MDS
ATO Insight
Know before you go.
Edition
Lightweight
Lightweight
Standard
Enterprise
Field Edition
Collect with confidence.
Hand off with clarity.
Assessment work doesn’t always happen in one place. The Lightweight Edition is built for the Compliance Assessor in the field — at a remote site, in an air-gapped enclave, or on-site with a customer. Point it at your checklists, extract standardized compliance data, and hand off a clean package. No server. No database. No complexity.
Designed for
  • Compliance Assessors (ISSOs) working on-site or at remote and air-gapped facilities
  • Contractors collecting checklist data across multiple customer sites
  • Assessment teams who collect data but don’t manage the ATO boundary
  • Anyone who needs a clean, portable assessment deliverable to hand up the chain
No server. No infrastructure. No additional ATO. Most platforms that manage your ATO process require dedicated web and database server infrastructure — and their own accreditation before you can use them to manage yours. “The irony of needing an ATO for your ATO tool is real. ATO Insight sidesteps it entirely.”
📋

Compliance Checklist Extraction

Reads CKL, CKLB, and XCCDF format checklists produced by STIGViewer, Evaluate-STIG, SCC, STIG Manager, and compatible assessment tools.

📦

Portable Output Packages

Produces standardized data packages ready for handoff. Standard and Enterprise users ingest them directly — no reformatting, no manual consolidation.

✈️

Air-Gap Compatible

No network access required. No cloud dependencies. Runs as a single local application on any Windows system in any environment, including classified networks.

🛰️

Scan-Seeded Discovery

No inventory list? Drop in a non-credentialed scan and get a proposed set of targets — hostnames, IPs, OS fingerprint — plus the checklists each system likely needs (a web server calls for the OS, IIS Server and IIS Site STIGs, not just one). Confirm and collect.

🧩

Coverage Gap Detection

Compares what you actually collected against what each system should have, and flags the checklist you didn’t run — the missing IIS Site, SQL instance, or OS STIG — before the AO finds it for you.

📊

Assessment Snapshot Report

Generates a printable summary of findings — system inventory, raw CAT counts by environment, compliance families covered — as a field deliverable.

🔄

Always Current — Quarterly Release Cycle

Active subscriptions include updated releases aligned with DISA quarterly STIG drops, CISA guidance updates, and NIST framework revisions. If checklists reference controls that don’t match the current benchmark, you’ll see it immediately. Download the latest version under your active license — no network connection required.

The Compliance Assessor’s job is to collect and assess — not manage the boundary picture. Lightweight handles the collection side cleanly so that whoever manages the ATO boundary gets consistent, standardized data regardless of where or how the assessment work was done.

Field collection is rarely clean or complete on the first pass. Lightweight is built for exactly that reality — point-and-shoot, no setup required, and no penalty for not having every answer up front.
Contract Assessor · Remote Site
Collect in passes, not all at once
“They dispatch me to a facility with credentials and access, but I can’t hit every system in one visit. Today it’s the web servers; tomorrow it’s the boxes in the comms closet. I run collection in passes — pick up where I left off, add systems as I reach them, and never lose what I already gathered.”
ISSO · Undocumented Enclave
No inventory? Start from a scan.
“Nobody handed me a hardware list. I start from an ACAS or non-credentialed scan — IPs, NetBIOS names, FQDNs, OS fingerprints — and let that become my starting inventory. As real checklists come in, the picture fills itself in. I don’t need every answer up front to make progress.”
This edition
Lightweight
  • ✓ CKL, CKLB & XCCDF extraction
  • ✓ Standardized output packages
  • ✓ Air-gap compatible
  • ✓ Assessment snapshot report
  • – Full analytics dashboard
  • – Scanner import & trend tracking
Upgrade to
Standard
  • ✓ Includes Lightweight Edition license
  • ✓ Full analytics dashboard
  • ✓ Multi-run trend tracking
  • ✓ Tenable/ACAS & Qualys import
  • ✓ Pre-submission readiness
  • ✓ On-demand report suite
Also available
Enterprise
  • ✓ Everything in Standard + Lightweight Edition licenses
  • ✓ Multi-boundary roll-up
  • ✓ Cross-boundary queries
  • ✓ Boundary consolidation
  • ✓ Comprehensive flexible reports
  • ✓ Conflict detection
MDS
ATO Insight
Know before you go.
Edition
Standard
Lightweight
Standard
Enterprise
Standard Edition
Know before you go
into eMASS.
eMASS, CSAM, and similar GRC platforms are systems of record — not analytics tools. ATO Insight Standard gives you the clear picture of where you stand before you’re inside the package under deadline pressure. See every finding across every system, track what changed since the last assessment, and confirm your readiness — all from a single file that runs on the laptop you’re already using.
Designed for
  • Compliance Assessors (ISSOs) managing day-to-day assessment and checklist work
  • Security Managers (ISSMs) overseeing one or more ATO boundaries
  • Assessment teams preparing packages for submission to eMASS, CSAM, or equivalent
  • Anyone who needs the fleet-wide view that single-checklist tools can’t provide
No server. No infrastructure. No additional ATO. Server-based assessment management platforms require dedicated web and database infrastructure — and their own accreditation before you can use them to manage yours. “The irony of needing an ATO for your ATO tool is real. ATO Insight sidesteps it entirely.”
📊

