RMF packages that go in right the first time

Tools that keep your checklists, your scan results, and your eMASS POA&M in agreement, so the package doesn’t come back.

Works with what you already have

  • CKL
  • CKLB
  • SCAP
  • .nessus
  • ACAS
  • eMASS POA&M
  • eMASS test results
  • Evaluate-STIG answer files
Checklists on a single Windows server
6-12
Checklists in a typical package
Hundreds

The problem

Hundreds of checklists. Spreadsheets and scripts holding it together.

Everyone doing this work has built their own way through it: spreadsheets, PowerShell, Python, whatever could be cobbled together. It works, right up until it doesn’t.

It doesn’t scale

What handles 40 checklists fails at 400.

It takes a scripting skill set

The work ends up gated behind whoever on the team can write the scripts, and it leaves with them.

It isn’t a process

Nothing repeatable, nothing you can document, nothing you can hand to someone new.

How it goes wrong

The parts stop agreeing, and you have no way of knowing

The hardware and software list stops matching what was actually tested. The POA&M stops matching the results behind it. You find out when a reviewer does.

BaselineHardware and software list, test plan
TestingChecklists and scans, across hundreds of assets
POA&MGenerated from the actual results
Each step feeds the next, and the POA&M has to trace back to the baseline it started from. Nothing in the standard toolchain closes that loop.

What it costs

Rework is the expensive part

A package that comes back isn’t a scheduling inconvenience. It’s re-testing, re-documenting, and re-submitting, while the ATO date moves and everyone waits on you.

The mistakes that cause it are rarely dramatic. A system in the baseline that never got tested. A POA&M entry that doesn’t match the finding it came from. A checklist still on last quarter’s version. Small, individually invisible, and expensive in aggregate.

Who we are

We built the tools we needed

STIG Solution builds applications for the people who assemble RMF packages. Not checklist editors with extra features, but tools built around how the work actually runs: establish a baseline, test against it, prove the results agree, and keep the POA&M current.

We also publish the quarterly DISA STIG revision summaries, parsed into JSON and Excel, free to anyone who wants them. We’ve done it every quarter for five years, and we’ll keep doing it whether you ever buy anything.

How it works

Three steps, at package scale

Build your baseline from what’s actually there

Your hardware and software list, and the test plan that covers it. NESSviewer builds the software list from what the scans actually found, so it reflects the systems rather than a spreadsheet somebody last touched a year ago.

Test against it

Checklists and scans across hundreds of assets, with bulk operations that scale instead of breaking.

Prove it holds together

Confirm everything in the baseline was tested, that the results agree, and generate and maintain your eMASS POA&M and AP test results from the actual results.

Products

One free. Two that run the package.

Free, permanently

STIGreviewer

Replaces DISA STIG Viewer. Both CKL and CKLB in one application, a full inventory of your checklists, and version comparison against the current STIG library. No license key, no trial clock.

Explore STIGreviewer

Paid, with a free trial

STIGrevolution

Bulk operations across hundreds of checklists, analysis and reporting across the whole set, and an eMASS POA&M and AP test results kept in step with the results. Windows.

Explore STIGrevolution

Beta, current release still available

NESSviewer

Executive summaries, per-asset software lists derived from plugin output, port and listener enumeration, and the baseline your software list feeds. Windows.

Explore NESSviewer

The baseline, and where it is today

Your hardware and software list and test plan, in one place, populated from real data rather than a spreadsheet. It ships in the NESSviewer beta now; STIGrevolution’s next release brings the same module, and the two will share one baseline.

Before you ask

What running this actually involves

Signed installersSTIGreviewer: MSIX on Windows, .pkg on macOS. NESSviewer beta: MSIX on Windows. NESSviewer’s current release and STIGrevolution: a single-file Windows EXE that runs without installing, or an MSIX.
You work on local copiesChecklists and scan data stay on your machine.
AI is off until you turn it onEvery AI feature stays hidden until you connect a provider. Choose OpenAI, Azure OpenAI, Claude, or Ollama running locally on your own machine. With Ollama, nothing leaves your computer.
We’re never in the middleYour key, your provider account. There is no STIG Solution AI service and nothing is routed through us.
One outbound connectionThe license check, over 443. It carries a computer ID and your license key. It does not carry your data, and it picks up proxy settings automatically.

Quarterly STIG revision files, free

DISA publishes the revision summaries as PDFs. We parse them into JSON and Excel, with change statements that say what actually changed. The JSON loads straight into our applications.

Download the current release

Your next package can go in clean

STIGreviewer is free, permanently: no key, nothing to activate, nothing phoning home. It’s a no-commitment way to see how our applications work. When the job is the whole package, the trial runs 14 days.