Built for ISSMs, ISSOs, and security teams who live in the ConMon grind. CM Toolkit manages the entire continuous monitoring lifecycle across multiple accredited systems. It drives your CM schedule week by week, generates fillable PDF checklists with signature blocks, tracks what's been completed (and by whom), and rolls everything up into polished reports your AO and assessors will actually want to read.
Landscape PDF worksheets with form fields, initials, and signature blocks generated straight from your control schedule. Completed work is never overwritten, and cross-frequency tasks already done elsewhere are flagged automatically.
Weekly Report, Monthly Status Report, Top Ten Actions Status, Monthly Brief (PPTX), Full Review, and POA&M/Outstanding tracking — plus Cross-System Delta, N/A Scan, Signature Inventory, CCR generation, and Policy Review reports.
Import your authoritative control set directly from an eMASS export to stand up a new system's schedule in minutes, and run diffs to catch drift between eMASS and your working schedule.
Manage every system under your ATO from one console. Granular per-user permissions (App Manager, ISSM, ISSO, PM, and custom roles) gate reports, schedule edits, checklist generation, and administration.
Every checklist change is captured: who stamped initials, which OS user made the change, and a structured diff of exactly what changed.
Store system credentials securely inside the app, gated by explicit per-user permission.
Deferred activities are automatically scored and tiered (Critical/High/Medium/Low) with threat scenarios, CIA impact, and ATO impact narratives ready for AO briefings.
Every activity ties back to NIST SP 800-53 controls (CA-7, CM-6, SC-7, AU-6, and more), keeping your evidence aligned with your SSP-declared strategy and DCSA Security Review expectations.