Checkpoint Ai
FreeNot checkedNIST AI RMF / EU AI Act / ISO 42001 self-assessment & SSP generator
About
NIST AI RMF / EU AI Act / ISO 42001 self-assessment & SSP generator
README
CHECKPOINT-AI
NIST AI RMF / EU AI Act / ISO 42001 self-assessment & SSP generator
PyPI CI License: COCL 1.0 Suite
Federal / Compliance — NIST, CMMC, FedRAMP, and SBIR/GSA workflows.
pip install cognis-checkpoint-ai
checkpoint-ai scan . # → prioritized findings in seconds
🔎 Example output
Real, reproducible output from the tool — runs offline:
$ checkpoint-ai-emit --version
CHECKPOINT-AI 0.1.0
$ checkpoint-ai-emit --help
usage: checkpoint-ai [-h] [--version] [--format {table,json,sarif,csv}]
{catalog,assess,ssp} ...
CHECKPOINT-AI: NIST AI RMF / EU AI Act / ISO 42001 self-assessment & SSP
generator.
positional arguments:
{catalog,assess,ssp}
catalog list the cross-walked control catalog
assess score a self-assessment JSON file
ssp generate an OSCAL-flavored SSP from an assessment
options:
-h, --help show this help message and exit
--version show program's version number and exit
--format {table,json,sarif,csv}
output format (sarif/csv apply to the 'assess'
command)
$ checkpoint-ai-emit catalog
CHECKPOINT-AI control catalog (12 controls)
GOV-1 (w5) GOVERN AI governance policy & accountability owner
nist_ai_rmf=GOVERN 1.1 eu_ai_act=Art.17 iso_42001=5.2
GOV-2 (w4) GOVERN Risk tolerance & escalation thresholds defined
nist_ai_rmf=GOVERN 1.3 eu_ai_act=Art.9 iso_42001=6.1
GOV-3 (w3) GOVERN Workforce AI competency & training
nist_ai_rmf=GOVERN 2.2 eu_ai_act=Art.4 iso_42001=7.2
MAP-1 (w4) MAP Intended purpose & context of use documented
nist_ai_rmf=MAP 1.1 eu_ai_act=Art.11 iso_42001=8.1
MAP-2 (w4) MAP Foreseeable misuse & impacted populations identified
nist_ai_rmf=MAP 3.1 eu_ai_act=Art.9 iso_42001=6.1.2
MAP-3 (w5) MAP Data provenance & lawful basis recorded
nist_ai_rmf=MAP 2.3 eu_ai_act=Art.10 iso_42001=7.4
MEA-1 (w4) MEASURE Performance & accuracy metrics evaluated
nist_ai_rmf=MEASURE 2.3 eu_ai_act=Art.15 iso_42001=9.1
MEA-2 (w5) MEASURE Bias / fairness testing across subgroups
nist_ai_rmf=MEASURE 2.11 eu_ai_act=Art.10 iso_42001=9.1
MEA-3 (w4) MEASURE Adversarial robustness & security testing
nist_ai_rmf=MEASURE 2.7 eu_ai_act=Art.15 iso_42001=8.3
MAN-1 (w5) MANAGE Human oversight & intervention controls
nist_ai_rmf=MANAGE 1.1 eu_ai_act=Art.14 iso_42001=8.4
MAN-2 (w4) MANAGE Incident response & post-market monitoring
nist_ai_rmf=MANAGE 4.1 eu_ai_act=Art.72 iso_42001=10.1
MAN-3 (w4) MANAGE Logging & traceability of system decisions
nist_ai_rmf=MANAGE 2.2 eu_ai_act=Art.12 iso_42001=8.5
Blocks above are real
checkpoint-aioutput — reproduce them from a clone.
Usage — step by step
checkpoint-ai runs an AI-governance self-assessment cross-walked across NIST AI RMF, the EU AI Act, and ISO 42001, and can emit an OSCAL-flavored SSP.
- Install:
pip install -e . - List the cross-walked control catalog:
checkpoint-ai catalog - Score a self-assessment JSON file:
checkpoint-ai assess assessment.json - Generate an SSP (OSCAL-flavored System Security Plan) from the same assessment:
checkpoint-ai ssp assessment.json > ssp.json - Export findings in the format your dashboard speaks. Each open control gap
is a finding;
assesscan emit it as a table, JSON, SARIF 2.1.0, or CSV:
The SARIF log carries one rule per control and one result per gap, each tagged with acheckpoint-ai --format sarif assess assessment.json > checkpoint.sarif.json # code-scanning dashboards checkpoint-ai --format csv assess assessment.json > gaps.csv # spreadsheets / GRC trackerssecurity-severityand the NIST AI RMF / EU AI Act / ISO 42001 crosswalk. - Automate in CI — gate the build and publish findings on each governance change:
checkpoint-ai assess assessment.json # non-zero exit on an unaddressed weight-5 gap checkpoint-ai --format sarif assess assessment.json > checkpoint.sarif.json # upload to code scanning
Demos — real-world scenarios
Each folder under demos/ is a self-contained scenario: a realistic
assessment file in the tool's input format plus a SCENARIO.md describing where
the data came from, what to expect, the exact run command, and how to act.
