What is NIST SP 800-171 and do I need an SSP?▾
NIST SP 800-171 defines requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems. If your organization handles CUI under a DoD contract or federal program, you are required to document how you protect that information in a System Security Plan (SSP).
How is ASSP different from ARMS?▾
ARMS is focused on CMMC 2.0 Level 2 assessment readiness — SPRS scoring, POA&M tracking, and evidence management. ASSP is focused on SSP generation and security system planning — documenting your environment, controls, roles, boundaries, and interconnections in a complete System Security Plan.
How is the app delivered?▾
ASSP is a single HTML file. After purchase you receive a license key by email. Open the app in any modern browser, enter your key, and you're in. No installation, no server, no cloud account required. Your data stays entirely on your machine.
Where is my data stored?▾
Entirely in your browser's local storage — nothing leaves your machine. You can export your data to a local JSON file at any time using the built-in Save function and reload it later. Zero cloud dependency.
What's the difference between Basic, Pro, and Enterprise?▾
Basic covers core planning for up to 5 systems with 12-month updates. Pro adds unlimited assessments, advanced threat modeling, and lifetime updates. Enterprise adds multi-site deployment, team tools, API integration, and a dedicated support SLA. All tiers are one-time perpetual licenses.
Is this a subscription? Will I be charged again?▾
No subscription, ever. All ASSP licenses are one-time perpetual purchases. You pay once and own your tier permanently.