The STIG Viewer replacement you’ve been waiting for
DISA STIG Viewer was built to check a box. STIGreviewer was built to make your job easier: everything STIG Viewer does, and more, free.
No license key. No trial period. Free permanently.

The problem
If you’ve spent any time doing real STIG work, you know the pain
- You need one version of STIG Viewer for CKL files and a different version for CKLB, because a single tool can’t handle both.
- There is no inventory. You open files one at a time, with no way to see what you have at a glance.
- When a new STIG version drops, you don’t have an easy way to know which of your checklists are out of date.
- You can’t see your eMASS POA&M findings alongside your checklists, so you’re constantly switching windows.
- There is no way to see what actually changed between STIG versions without manually comparing them.
You weren’t hired to fight with your tools. You were hired to do cyber security work.
Who we are
We’ve been there, so we built something better
We build tools for the people who actually do this work, not for the people who write the requirements. STIGreviewer is the answer to a simple question: what would DISA STIG Viewer look like if it were designed by the people who actually used it?
What it does
Everything you need. Nothing you have to put up with.
Checklist inventory, CKL and CKLB in one app
Edit both CKL and CKLB checklists in a single application. No more hunting down the right version of STIG Viewer for the file format you’re working with.
Load your files and immediately see a full inventory of your checklists, all in one place, without opening them one at a time.
Demo
eMASS POA&M integration
Load your eMASS POA&M alongside your checklists so you can see existing findings as you edit. No more switching back and forth from spreadsheets to STIG Viewer.
Demo
STIG library comparison
Load the latest STIGs from DISA via the STIG Library page and instantly see which of your checklists have newer versions available.
Demo
Revisions file support
Load the revisions file from stigsolution.com and see exactly what changed between versions of a checklist.
Demo
Single-click version update
When editing a checklist, upgrade it to the latest STIG version in a single click. No manual migration, no copy-paste.
Demo
Single-click CKL to CKLB
Convert a CKL checklist to the newer CKLB format in one click. Move to the modern format without starting from scratch.
Demo
Reusable notes for STIGs
Store reusable STIG notes that load in every checklist for that STIG.
Demo
Auto-fill that leaves the judgment with you
Auto-fill drafts finding details, comments, and notes. Nothing it produces reaches a checklist on its own: you click Add or Apply. It removes the blank page; the call stays yours.
Optionally, it can fill Finding Details the moment you set a status, for working through items in bulk. That one writes directly and overwrites the field, so it ships switched off.
AI is opt-in throughout. Connect OpenAI, Azure OpenAI, Claude, or Ollama on your own machine. Until you do, none of these buttons appear.
Demo
Quality gate
It tells you what’s wrong before a reviewer does
Load your checklists and STIGreviewer checks them against rules you set: green, amber, or red across everything you have open, with the detail a click away.
Outdated STIG versions
Which of your checklists are built on a STIG that has since been superseded.
STIGs missing from your library
Checklists built on a STIG you don’t hold. Flagged beside outdated versions, so you know whether you have a STIG to compare against before you verify or update.
Missing host information
Exactly which fields are missing on which hosts. You choose what counts as required: hostname, IP, MAC, FQDN.
Severity overrides
Items carrying an override when your rules don’t permit them.
You decide what counts as a problem
Business Rules set the standard once (which host fields are mandatory, whether severity overrides are permitted, what counts toward completion), and every checklist you open is measured against it. That’s the difference between a house style and a rule that actually holds.
Also included
The things you’d otherwise do by hand
Combine checklists
Combine the checklists you select into a single file, such as every STIG for one host. Then choose whether to unload the originals, and whether to delete them from disk.
Split multi-STIG checklists
Split a checklist that carries several STIGs back into one file per STIG, with the same choice about the originals afterward.
Evaluate-STIG answer files
Open, create, and edit Evaluate-STIG answer files beside the checklist you’re reviewing, instead of hand-editing XML. They stay separate files, so editing one never touches your CKL or CKLB.
Export for reporting
PDF for a printable report, Word for something editable, Excel or CSV for analysis. Exporting is separate from saving; your checklist on disk is kept current by autosave.
Your own STIG library
Hold DISA STIG XML locally. It drives new checklist creation, version refreshes, and the flagging of checklists whose STIG you don’t have.
Load however you’ve got them
Individual files, whole folders, ZIP archives, or drag and drop. Your last session reopens automatically.
Side by side
What you get that STIG Viewer doesn’t give you
| DISA STIG Viewer | STIGreviewer | |
|---|---|---|
| CKL and CKLB in one application | Separate versions | Yes |
| Checklist inventory at a glance | One file at a time | Yes |
| See which checklists are out of date | Manual comparison | Yes |
| eMASS POA&M alongside your checklists | No | Yes |
| See what changed between STIG versions | Manual comparison | Yes |
| Single-click version update | No | Yes |
| Single-click CKL to CKLB conversion | No | Yes |
| Runs on macOS | Windows and Linux only | Yes |
| Price | Free | Free |
Before you ask
Frequently asked questions
- Is STIGreviewer free?
- Yes, permanently. There is no license key, no trial period, no activation, and no limit on the number of computers you install it on.
- Does STIGreviewer send anything to STIG Solution?
- No. It has no license check, and your checklists stay on your machine. It only reaches out if you connect an AI provider, and then only to that provider.
- Can it replace DISA STIG Viewer?
- Yes. It opens and edits both CKL and CKLB checklists in one application, so you no longer need a different STIG Viewer version for each format.
- What can I load?
- CKL and CKLB checklists one at a time, a whole folder, or ZIP archives, including nested ZIPs. It can also create new checklists from SCAP results.
- Where does my data go if I use the AI features?
- To the provider you connect, under your own account: OpenAI, Azure OpenAI, Claude, or Ollama running on your own machine. Your key is kept in your operating system’s secure storage. There is no STIG Solution AI service, and with Ollama nothing leaves your computer.
- What does it need to run on Windows?
- Windows 10 version 1809 or later, Windows 11, or Windows Server 2019 or later, 64-bit. It installs from a signed MSIX and uninstalls completely.
- Is it usable for low-vision users?
- It has 28 themes across light, dark, mid-contrast, and high-contrast families, including WCAG AA high-contrast options for low-vision use.
Going further
When the unit of work becomes the package
STIGreviewer edits one checklist at a time. STIGrevolution edits them in bulk, and runs the package around them: analysis across the whole set, the eMASS POA&M built from your results, and the Assessment Procedure (AP) results that go with it.
Get a better STIG Viewer today. And keep it.
Free permanently. No license key, no trial period, no catch.