Bastion walks defense suppliers through all 110 NIST 800-171 controls, calculates your live DoD SPRS score, and generates an audit-ready SSP and POA&M — entirely in your browser.
DoD CMMC enforcement went live in November 2025, and primes like Boeing now make CMMC Level 2 a condition of contract award. For small and mid-size suppliers, that means proving compliance against 110 NIST 800-171 controls — often with no GRC staff and no budget for a six-figure consulting engagement. Miss it, and the contracts you depend on go to a supplier who didn't.
One tool takes you from "where do we even start?" to a documented, scored, defensible posture.
Step through every NIST 800-171 control in plain language, with practical guidance on what each one means for your shop.
Your Supplier Performance Risk System score updates in real time using the official DoD weighted methodology — no spreadsheet math.
See exactly where you stand across all 14 control families so you fix the highest-impact gaps first.
Turn your answers into a complete System Security Plan documenting how each control is implemented — the artifact every assessor expects.
Every open control becomes a Plan of Action & Milestones entry with an owner and target date, so remediation is tracked, not forgotten.
Organize the proof behind each control — policies, configs, logs — so you're ready the day an assessor asks.
Hand your prime, assessor, or team clean, portable artifacts in the format they need.
Bastion executes locally. Your CUI, evidence, and assessment never leave your device — there's no server to trust.
Bastion auto-evidences controls from the tools you already run — so your score reflects real, current data, not stale screenshots.
Pulls live endpoint posture — encryption, patching, MFA, EDR, and logging — to auto-evidence your technical controls with real, current data.
Links your policies, procedures, and training records to the controls they satisfy, auto-evidencing the documentation controls assessors scrutinize most.
◆Accurate by design. SPRS scoring follows the official DoD weighted methodology — the number you see is the number that counts.
◆Artifacts in minutes. Audit-ready SSP and POA&M generated in minutes, not the weeks a consultant would bill for.
◆Your CUI stays put. Fully local execution — no cloud upload, no third party holding your sensitive data.
◆Priced for your shop. A straightforward licence — see your SPRS score and get audit-ready without a six-figure consulting engagement.
No six-figure consultant, no CUI leaving your machine. Just an accurate score and audit-ready artifacts.