SecurityBagel/CMMC-Bagel
β 109 stars | License: GPL-3.0 | Recommendation: HIGH
What it is
Power BI template for CMMC compliance assessment tracking and POA&M management. Uses Excel as data source. Works locally or via SharePoint/Power BI Service.
Key files
Templates/800-171 Assessment Template.xlsxβ fill-in-the-blank assessment spreadsheetTemplates/POA&M Template.xlsxβ POA&M tracking spreadsheetData/Example Assessment.xlsxβ complete example assessmentData/Example POA&M.xlsxβ example POA&M*.pbit/*.pbixβ Power BI report files- Includes AWS Managed Rules and Customer Compliance Guides xlsx files
How it could be used
- SPRS score calculation β automatically calculates your SPRS score (required for DoD self-assessments under 32 CFR Part 170)
- POA&M management β track all outstanding findings with remediation status
- Multi-assessment scope β combine scores across facilities, CUI assets, etc.
- Dashboard β visual compliance posture for stakeholders
Caveats
- Requires Microsoft Power BI Desktop (free) or Power BI Service
- GPL-3.0 means modifications must be open-sourced
Notes
This is the most mature open-source CMMC compliance tracking tool available. The Excel templates are directly usable even without Power BI.