Stop stitching. Start assessing.
The first API to deliver pre-resolved traceability across NIST 800-53, 800-171, CMMC, FedRAMP, CCIs, and STIGs — normalized, versioned, and query-ready.
Compliance data fragmented over decades.
NIST, DISA, CMMC AB, and FedRAMP each evolved independently — incompatible formats, separate portals, different cadences. Nobody planned the mess. But every GRC team is still stuck solving the same stitching problem from scratch.
Seven silos, zero joins
NIST publishes OSCAL catalogs. DISA distributes XCCDF ZIP bundles. CMMC AB posts PDFs. FedRAMP maintains GitHub repos. None of them speak to each other, and none of them are query-ready.
The Rev 4 hangover
DISA's CCI list still references NIST 800-53 Rev 4. If you're working against Rev 5 — and you should be — every STIG-to-control trace needs a translation layer that doesn't officially exist yet.
Bookmarks are good. API access is better.
Thousands of practitioners have bookmarked StigViewer URLs for fast STIG reference — and we're not going anywhere. Those links stay live. But GRC platforms and compliance pipelines need to consume this data programmatically, at scale, without a browser in the loop.
No common format for findings
Scanner output from Tenable, OpenSCAP, and STIG Viewer all look different. There's no shared schema for findings, no standard way to import them into a GRC tool, and no agreed structure for carrying a finding through to a POA&M.
Mandates aren't machine-readable
A STIG rule, a CCI, a control statement — these are compliance mandates expressed as prose. They can be read by humans and audited by hand, but they can't be queried, asserted, or automated against. This is the foundational gap our Claimify system solves.
Every team rebuilds this
GRC platform teams, system integrators, and compliance tool vendors have all built their own internal versions of this normalization layer. It's undifferentiated infrastructure — and it's costing the industry millions of hours a year.
One query. The full chain.
StigViewer pre-resolves the entire traceability path from a scanner finding to a compliance posture. What your team currently assembles in hours is a single API call.
Every source. One schema.
We ingest, normalize, version, and cross-reference all major GRC data sources — so you don't have to maintain seven different parsers and reconciliation scripts.
All sources are versioned independently. Breaking changes emit change events with affected control and rule IDs.
NIST SP 800-53 Rev 5
Full control catalog including all enhancements, ODPs, and related control links. OSCAL-native ingestion.
NIST SP 800-171 Rev 2
All 110 practices with resolved 800-53 mappings, relationship types, and enhancement disambiguation.
FedRAMP Low / Mod / High
Pre-resolved profiles with ODP substitutions applied and all FedRAMP-specific prop extensions normalized.
CMMC 2.0 Levels 1–3
All 110 Level 2 practices with SPRS scoring weights and C3PAO assessment objective mappings.
DISA CCI List
All ~2,400 Control Correlation Identifiers with Rev 4→Rev 5 translation applied automatically.
DISA STIGs
250+ product STIGs with fully parsed rules, stable vuln_id tracking, and CCI-to-control resolution pre-computed.
SRGs
Technology-class Security Requirements Guides — General OS, Web Server, Database, Application Server, and more.
DoD 8500 / 8510
Legacy DIACAP controls and RMF policy references, mapped to current 800-53 Rev 5 equivalents.
Built for how assessors actually work.
Every endpoint reflects a real workflow — finding triage, control gap analysis, POA&M generation, and cross-framework rollup. JSON responses, OpenAPI spec included.
| Capability | Building it yourself | StigViewer API |
|---|---|---|
| STIG ingest + parse | ✕ 3–6 weeks, double-decode trap, re-parse on every release | ✓ Pre-parsed, weekly sync, stable vuln_id tracking |
| CCI → 800-53 Rev 5 resolution | ✕ Manual spreadsheet, not machine-readable, breaks on Rev 5 | ✓ Rev 4→Rev 5 translation applied, queryable by CCI ID |
| 800-171 ↔ 800-53 mapping types | ✕ Flat "maps to" — loses enhancement vs base control nuance | ✓ Typed relationships: equivalent, subset, maps-to-enhancement |
| FedRAMP profile resolution | ✕ Requires OSCAL resolver, ODP substitution, namespace handling | ✓ Pre-resolved, cached, all three baselines available |
| STIG version change detection | ✕ Manual diff, orphaned finding IDs on every update | ✓ Diff endpoint, change events, stable vuln_id across versions |
| Full traceability chain query | ✕ 4+ data sources, hand-assembled, hours per finding | ✓ Single API call, finding to compliance posture |
The compliance vocabulary everyone's been missing.
Every framework uses its own terminology. The Lexicon is a master dictionary of 3,100+ authoritative terms — tagged, cross-referenced, and embedded directly into source documents so a single query surfaces every relevant passage across your entire compliance library.
Every finding mapped to the humans behind it.
Grounded in the Department of Labor's O*NET workforce science and Bloom's Taxonomy, this feature answers three questions: who owns it, how cognitively demanding is it, and can a tool do it?
Join the teams building on clean compliance data.
We're onboarding a limited cohort of GRC platform teams and compliance engineers. API credentials, full documentation, and direct access to our data team.