Local-first ATO workbench for ISSOs and small defense contractors.
Import Terraform or build your topology → map control narratives → export an SSP PDF your assessor can review.
Runs locally on your machine. No cloud sync. No telemetry.
Free to run · No credit card · Works offline after pull

Every feature is purpose-built for NIST SP 800-53 Rev 5 with LOW, MODERATE, and HIGH baselines — so your documentation is aligned with FedRAMP and the Risk Management Framework from the start.
Drag-and-drop network diagramming with device placement, security boundaries, and connection routing
Import from Terraform plans to build diagrams from your existing infrastructure
Visual annotations and boundary drawings that map directly to your SSP
Export diagrams as PNG, SVG, CSV, or JSON for inclusion in authorization packages
Bulk operations for managing large system topologies efficiently

Generate complete SSP documents aligned with NIST SP 800-53 Rev 5
Supports LOW, MODERATE, and HIGH baselines with full control family coverage
Narratives are linked to your actual topology — assessors can trace evidence back to your system
Consistent formatting across all 20 control families, ready for review
Formatted for RMF authorization workflows (FedRAMP, agency ATO packages)

Edit individual NIST 800-53 control implementations with templates and topology-based suggestions
Link control narratives to specific devices and boundaries in your diagram
Manual editing workflow — you review and approve everything before it goes into the SSP

Track device properties including type, manufacturer, model, OS, and network addresses
PPSM tab for ports, protocols, and services per device
Maintain SSP metadata like system categorization and impact levels alongside your inventory
Bulk import via CSV and bulk editing for large environments
Supports 1,700+ device icons including Azure, AWS, and network gear

Your topology, SSPs, control narratives, and inventories stay in a local Docker volume — no cloud sync or telemetry
Works fully offline after the image is pulled — ideal for air-gapped and classified environments
Open localhost:3000 in your browser; data stored in SQLite inside the container
No external services required for day-to-day documentation work
ghcr.io/stihelc/complinist-lite:lite
Open in your browser at localhost:3000
Real scenarios from organizations that used CompliNIST to produce better authorization packages in less time.
A small contractor supporting a DoD system needed a MODERATE baseline SSP. Their ISSO imported existing infrastructure, built the topology, and produced a reviewable SSP package in two weeks — cutting months off the typical authorization timeline.
Use Case, DoD RMF Authorization
A health IT organization needed NIST 800-53 documentation but couldn't send network diagrams to an external tool. They ran CompliNIST on a locked-down workstation, built the topology locally, and produced documentation that satisfied both their HIPAA and NIST audit requirements.
Use Case, HIPAA + NIST Crosswalk
A mid-size integrator preparing a FedRAMP Moderate package used CompliNIST to produce control narratives tied to their actual cloud architecture. Instead of starting 300+ narratives from scratch, the team focused on reviewing and refining narratives in the editor — and submitted a higher-quality package.
Use Case, FedRAMP Moderate Package
Most teams either spend six figures on consultants or burn months cobbling together Word documents and Visio diagrams. Here's how that changes.
| Traditional Approach | With Complinist |
|---|---|
| Word docs + Visio diagrams (disconnected) | Topology, inventories, and SSP in one tool |
| 3–6 months per authorization package | Weeks, not quarters |
| Writing narratives from scratch | Draft, review, and refine with built-in tools |
| Sensitive data uploaded to cloud tools | Everything stays on your machine |
| $50K+ in consultant fees | A fraction of the cost |
| Documentation outdated by the time it's reviewed | Diagrams and narratives stay linked and current |
Free to run locally. No credit card required.
Everything you need to get started with CompliNIST — from setup to generating your first SSP.
Installation, setup, and your first ATO documentation project in minutes.
Drag-and-drop network diagrams with 1,700+ device icons and security boundaries.
Generate network diagrams and compliance docs from your Infrastructure as Code.
Generate System Security Plans across NIST 800-53 LOW, MODERATE, and HIGH baselines.
Map NIST 800-53 controls to system components and write implementation narratives in the built-in editor.
Manage hardware and software inventories. Import via CSV, link to topology diagrams.
Export as PDF, PNG, SVG, JSON, and CSV for RMF authorization workflows.
Common issues, solutions, performance tips, and frequently asked questions.
Practical guides on NIST 800-53 implementation, control narratives, and RMF compliance.
Learn exactly what assessors look for, see real before-and-after examples across four control families, and use a repeatable template.
In-depth guide to the RMF ATO process. Learn how to get an ATO, understand RMF steps, and avoid costly authorization delays.
Includes control narrative examples, diagram alignment guidance, and an internal SSP review checklist.
Common questions from teams preparing authorization packages and audit documentation.
Use the control narrative editor to write and edit implementations for each NIST 800-53 control. Templates and topology-based suggestions help you get started; you review and approve everything before it goes into the SSP.
You build your system topology (drag-and-drop or Terraform import), configure device properties, and write your control narratives. When you're ready, CompliNIST assembles everything into a formatted PDF aligned with NIST 800-53 Rev 5. Supports LOW, MODERATE, and HIGH baselines.
NIST SP 800-53 Rev 5, SP 800-37, SP 800-171, FedRAMP requirements, and RMF guidance documents. The drafting tools are grounded in these authoritative sources so your documentation aligns with published standards — not generic security advice.
CompliNIST runs in a Docker container on your machine. Open localhost:3000 in your browser. Your topology, narratives, inventories, and all project data stay in a local volume—no cloud accounts, no data uploads, no external API calls. Suitable for air-gapped networks and environments with data sovereignty requirements.
Yes. After you pull the Docker image, the app runs fully offline. Topology, narratives, SSP PDF export, and all exports work without network connectivity. A subscription license code is optional and not required to use features.
NIST 800-53 is the primary focus — that's what the SSP generator, control editor, and narrative tools are built around. The topology and documentation features are also useful for FedRAMP, SOC 2, and HIPAA packages, though you'd apply your own control mappings for those frameworks.
A FedRAMP authorization typically costs $50K–$200K in consulting fees plus months of your team's time. CompliNIST handles the mechanical work — topology-linked narratives with templates, diagram exports, and SSP PDF assembly. You still need security expertise to validate the content, but you're not paying someone to format it in Word.
Optional priority support ($20/mo — early supporter pricing while we onboard teams. increases as support demand grows.) gives you direct email help with Terraform import, SSP structure, and review prep, plus license code delivery and billing management. It does not unlock app features — the full ATO workbench is included when you run the Docker image locally.