Reads CKL, CKLB, and XCCDF format checklists produced by STIGViewer, Evaluate-STIG, SCC, STIG Manager, and compatible assessment tools.
Produces standardized data packages ready for handoff. Standard and Enterprise users ingest them directly — no reformatting, no manual consolidation.
No network access required. No cloud dependencies. Runs as a single local application on any Windows system in any environment, including classified networks.
No inventory list? Drop in a non-credentialed scan and get a proposed set of targets — hostnames, IPs, OS fingerprint — plus the checklists each system likely needs (a web server calls for the OS, IIS Server and IIS Site STIGs, not just one). Confirm and collect.
Compares what you actually collected against what each system should have, and flags the checklist you didn’t run — the missing IIS Site, SQL instance, or OS STIG — before the AO finds it for you.
Generates a printable summary of findings — system inventory, raw CAT counts by environment, compliance families covered — as a field deliverable.
Active subscriptions include updated releases aligned with DISA quarterly STIG drops, CISA guidance updates, and NIST framework revisions. If checklists reference controls that don’t match the current benchmark, you’ll see it immediately. Download the latest version under your active license — no network connection required.
The Compliance Assessor’s job is to collect and assess — not manage the boundary picture. Lightweight handles the collection side cleanly so that whoever manages the ATO boundary gets consistent, standardized data regardless of where or how the assessment work was done.
Every finding across every system in one view. Filter by environment, system type, and severity. Drill from fleet summary to individual system findings in seconds.
Load multiple assessment runs and see exactly how posture changes over time. New findings, closed findings, systems that improved or regressed — all tracked automatically.
Build your target list straight from a discovery scan — OS fingerprint and open ports suggest the checklists each system needs — then track coverage gaps fleet-wide against it. Scan age is surfaced, so a stale snapshot never passes for current posture.
A structured go/no-go list before entering eMASS or CSAM. Open CAT-I count, unreviewed findings, coverage gaps, stale checklists — computed automatically from your data.
Import results from Tenable/ACAS, Qualys, and other major scanners via standard CSV export. Scan findings shown alongside checklist data — kept visually distinct, never conflated.
One license covers every boundary you manage. Switch between them instantly — each maintains its own independent database and full assessment history.
Executive Brief, Full Assessment Report, Trend Summary, and Remediation Priority Report — generated on demand as print-ready HTML/PDF. No additional software required.
Active subscriptions include updated releases aligned with DISA quarterly STIG drops, CISA guidance updates, and NIST framework revisions. If checklists reference controls that don’t match the current benchmark, you’ll see it immediately. Download the latest version under your active license — no network connection required.
ATO Insight™ does not touch eMASS, CSAM, or any GRC platform. It doesn’t replace STIGViewer, manage your POA&Ms, or upload anything anywhere. It shows you — clearly and locally — what your compliance posture actually looks like before you enter the systems that are notoriously difficult to navigate. Think of it as your pre-flight check.
All managed ATO boundaries simultaneously in one view. Compare posture, identify organization-wide risk patterns, and brief leadership without switching databases.
Find findings, trends, and risk patterns across all boundaries at once. Is the same vulnerability present in both PROD and DEV? Now you can see it.
When separate ATOs merge under one package, consolidate two databases into one. Original databases are always preserved — the merge creates a new combined boundary.
Receive and consolidate data from Lightweight users at remote sites and air-gapped enclaves. COOP site data flows in alongside primary site data — seamlessly.
All Standard reports plus a multi-boundary roll-up report and a fully configurable comprehensive report — select the sections the program office or AO actually needs.
Automatically flags when the same eMASS or CSAM Package ID appears in multiple databases — catching boundary confusion before it becomes a submission problem.
Active subscriptions include updated releases aligned with DISA quarterly STIG drops, CISA guidance updates, and NIST framework revisions. If checklists reference controls that don’t match the current benchmark, you’ll see it immediately. Download the latest version under your active license — no network connection required.
Enterprise does not change what ATO Insight™ fundamentally is. It is still a local, standalone analytics layer — not a cloud platform, not a system of record, not an eMASS or CSAM integration. It extends the pre-flight capability to the organizational level so that the people responsible for the broadest picture have the same clarity as the Compliance Assessors working individual boundaries.