Fleet-Wide Analytics Dashboard

Every finding across every system in one view. Filter by environment, system type, and severity. Drill from fleet summary to individual system findings in seconds.

📈

Multi-Run Trend Tracking

Load multiple assessment runs and see exactly how posture changes over time. New findings, closed findings, systems that improved or regressed — all tracked automatically.

🛰️

Scan-Seeded Discovery & Coverage

Build your target list straight from a discovery scan — OS fingerprint and open ports suggest the checklists each system needs — then track coverage gaps fleet-wide against it. Scan age is surfaced, so a stale snapshot never passes for current posture.

🎯

Pre-Submission Readiness Checklist

A structured go/no-go list before entering eMASS or CSAM. Open CAT-I count, unreviewed findings, coverage gaps, stale checklists — computed automatically from your data.

🔍

Vulnerability Scan Correlation

Import results from Tenable/ACAS, Qualys, and other major scanners via standard CSV export. Scan findings shown alongside checklist data — kept visually distinct, never conflated.

🗂️

Unlimited ATO Boundaries

One license covers every boundary you manage. Switch between them instantly — each maintains its own independent database and full assessment history.

📄

On-Demand Report Suite

Executive Brief, Full Assessment Report, Trend Summary, and Remediation Priority Report — generated on demand as print-ready HTML/PDF. No additional software required.

🔄

Always Current — Quarterly Release Cycle

Active subscriptions include updated releases aligned with DISA quarterly STIG drops, CISA guidance updates, and NIST framework revisions. If checklists reference controls that don’t match the current benchmark, you’ll see it immediately. Download the latest version under your active license — no network connection required.

ATO Insight does not touch eMASS, CSAM, or any GRC platform. It doesn’t replace STIGViewer, manage your POA&Ms, or upload anything anywhere. It shows you — clearly and locally — what your compliance posture actually looks like before you enter the systems that are notoriously difficult to navigate. Think of it as your pre-flight check.

One ATO boundary, one database — spanning every tier you own: PROD, TEST, TRAIN, DEV, and a COOP site three states away. Standard gives the ISSM and ISSO the fleet-wide answer before deadline pressure makes it expensive to be surprised.
ISSM · Single ATO Boundary
Know the answer before eMASS asks
“Before I open the package under a deadline, I want to know exactly where I stand — open CAT-Is, unreviewed checks, stale benchmarks — across every environment including my COOP site. One boundary, one database, the whole fleet in a single view. I walk in already knowing the answer instead of discovering it in the system of record.”
ISSO · Mixed Windows Fleet
Find the checklists you never got
“I told my admins to run STIGs against every system — but I got the OS checklist for a web box and never got its IIS site STIG. ATO Insight compares what should exist against what actually came in and shows me the coverage gap, before the AO finds it for me.”
Also available
Lightweight
  • ✓ CKL, CKLB & XCCDF extraction
  • ✓ Standardized output packages
  • ✓ Air-gap compatible
  • – Full analytics dashboard
  • – Scanner import
  • – Readiness checklist
This edition
Standard
  • ✓ Includes Lightweight Edition license
  • ✓ Full analytics dashboard
  • ✓ Multi-run trend tracking
  • ✓ Tenable/ACAS & Qualys import
  • ✓ Pre-submission readiness
  • ✓ On-demand report suite
Upgrade to
Enterprise
  • ✓ Everything in Standard + Lightweight Edition licenses
  • ✓ Multi-boundary roll-up
  • ✓ Cross-boundary queries
  • ✓ Boundary consolidation
  • ✓ Comprehensive flexible reports
  • ✓ Conflict detection
MDS
ATO Insight
Know before you go.
Edition
Enterprise
Lightweight
Standard
Enterprise
Enterprise Edition
The full picture,
across every boundary.
When you’re responsible for more than one ATO boundary — or when multiple teams are collecting compliance data across sites, enclaves, and environments — you need more than a per-boundary view. Enterprise brings everything together: all your boundaries simultaneously, consolidated field data, cross-boundary risk patterns, and the organizational oversight that program offices and commands require before any package moves forward.
● Enterprise Roll-Up View  —  All 3 Boundaries Simultaneously
Real-World Scenario
Boundary 1
Operations
PROD SUPPORT
COOP
Separate sites — same ATO
Boundary 2
Non-Production
TEST TRAIN
Boundary 3
Development
DEV
Completely
isolated
Note: Standard Edition shows one boundary at a time
Enterprise-class visibility. Zero infrastructure overhead. No web server, no database server, no additional attack surface, no additional accreditation burden — at any tier. “The irony of needing an ATO for your ATO tool is real. ATO Insight sidesteps it entirely.”
🌐

