Local-first ATO workbench for ISSOs and small defense contractors.

Cut SSP prep from
weeks to days.

Import Terraform or build your topology → map control narratives → export an SSP PDF your assessor can review.

Runs locally on your machine. No cloud sync. No telemetry.

Free to run · No credit card · Works offline after pull

Complinist ATO documentation workbench — topology, control narratives, and SSP export

Built Around NIST 800-53

Every feature is purpose-built for NIST SP 800-53 Rev 5 with LOW, MODERATE, and HIGH baselines — so your documentation is aligned with FedRAMP and the Risk Management Framework from the start.

NIST 800-53 Rev 5FedRAMPRMF

System Topology Diagrams

Drag-and-drop network diagramming with device placement, security boundaries, and connection routing

Import from Terraform plans to build diagrams from your existing infrastructure

Visual annotations and boundary drawings that map directly to your SSP

Export diagrams as PNG, SVG, CSV, or JSON for inclusion in authorization packages

Bulk operations for managing large system topologies efficiently

Screenshot of Complinist system topology diagrams feature for NIST 800-53 compliance

Assessor-Ready SSP Generation

Generate complete SSP documents aligned with NIST SP 800-53 Rev 5

Supports LOW, MODERATE, and HIGH baselines with full control family coverage

Narratives are linked to your actual topology — assessors can trace evidence back to your system

Consistent formatting across all 20 control families, ready for review

Formatted for RMF authorization workflows (FedRAMP, agency ATO packages)

Screenshot of Complinist assessor-ready ssp generation feature for NIST 800-53 compliance

Control Narrative Editor

Edit individual NIST 800-53 control implementations with templates and topology-based suggestions

Link control narratives to specific devices and boundaries in your diagram

Manual editing workflow — you review and approve everything before it goes into the SSP

Screenshot of Complinist control narrative editor feature for NIST 800-53 compliance

Hardware & Software Inventories

Track device properties including type, manufacturer, model, OS, and network addresses

PPSM tab for ports, protocols, and services per device

Maintain SSP metadata like system categorization and impact levels alongside your inventory

Bulk import via CSV and bulk editing for large environments

Supports 1,700+ device icons including Azure, AWS, and network gear

Screenshot of Complinist hardware & software inventories feature for NIST 800-53 compliance

Runs Locally in Docker

Your topology, SSPs, control narratives, and inventories stay in a local Docker volume — no cloud sync or telemetry

Works fully offline after the image is pulled — ideal for air-gapped and classified environments

Open localhost:3000 in your browser; data stored in SQLite inside the container

No external services required for day-to-day documentation work

Docker

ghcr.io/stihelc/complinist-lite:lite

Open in your browser at localhost:3000

How Teams Get to ATO Faster

Real scenarios from organizations that used CompliNIST to produce better authorization packages in less time.

A small contractor supporting a DoD system needed a MODERATE baseline SSP. Their ISSO imported existing infrastructure, built the topology, and produced a reviewable SSP package in two weeks — cutting months off the typical authorization timeline.

Defense Contractor ISSO

Use Case, DoD RMF Authorization

A health IT organization needed NIST 800-53 documentation but couldn't send network diagrams to an external tool. They ran CompliNIST on a locked-down workstation, built the topology locally, and produced documentation that satisfied both their HIPAA and NIST audit requirements.

Healthcare Compliance Team

Use Case, HIPAA + NIST Crosswalk

A mid-size integrator preparing a FedRAMP Moderate package used CompliNIST to produce control narratives tied to their actual cloud architecture. Instead of starting 300+ narratives from scratch, the team focused on reviewing and refining narratives in the editor — and submitted a higher-quality package.

Federal Systems Integrator

Use Case, FedRAMP Moderate Package

What This Replaces

Most teams either spend six figures on consultants or burn months cobbling together Word documents and Visio diagrams. Here's how that changes.

Traditional ApproachWith Complinist
Word docs + Visio diagrams (disconnected)Topology, inventories, and SSP in one tool
3–6 months per authorization packageWeeks, not quarters
Writing narratives from scratchDraft, review, and refine with built-in tools
Sensitive data uploaded to cloud toolsEverything stays on your machine
$50K+ in consultant feesA fraction of the cost
Documentation outdated by the time it's reviewedDiagrams and narratives stay linked and current
Start Your ATO Package

Free to run locally. No credit card required.

Frequently Asked Questions

Common questions from teams preparing authorization packages and audit documentation.

01

How does CompliNIST help with control narratives?

Use the control narrative editor to write and edit implementations for each NIST 800-53 control. Templates and topology-based suggestions help you get started; you review and approve everything before it goes into the SSP.

02

How does SSP generation work?

You build your system topology (drag-and-drop or Terraform import), configure device properties, and write your control narratives. When you're ready, CompliNIST assembles everything into a formatted PDF aligned with NIST 800-53 Rev 5. Supports LOW, MODERATE, and HIGH baselines.

03

What guidance is the tool built around?

NIST SP 800-53 Rev 5, SP 800-37, SP 800-171, FedRAMP requirements, and RMF guidance documents. The drafting tools are grounded in these authoritative sources so your documentation aligns with published standards — not generic security advice.

04

What does 'runs locally' mean?

CompliNIST runs in a Docker container on your machine. Open localhost:3000 in your browser. Your topology, narratives, inventories, and all project data stay in a local volume—no cloud accounts, no data uploads, no external API calls. Suitable for air-gapped networks and environments with data sovereignty requirements.

05

Does it work offline and in air-gapped environments?

Yes. After you pull the Docker image, the app runs fully offline. Topology, narratives, SSP PDF export, and all exports work without network connectivity. A subscription license code is optional and not required to use features.

06

Which compliance frameworks are supported?

NIST 800-53 is the primary focus — that's what the SSP generator, control editor, and narrative tools are built around. The topology and documentation features are also useful for FedRAMP, SOC 2, and HIPAA packages, though you'd apply your own control mappings for those frameworks.

07

How does this compare to hiring a consultant?

A FedRAMP authorization typically costs $50K–$200K in consulting fees plus months of your team's time. CompliNIST handles the mechanical work — topology-linked narratives with templates, diagram exports, and SSP PDF assembly. You still need security expertise to validate the content, but you're not paying someone to format it in Word.

08

What does the optional subscription include?

Optional priority support ($20/mo — early supporter pricing while we onboard teams. increases as support demand grows.) gives you direct email help with Terraform import, SSP structure, and review prep, plus license code delivery and billing management. It does not unlock app features — the full ATO workbench is included when you run the Docker image locally.