RMF packages that go in right the first time

Tools that keep your checklists, your scan results, and your eMASS POA&M in agreement, so the package doesn’t come back.

STIGreviewer’s checklist inventory, flagging outdated STIGs and a host information issue across the loaded checklists

STIGreviewer, free

  1. The Issue Summary: outdated STIGs and host information problems across every checklist you have open.
  2. Every checklist flagged when a newer version of its STIG is available.
  3. Host details checked against your own rules, one click away.

Works with what you already have

  • CKL
  • CKLB
  • SCAP
  • .nessus
  • ACAS
  • eMASS POA&M
  • eMASS test results
  • Evaluate-STIG answer files
Checklists on a single Windows server
6-12
Checklists in a typical package
Hundreds

The problem

Hundreds of checklists. Spreadsheets and scripts holding it together.

Everyone doing this work has built their own way through it: spreadsheets, PowerShell, Python, whatever could be cobbled together. It works, right up until it doesn’t.

It doesn’t scale

What handles 40 checklists fails at 400.

It takes a scripting skill set

The work ends up gated behind whoever on the team can write the scripts, and it leaves with them.

It isn’t a process

Nothing repeatable, nothing you can document, nothing you can hand to someone new.

How it goes wrong

The parts stop agreeing, and you have no way of knowing

The hardware and software list stops matching what was actually tested. The POA&M stops matching the results behind it. You find out when a reviewer does.

BaselineHardware and software list, test plan
TestingChecklists and scans, across hundreds of assets
POA&MGenerated from the actual results
Each step feeds the next, and the POA&M has to trace back to the baseline it started from. Nothing in the standard toolchain closes that loop.

What it costs

Rework is the expensive part

A package that comes back isn’t a scheduling inconvenience. It’s re-testing, re-documenting, and re-submitting, while the ATO date moves and everyone waits on you.

The mistakes that cause it are rarely dramatic. A system in the baseline that never got tested. A POA&M entry that doesn’t match the finding it came from. A checklist still on last quarter’s version. Small, individually invisible, and expensive in aggregate.

Who we are

We built the tools we needed

STIG Solution builds applications for the people who assemble RMF packages. Not checklist editors with extra features, but tools built around how the work actually runs: establish a baseline, test against it, prove the results agree, and keep the POA&M current.

We also publish the quarterly DISA STIG revision summaries, parsed into JSON and Excel, free to anyone who wants them. We’ve done it every quarter for five years, and we’ll keep doing it whether you ever buy anything.

How it works

Three steps, at package scale

Build your baseline from what’s actually there

Your hardware and software list, and the test plan that covers it. NESSviewer builds the software list from what the scans actually found, so it reflects the systems rather than a spreadsheet somebody last touched a year ago.

Test against it

Checklists and scans across hundreds of assets, with bulk operations that scale instead of breaking.

Prove it holds together

Confirm everything in the baseline was tested, that the results agree, and generate and maintain your eMASS POA&M and AP test results from the actual results.

Products

One free. Two that run the package.

Free, permanently

STIGreviewer

Replaces DISA STIG Viewer. Both CKL and CKLB in one application, a full inventory of your checklists, and version comparison against the current STIG library. No license key, no trial clock.

Explore STIGreviewer

Paid, with a free trial

STIGrevolution

Bulk operations across hundreds of checklists, analysis and reporting across the whole set, and an eMASS POA&M and AP test results kept in step with the results. Windows.

Explore STIGrevolution

Beta, current release still available

NESSviewer

Executive summaries, per-asset software lists derived from plugin output, port and listener enumeration, and the baseline your software list feeds. Windows.

Explore NESSviewer

The baseline, and where it is today

Your hardware and software list and test plan, in one place, populated from real data rather than a spreadsheet. It ships in the NESSviewer beta now; STIGrevolution’s next release brings the same module, and the two will share one baseline.

Before you ask

Frequently asked questions

Does my checklist or scan data leave my machine?
No. You work on local copies, and none of our applications send checklist or scan data to us. The paid products make one outbound connection, for the license check.
What network access do the applications need?
STIGreviewer needs none. NESSviewer and STIGrevolution check their license with licensing.stigsolution.com over port 443. The check carries your license key, a hashed computer ID, and the application version, never your data, and it picks up proxy settings automatically.
Can I use them on a disconnected or air-gapped network?
Yes. STIGreviewer works there with no setup, because it has no license check. NESSviewer and STIGrevolution are supported on disconnected, classified, and air-gapped networks too. They normally check their license online every 14 days, so coordinate with us at mail@stigsolution.com and we will set up licensing for your environment.
Do the applications use AI, and where does my data go?
Only if you turn it on. Every AI feature stays hidden until you connect a provider: OpenAI, Azure OpenAI, Claude, or Ollama running on your own machine. Requests go to that provider under your own account. There is no STIG Solution AI service, nothing is routed through us, and with Ollama nothing leaves your computer.
How are the applications installed?
STIGreviewer installs from a signed MSIX on Windows or a .pkg on macOS, and the NESSviewer beta from a signed MSIX. NESSviewer’s current release and STIGrevolution come as a single-file EXE that runs without installing, or as an MSIX.
Is STIGreviewer really free?
Yes, permanently. There is no license key, no trial period, no activation, and no limit on the number of computers you install it on.
How long is the free trial for the paid products?
14 days from activation for NESSviewer and STIGrevolution, with no license key needed to start.
Are you affiliated with DISA?
No. STIG Solution is an independent company, not affiliated with or endorsed by DISA or the Department of Defense. Our applications work with the file formats that DISA’s tools and eMASS use.

Quarterly STIG revision files, free

DISA publishes the revision summaries as PDFs. We parse them into JSON and Excel, with change statements that say what actually changed. The JSON loads straight into our applications.

Download the current release

Your next package can go in clean

STIGreviewer is free, permanently: no key, nothing to activate, nothing phoning home. It’s a no-commitment way to see how our applications work. When the job is the whole package, the trial runs 14 days.