Local-first ATO workbench for ISSOs and small defense contractors.

What CompliNIST does for your ATO package

Import Terraform or build your topology → map control narratives → export an SSP PDF your assessor can review.

Network topology canvas

Drag-and-drop network diagramming. Place devices, draw connections and security boundaries, then export the result as a PNG, CSV, or JSON. The topology feeds directly into SSP generation — your diagrams become part of the document, not a separate artifact you paste in later.

  • • 1,700+ device icons including Azure and AWS services
  • • Security boundary drawing (DMZ, internal, external zones)
  • • Zoom, pan, multi-selection, and configurable canvas dimensions
  • • Bulk device import via CSV and Terraform import
  • • Undo/redo and real-time visual feedback

SSP generation

One-click PDF generation following NIST SP 800-53 Rev 5. The output includes a cover page, table of contents, executive summary, system description, control implementations with narratives, architecture diagrams, and appendices. Narratives are topology-aware — they reference the actual devices and boundaries in your project.

  • • Three baselines: LOW (~50 controls), MODERATE (~140), HIGH (~200+)
  • • All 20 NIST control families covered
  • • Formatted for RMF authorization workflows

Control narrative editor

Edit individual NIST control narratives, customize implementations per system, and link controls to specific devices in your topology. Track status across your control set and export the results into your SSP or as standalone documentation.

  • • Rich text editing with per-control customization
  • • Control status tracking (Not Started, In Progress, Complete)
  • • Link controls to specific devices and boundaries
  • • Templates and topology-based suggestions (manual editing)

Device and project management

Each device carries detailed properties — name, type, OS, IP/MAC, ports, risk level, compliance tags, and hardware/software inventory. Projects are self-contained with their own baselines, devices, and connections. Export or import entire projects as JSON.

  • • Bulk CSV import and bulk property editing
  • • Multi-project workspace with per-project baselines
  • • Search, filter, and group devices
  • • Export as PNG, CSV, JSON, or PDF

How it's built

Docker

Docker deployment

CompliNIST runs as a Docker container on Windows, macOS, or Linux. Pull ghcr.io/stihelc/complinist-lite:lite from GitHub Container Registry and open the app in your browser at localhost:3000. All data is stored in a local SQLite database inside the container volume — no cloud account required. The app works fully offline once the image is pulled — you don't need an internet connection to build topologies or generate SSPs.

Pricing

Turn infrastructure into assessor-ready SSP packages — topology, control narratives, and NIST 800-53 PDF without Word-and-Visio copy-paste. The full workbench is free to run locally. Optional priority support ($20/mo — early supporter pricing while we onboard teams. increases as support demand grows.) adds direct help with import, SSP structure, and review prep — not required for any compliance feature.

Stop assembling SSPs in Word and Visio