APTSecurity Management

Free tools

Eight tools. No signup, no email capture.

Built for the CMMC and NIST SP 800-171 work that defense contractors actually have to do. Free to use, nothing to sign up for, and no attempt to collect your address before showing you the answer.

Seven of the eight serve obligations the July 2026 CMMC suspension left untouched. Self-assessment, SSP, POA&M and SPRS scoring are all still required under DFARS 252.204-7012 and 7021.

  • CMMC Readiness Check

    Walks the scoping questions and tells you which CMMC level your contract points to, and why.

    readiness-check.aptsecuritymanagement.com

  • SPRS Score Calculator

    Scores your NIST SP 800-171 implementation the way SPRS does, including the negative weighting people get wrong.

    sprs-calculator.aptsecuritymanagement.com

  • CUI Identifier

    Checks a document or data type against the CUI registry categories so you can tell FCI from CUI.

    cui-identifier.aptsecuritymanagement.com

  • SSP Scaffolder

    Produces a System Security Plan skeleton structured around your actual boundary rather than a generic template.

    ssp-scaffolder.aptsecuritymanagement.com

  • POA&M Builder

    Turns a list of unmet practices into a POA&M with owners, dates and milestones an assessor will accept.

    poam-builder.aptsecuritymanagement.com

  • Practice Lookup

    Every 800-171 practice, searchable, with what evidence satisfies it.

    practice-lookup.aptsecuritymanagement.com

  • Asset Categorizer

    Sorts assets into the CMMC asset categories, which is what decides how much of your estate is in scope.

    asset-categorizer.aptsecuritymanagement.com

  • Flow-Down Letter Generator

    Generates a DFARS flow-down letter naming the clauses and the data type for a subcontractor.

    flow-down-letter.aptsecuritymanagement.com

Each tool runs on its own subdomain. They are free because the scoping work they do is the part people get wrong on their own, and a contractor who scopes correctly is a better conversation than one who does not.

These are the ones we built. For the ones we did not, see free security tools we actually recommend, which is third-party software we make no money from.

Tool told you something you did not expect?

That happens most often with scoping. Worth a short conversation before you act on it.