Skip to content
Foxx Cyberfoxxcyber/docs

Frameworks and Baselines

Adopt frameworks from the built-in catalog, scope NIST SP 800-53 to a baseline, carry answers across frameworks with crosswalks, and record posture snapshots.

Frameworks are how you measure a client's program. The catalog is shared by every client; each client adopts the frameworks that apply to it and answers them independently.

The catalog

Frameworks in the sidebar lists the catalog's eight frameworks: NIST CSF 2.0, CMMC 2.0 Level 1 and Level 2, NIST SP 800-171 Rev. 3, NIST SP 800-53 Rev. 5 (release 5.2.0), and the HIPAA Security, Privacy and Breach Notification Rules. Each card shows the publisher, version, number of assessable controls and a link to the source, and you can download the whole framework with its crosswalks as Excel or CSV.

The catalog is part of the application. There is no custom framework import. What each framework contains, where it comes from and what is left out is on Frameworks Catalog and Sources.

Adopt a framework

Open the client's Frameworks tab and use the Add a framework card:

  • Framework: pick one the client has not adopted yet. What each framework covers, under the field, describes them all.
  • Target (optional, free text): for example "Tier 3 by Q4" or "SPRS 110 before renewal".
  • Primary framework: the one shown on the portfolio and first on the overview. The box is ticked for the first framework you adopt; marking another one as primary moves the flag.

Then choose Add framework.

NIST CSF 2.0 is the usual backbone for a client's program; CMMC Level 1 or Level 2 and NIST SP 800-171 add the contract obligations for defense suppliers, and the HIPAA rules cover healthcare clients and their business associates.

Remove from this client, in the framework's row menu, takes a framework off the client after a confirmation. Its answers are kept, so adding it back later restores them.

The Frameworks tab

Each adopted framework has a row with:

  • its name, with Primary on the primary one, the full name, how many controls are in scope and the target;
  • a Status mix bar (implemented, partial, not implemented, not applicable, not assessed);
  • Coverage: the implemented share of applicable controls, with partial counting as half, or the SPRS score for CMMC Level 2 (with how many practices are still unassessed);
  • Assessed: the share of controls with any decided status;
  • Maturity: the mean current maturity on the 0 to 5 scale, shown when a framework on the client is rated for maturity (NIST CSF 2.0 always is).

The Frameworks tab for a client with NIST CSF 2.0 as primary framework and NIST SP 800-53 at the Moderate baseline, with the CSF row's menu open showing Export the answers, Target, Primary framework, Save target and Remove from this client

Assess opens the control-by-control assessment (it reads Open when you can only read the framework); see Assessing Controls. Everything else is in the row's menu (the button with three dots), for staff:

Menu itemWhat it does
Export the answers (.xlsx)The framework's answers as a workbook.
Issued assessmentsShown while a partner firm holds the framework: the versions it has issued.
Compare with SP 800-171 Rev 3On the CMMC Level 2 row only: compare with NIST SP 800-171 Rev. 3 and move the answers across. See Moving to NIST SP 800-171 Rev. 3.
eMASS results templateOn the CMMC Level 2 row only. See CMMC Level 2 Results for eMASS.
Target, Primary framework, then Save targetChanges the framework's target, or makes it the primary one.
Fill from crosswalksFills unassessed controls from answers on other frameworks, after a confirmation (below). Shown on CMMC Level 1, Level 2 and NIST SP 800-171 Rev. 3.
Assessed by, then Save who assesses itAdmins only: hands the framework to a partner assessment firm, or back to Foxx Cyber staff. See Assigning a Firm.
Remove from this clientTakes the framework off the client, keeping its answers.

Target, primary, crosswalk fills and removal need edit access to the client.

A framework a partner firm is assessing

When a framework has been handed to a firm, its row shows an Assessed by firm badge and the assessment's phase:

PhaseMeaning
PlanningNo answer from the firm yet.
AssessingThe firm has started answering.
IssuedThe firm has issued a version, and some of its findings still have no finished roadmap work.
Closed outEvery finding in the latest issued version has roadmap work that is done or dropped.

While a firm holds a framework, staff can read its answers but not change them: Assess reads Open, and the target, Fill from crosswalks and Remove from this client are not offered.

Scope NIST SP 800-53 to a baseline

For NIST SP 800-53, the assessment page offers a scope: every control (1,014 controls and enhancements), or one of the NIST SP 800-53B baselines:

BaselineControls and enhancements
Low149
Moderate287
High370
Privacy (additive)96

Pick Low, Moderate or High, tick Add the privacy baseline if it applies, and choose Save scope. Controls outside the scope are not listed or counted in posture, and their groups are marked Outside the baseline in the tree. Their answers are kept, so widening the scope later brings them back.

For other frameworks, scope is set control by control: mark a control not applicable and say why in its narrative.

Crosswalks: answer once

Crosswalks link equivalent or related requirements across frameworks:

FromToSource
CMMC Level 1CMMC Level 2The CMMC Assessment Guides' references to the same NIST SP 800-171 requirement
CMMC Level 2NIST SP 800-171 Rev. 3NIST's Rev. 2 to Rev. 3 change analysis
NIST SP 800-171 Rev. 3NIST SP 800-53 Rev. 5NIST's source controls for each requirement
NIST CSF 2.0NIST SP 800-171 Rev. 3 and SP 800-53 Rev. 5NIST's CSF 2.0 informative references
HIPAA Security RuleNIST SP 800-53 Rev. 5NIST SP 800-66 Rev. 2

They work in two ways:

  • On every control page, a Crosswalk panel lists the mapped requirements in other frameworks, with the client's answer where that framework is adopted.
  • Fill from crosswalks, in a framework's row menu on the Frameworks tab, fills that framework's unassessed controls from answers the client already has elsewhere. It appears on frameworks with equivalent or subset mappings (CMMC Level 1 and Level 2, and NIST SP 800-171 Rev. 3), follows only those mappings, and copies an answer only when every mapped answer agrees; anything ambiguous is left for you. Each copied answer says where it came from ("Carried over from … by crosswalk. Confirm before relying on it.").

The crosswalk fill has three limits:

  • It never copies "not applicable". Whether a control applies belongs to each framework's own scope, so a person decides it, with a reason.
  • It never fills a framework a partner firm holds, and never reads one as a source: those answers belong to the firm until it issues them.
  • It never overwrites a control that already has an answer.

Most mappings, including all of CSF 2.0's and the HIPAA Security Rule's, are related rather than equivalent. They inform your answer on the control page but never fill one in. The HIPAA Privacy and Breach Notification Rules have no published crosswalk, so they have none here.

Posture snapshots

Record snapshot, at the foot of the Posture history card on the Frameworks tab (with an optional Snapshot label such as "Q3 review"), captures the posture of every adopted framework at once. Posture history lists every snapshot, newest first and paged, and draws a coverage trend line per framework once there are two. For active and onboarding clients, a snapshot comes due in Monitoring about a quarter (91 days) after the last one, or after the framework was adopted.

Continue with Assessing Controls.

Last updated October 9, 2026