Multi-Boundary Roll-Up Dashboard

All managed ATO boundaries simultaneously in one view. Compare posture, identify organization-wide risk patterns, and brief leadership without switching databases.

🔎

Cross-Boundary Queries

Find findings, trends, and risk patterns across all boundaries at once. Is the same vulnerability present in both PROD and DEV? Now you can see it.

🔀

Boundary Consolidation

When separate ATOs merge under one package, consolidate two databases into one. Original databases are always preserved — the merge creates a new combined boundary.

📥

Field Package Aggregation

Receive and consolidate data from Lightweight users at remote sites and air-gapped enclaves. COOP site data flows in alongside primary site data — seamlessly.

📑

Comprehensive Flexible Reports

All Standard reports plus a multi-boundary roll-up report and a fully configurable comprehensive report — select the sections the program office or AO actually needs.

⚠️

Boundary Conflict Detection

Automatically flags when the same eMASS or CSAM Package ID appears in multiple databases — catching boundary confusion before it becomes a submission problem.

🔄

Always Current — Quarterly Release Cycle

Active subscriptions include updated releases aligned with DISA quarterly STIG drops, CISA guidance updates, and NIST framework revisions. If checklists reference controls that don’t match the current benchmark, you’ll see it immediately. Download the latest version under your active license — no network connection required.

Enterprise does not change what ATO Insight fundamentally is. It is still a local, standalone analytics layer — not a cloud platform, not a system of record, not an eMASS or CSAM integration. It extends the pre-flight capability to the organizational level so that the people responsible for the broadest picture have the same clarity as the Compliance Assessors working individual boundaries.

Standard shows one boundary at a time. Enterprise is for the people accountable for many — every boundary at once, from separate databases, compared side by side or queried as one. The org-wide picture, however you need to slice it, without uploading anything anywhere.
AO / CISO · Multiple Boundaries
Pinpoint risk across the whole org
“I’m accountable for the organization, not one package. When there’s a database-hardening problem in the Training environment, or the ESXi hosts are drifting across enclaves, I need to pinpoint it across every boundary at once — and brief leadership from one roll-up view, without ever uploading a thing to eMASS or CSAM.”
Program Security · Consolidation
When two ATOs become one
“Two separately accredited boundaries are merging under a single package. I consolidate their databases into one combined boundary — originals preserved, untouched — and immediately see the true posture. Conflict detection flags the same Package ID living in two places before it becomes a submission problem.”
Also available
Lightweight
  • ✓ CKL, CKLB & XCCDF extraction
  • ✓ Standardized output packages
  • ✓ Air-gap compatible
  • – Analytics dashboard
  • – Scanner import
  • – Multi-boundary view
Also available
Standard
  • ✓ Full analytics dashboard
  • ✓ Trend tracking
  • ✓ Tenable/ACAS & Qualys import
  • ✓ Pre-submission readiness
  • ✓ On-demand reports
  • – Multi-boundary view
This edition
Enterprise
  • ✓ Everything in Standard + Lightweight Edition licenses
  • ✓ Multi-boundary roll-up
  • ✓ Cross-boundary queries
  • ✓ Boundary consolidation
  • ✓ Comprehensive flexible reports
  • ✓ Conflict detection