Directory

The SecBaseline suite

Each tool covers one standard and speaks the same language as the rest. Live tools are available now; the remainder are in development.

DISA STIG

STIG Explainer

Translates DISA STIG findings into plain English — what the rule checks, why it matters, the risk, and how to fix it. Maps findings to NIST 800-53 via CCI and prioritizes imported scan results.

Open STIG Explainer

CIS Benchmarks

CIS Benchmark Explainer

Explains CIS Benchmark recommendations in plain English, including operational impact. Maps to CIS Controls and prioritizes findings across Linux, Windows, cloud, and Kubernetes.

Open CIS Benchmark Explainer

POA&M tracking

POAM Guardian

In development

Tracks Plan of Action and Milestones items from open finding through closure, with owners, due dates, and the evidence attached to each remediation.

CMMC

CMMC Compass

In development

Walks defense suppliers through CMMC readiness, showing which practices are met by existing baselines and which still need work before an assessment.

System Security Plans

SSP Ally

In development

Drafts and maintains System Security Plans from your control set, keeping narratives in sync with the baselines actually applied to each system.

OSCAL

Oscal Bridge

In development

Converts baselines, control catalogs, and assessment results to and from OSCAL so machine-readable compliance artifacts stay portable between tools.