STIG Viewer opens one checklist. STIGrevolution works the whole set.

Bulk operations across hundreds of checklists, analysis and reporting across all of them at once, and your eMASS POA&M and Assessment Procedure results kept in step with your testing.

Two-week free trial. Windows.

STIGrevolution showing a bulk operation across many checklists
Bulk operations across the whole estate, not one file at a time.

The problem

A server carries a dozen checklists. A package carries hundreds.

At that volume the standard tools stop being slow and start being the reason things go wrong.

You create checklists from SCAP results one at a time. You hunt for “Not Reviewed” items across hundreds of files with no way to see them at once. You correct host information one checklist at a time. And when a new STIG version drops, you find out which of your checklists went stale by opening them.

So people build their own way through: spreadsheets, PowerShell, Python. It works, right up until it doesn’t. It doesn’t scale past a certain point, it only runs if the person who wrote it is still there, and it can’t be turned into a process you could hand to anyone else.

At scale

Bulk operations that actually scale

Create checklists from SCAP output in bulk

50 SCAP results become 50 checklists in one operation, not 50.

Migrate to new STIG versions in bulk

When a quarter’s revisions land, update every affected checklist at once instead of discovering them one file at a time.

Edit across assets

Set status, finding details, and comments for multiple assets in a single pass.

Duplicate against hostname and IP lists

Stand up checklists for a whole set of systems from a list you already have.

Fill closed items automatically

Default closure statements populate finding details for items you’ve already closed.

Already using STIGreviewer?

It’s our free STIG Viewer replacement, and it edits and validates checklists at whatever scale you work at. STIGrevolution is the reporting and eMASS layer on top: analysis across the whole set, POA&M updates generated from your results, and the eMASS Assessment Procedure results that go with them.

Prove it

Find the problems before a reviewer does

Review interface

Check and correct host information, surface every “Not Reviewed” item, and find items closed with no finding details, across the whole set rather than file by file.

Analysis

Sort, filter, and group across every checklist at once, then export the view as a report rather than as raw data you still have to shape.

Compare against your eMASS POA&M

Import the POA&M alongside your CKLs and ACAS files, see where they disagree, and generate the updates.

Assessment Procedures

eMASS test results, written from your actual testing

Every Assessment Procedure in eMASS needs a test result, and the evidence behind it is spread across hundreds of checklists and scans. STIGrevolution writes them from the results you already have loaded.

Pull in every result that answers it

Any loaded result tied to a CCI, AP, or control counts, compliant or not, from STIG checklists and ACAS alike. Policy and procedural APs draw from a policy results file you create and edit locally, like a checklist.

In your order, in your words

Choose the order results are listed in and add text before and after them: the standard wording you’d otherwise paste into hundreds of APs by hand, one at a time.

Written to fit the field

Technical results are aggregated per check: ID, STIG, title, and “12 of 14 hosts compliant.” Each result is capped at 4,000 characters, the size of the eMASS field, and edited down to fit when the full listing won’t.

When eMASS and the POA&M disagree

Load your eMASS test result export beside the POA&M, and STIGrevolution shows every place they’re out of sync, and can generate a test result import that brings them back in line.

Before you ask

What running this actually involves

Windows executable or MSIXA single-file EXE that runs without installing, or an MSIX package for managed deployment. Your choice.
You work on local copiesYour checklist data stays on your machine.
One outbound connectionThe license check, over 443. It carries a computer ID and your license key, not your data, and it picks up proxy settings automatically.
Free trialTwo weeks on activation, no license key required to start.
Platform
Windows 10, 11, Server 2012 R2, 2016, 2019
Runtime
.NET Framework 4.7.1 or higher
Formats
CKL, CKLB, and policy results files
Imports
SCAP output, ACAS files, eMASS POA&M, eMASS test result export
Exports
Excel reports, POA&M updates, eMASS test result import
License
365 days from date of purchase

Next

What’s coming

The next release of STIGrevolution moves to .NET MAUI, adds macOS, and brings the same baseline module as NESSviewer: your hardware and software list and test plan, shared between the two applications. It enters beta after NESSviewer’s.

Your next package can go in clean

Interested in licensing? Contact us atmail@stigsolution.com. Purchase is subject to the Terms of Use and EULA; see licensing for how activation works.