control selection, and ATO documentation support.
System Security Plan
SP 800-18 Rev 1 / SP 800-53 Rev 5
Build a complete SSP with system description, FIPS categorization, baseline tailoring, and SP 800-53 Rev 5 control narratives.
Security Assessment Report
SP 800-53A · ATO Artifact
Document control assessment results (methods, determination, and findings) and produce the SAR that anchors your authorization package. Pulls from the SSP, feeds the POA&M.
POA&M Tracker
FISMA / FedRAMP
Track findings, corrective actions, and milestones with responsible parties, due dates, priority/status badges, overdue alerts, and CSV export (Pro).
NIST CSF 2.0 Assessment
CSF 2.0
Score all 6 functions and 106 subcategories. Gap analysis, maturity gauges, and Pro trend tracking across snapshots.
NIST AI RMF Assessment
AI RMF 1.0
Score 72 subcategories across Govern, Map, Measure, Manage, plus the Generative AI Profile. Tier-by-tier examples and a regulatory crosswalk.
CMMC L2
SP 800-171 Rev 2 · DoD SPRS
Self-assess all 110 requirements and compute your DoD SPRS score for CMMC Level 2, with per-family progress and an exportable POA&M of gaps.
Risk Register
SP 800-37 Rev 2 · SP 800-39
Maintain an organization-wide risk register: track risks, response strategies, owners, and status as part of a continuous risk management program.
Risk Assessment
SP 800-30 Rev 1
Structured threat identification, vulnerability mapping, likelihood and impact scoring, with SP 800-30 methodology throughout.

Free to use. Save, export, and print for $179/year.

A Pro subscription unlocks import, JSON snapshots, CSV export, print/PDF reports, trend analysis, a progress-over-time dashboard across all tools, and a combined Authorization Package, plus every new tool as it ships.