Docs / Getting started

Getting started

Bastion runs entirely in your browser. Nothing to install, no account, no server. This page takes you from a blank slate to a scored, documented posture in five steps.

On this page

  1. Before you start: know your CUI scope
  2. Step 1 — Create a system profile
  3. Step 2 — Work through the assessment
  4. Step 3 — Read your SPRS score
  5. Step 4 — Plan your remediation
  6. Step 5 — Generate your artifacts

Before you start: know your CUI scope

The single most important thing to settle before you touch a single control is scope: where does Controlled Unclassified Information (CUI) live, flow, and get processed in your business? Your assessment only needs to cover the people, systems, and facilities that store, process, or transmit CUI — your "in-scope" environment, sometimes carved out into a dedicated enclave.

Before you create a profile, sketch out:

A tight, well-defined scope is the difference between a manageable assessment and an impossible one. The smaller and clearer your CUI boundary, the fewer systems your 110 controls apply to.

Step 1 — Create a system profile

A profile in Bastion represents one system or environment you're assessing — for example "GCC High enclave" or "Engineering CAD network." You can keep multiple profiles side by side, each with its own answers, evidence, score, and artifacts. That's useful when you want to assess separate enclaves, model a target state, or keep a clean baseline.

Open the app, create a profile, and give it a clear name. If you only handle Federal Contract Information (FCI) and not CUI, switch on CMMC Level 1 mode, which narrows the assessment to the 17 FCI safeguarding controls instead of all 110.

Step 2 — Work through the assessment

The assessment walks you through all 110 NIST SP 800-171 Rev 2 controls, grouped into 14 families (Access Control, Audit & Accountability, Configuration Management, and so on). Each control is written in plain language with practical guidance on what it means for a small shop.

For every control you'll set one of five statuses:

StatusUse it when…
MetThe control is fully implemented today and you can prove it.
Partially MetSome but not all of the control's requirements are in place. (Earns no SPRS credit — see why.)
Not MetThe control is not implemented.
N/AThe control genuinely does not apply to your environment, with a documented justification.
InheritedThe control is provided by an external provider (e.g. FedRAMP / GCC High).

For each control you can attach evidence in the per-control evidence vault and write notes describing exactly how the control is implemented. Do this as you go — those notes become the body of your SSP. The full method is in the Assessment guide.

Already running Sightline or Cairn? Import their JSON to auto-suggest statuses and pre-fill evidence for the ~72 technical and ~74 documentation controls they cover, then review each suggestion before accepting it.

Step 3 — Read your SPRS score

As you answer, Bastion calculates your DoD SPRS score live using the official weighted methodology. The score starts at 110 (a perfect posture) and subtracts weighted points for each control that isn't Met — 5, 3, or 1 points depending on the control's risk weight. The floor is −203.

Your gap dashboard breaks the score down by control family and surfaces your top remediation priorities — the highest-weight gaps to fix first. Don't panic at a low or negative number on day one; that's normal, and it's exactly what the remediation planner is for. See SPRS explained for the full methodology.

Step 4 — Plan your remediation

Use the remediation planner to sequence your open controls. As you mark controls as planned-to-fix, Bastion shows a what-if projected SPRS score so you can see the payoff of each chunk of work before you do it. Take score-history snapshots over time to show your trajectory — useful evidence that you're actively closing gaps.

Step 5 — Generate your artifacts

When you're ready, Bastion generates three documents directly from your assessment:

Everything exports to portable formats, and the whole assessment can be exported to JSON for backup or to move between machines. See SSP & POA&M for details.

Your data never leaves your machine. Bastion stores everything in your browser's localStorage. Because of that, clearing your browser data or switching devices will lose your work unless you've exported your JSON first. Export regularly.

Next: Assessment guide Back to docs