Success Stories

Customer success stories spelled out from automating with OpenRMF® Professional.

Current Navy Customer

This customer has a very small staff covering 1,000's of workstations. They could only manage a sample set of checklists with checklist files and PDF scan results. And upgrading checklists was a nightmare even across just a couple hundred checklist files.

Now, they load SCAP results into their OpenRMF® Professional instance and all the automation takes over. Bulk editing, bulk upgrades, tracking trends, automating their POAM and seeing their numbers instantaneously across all distinct workstations.


Before OpenRMF® Professional

Manually loading a subset of SCAP scans to checklists

Manually reviewing a subet of ACAS/Nessus scan results

Manually edit the POAM and Compliance history

Extrapolating out data based on the sample set

Shared Drive to store files, editing 1 at a time

After OpenRMF® Professional

Running compliance scans against all devices

Automatically tracking compliance and patch vulnerabilities through the UI

POAM kept up-to-date automatically

Data generated per device automatically from scans

100% web-based, multi-tenant, multi-user

"We just completed one of our step 4 checkpoints and our validators like how we were able to keep all the CKL files in one place using this tool. Allowed for other team members to help us walk through the validation without having to email things around all day."

Current Intel Community Customer

This customer was doing CIS scans manually, manually creating checklists from mapping CIS scans, loading into checklist files via STIGViewer, tracking other information in MS Excel files, and manually generating compliance for cyber auditors.

Now, Powershell automates the scanning and collection and uploading to OpenRMF® Professional automatically via our API. So they view results and adjust accordingly. They also fully automated the command cyber readiness inspection (CCRI) data generation.


Before OpenRMF® Professional

Manually loading CIS scans to checklists

Manually reviewing ACAS/Nessus scan results

Manually edit the POAM and Compliance history

Data calls by reviewing a bunch of files

Manual Compliance Listing for Controls and CCIs

Shared Drive to store files, editing 1 at a time

After OpenRMF® Professional

Automating compliance scans via Powershell

Automating Upload scan results via API

POAM kept up-to-date automatically

Data calls by running reports

Automated Cyber Readiness Data

Generate Compliance with one click

Current DoD Contractor Customer

This customer was doing scans manually, loading into checklist files via STIGViewer, tracking other information in MS Excel files, and manually generating compliance for cyber auditors.

Now, Ansible automates the scanning and collection and uploading to OpenRMF® Professional automatically. So they view results and adjust accordingly.


Before OpenRMF® Professional

Manually loading SCAP scans to checklists

Manually reviewing ACAS/Nessus scan results

Manually edit the POAM and Compliance history

Data calls by reviewing a bunch of files

Manual XLSX files to track trend history

Manual Compliance Listing for Controls and CCIs

Shared Drive to store files, editing 1 at a time

After OpenRMF® Professional

Automating compliance scans via Ansible

Automating Upload scan results via API

POAM kept up-to-date automatically

Data calls by running reports

Automated Cyber Readiness Data

Generate Compliance with one click

100% web-based, multi-tenant, multi-user

We are moving right along with our OpenRMF Professional deployment and just went through our first quarterly STIG updates. Made things a lot easier for us for sure.

- Current US Navy Customer

These guys are the Chick-Fil-A of RMF -- Amazing Customer Service!

- Group evaluating our application

We have been using it quite a lot and it has already saved us a ton of time mass updating STIG Checklists for each system

- Current Space Force Customer

This is worth it based on the bulk editing alone!

- Current US AF Customer

This allows our cyber engineers to do engineering, not be cyber administrators!

- Current VAR

A Live POAM -- I did not think that was possible

- Corporate Cybersecurity Director

Your tool is leaps and bounds ahead in this current market

- Governance, Risk, Compliance Team Lead

If this does even 50% of what you say it does, it is well worth it!

- FMS Customer

SoteriaSoft is 10/10 to work with!

- 2024 New Customer