| Demo | Scenario | EU tier | Outcome |
|---|---|---|---|
| 01-pre-launch-gap-analysis | Support copilot six weeks from launch | limited | weight-5 gaps → CI fails |
| 02-iso-42001-readiness | AIMS one control from a stage-1 audit | limited | single open gap |
| 03-eu-ai-act-high-risk | Hiring system conformity prep (Annex III) | high | bias-testing gap blocks CE mark |
| 04-prohibited-practice-stop | Citizen social-scoring proposal | unacceptable | perfect posture, still a hard stop |
| 05-medical-device-high-risk | Retinal-screening triage that passes | high | clean — the target state |
| 06-internal-analytics-minimal | Internal anomaly flagger | minimal | gaps, but exit 0 (right-sized) |
| 07-greenfield-baseline | Day-zero assessment, nothing built | limited | 0/100, full POA&M backlog |
| 08-na-scoping | OCR digitizer scoping controls out | minimal | not_applicable handling |
| 09-ci-sarif-gate | Credit adjudicator wired into CI | high | exit-code gate + SARIF upload |
| 10-vendor-model-intake | Third-party SaaS due diligence | limited | gaps → vendor questionnaire |
checkpoint-ai assess demos/09-ci-sarif-gate/self-assessment.json
checkpoint-ai --format sarif assess demos/09-ci-sarif-gate/self-assessment.json > checkpoint.sarif.json
Contents
- Why checkpoint-ai? · Features · Quick start · Example · Architecture · AI stack · How it compares · Integrations · Install anywhere · Related · Contributing
Why checkpoint-ai?
NIST AI RMF / EU AI Act / ISO 42001 self-assessment & SSP generator — without standing up heavyweight infrastructure.
checkpoint-ai is single-purpose, scriptable, and self-hostable: point it at a target, get prioritized results in the format your workflow already speaks (table · JSON · SARIF), gate CI on it, and let agents drive it over MCP.
Features
- ✅ Cross-walked control catalog: NIST AI RMF · EU AI Act · ISO/IEC 42001
- ✅ Weighted posture scoring, maturity bands, and per-function breakdown
- ✅ EU AI Act risk-tier classification (minimal / limited / high / unacceptable)
- ✅ Gap analysis with prioritized remediation (OSCAL-flavored SSP + POA&M)
- ✅ Export findings as table · JSON · SARIF 2.1.0 · CSV
- ✅ CI gate: non-zero exit on an unaddressed high-weight gap
- ✅ 10 real-world demo scenarios in demos/
- ✅ Runs on Linux/macOS/Windows · Docker · devcontainer
- ✅ Ports in Python, JavaScript, Go, and Rust (
ports/)
Quick start
pip install cognis-checkpoint-ai
checkpoint-ai --version
checkpoint-ai catalog # list the cross-walked controls
checkpoint-ai assess assessment.json # score; non-zero exit on a high-weight gap
checkpoint-ai --format json assess assessment.json # machine-readable
checkpoint-ai --format sarif assess assessment.json # SARIF 2.1.0 for code-scanning
checkpoint-ai ssp assessment.json > ssp.json # OSCAL-flavored SSP + POA&M
Example
$ checkpoint-ai assess demos/03-eu-ai-act-high-risk/self-assessment.json
CHECKPOINT-AI assessment: sentinel-resume-screener
owner : People Operations, Responsible AI Office
EU AI Act tier : high
overall posture : 72.8/100 (Defined)
function scores :
GOVERN : 91.2/100
MANAGE : 74.2/100
MAP : 76.2/100
MEASURE : 51.2/100
framework cover :
nist_ai_rmf : 66.7%
eu_ai_act : 66.7%
iso_42001 : 66.7%
...
open gaps : MAP-3, MEA-2, MEA-3, MAN-2
$ echo $?
2 # weight-5 gaps (MAP-3, MEA-2) remain — CI gate fails
Architecture
flowchart LR
IN[input] --> P[checkpoint-ai<br/>analyze + score]
P --> OUT[report]
Use it from any AI stack
checkpoint-ai is interoperable with every popular way of using AI:
- MCP server —
checkpoint-ai mcp(Claude Desktop, Cursor, Cognis.Studio, uncensored-fleet) - OpenAI-compatible / JSON — pipe
checkpoint-ai scan . --format jsoninto any agent or LLM - LangChain · CrewAI · AutoGen · LlamaIndex — wrap the CLI/JSON as a tool in one line
- CI / scripts — exit codes + SARIF for non-AI pipelines
How it compares
| Cognis checkpoint-ai | usnistgov | |
|---|---|---|
| Self-hostable, no account | ✅ | varies |
| Single command, zero config | ✅ | ⚠️ |
| JSON + SARIF for CI | ✅ | varies |
| MCP-native (AI agents) | ✅ | ❌ |
| Polyglot ports (JS/Go/Rust) | ✅ | ❌ |
| Open license | ✅ COCL | varies |
Built in the spirit of usnistgov/OSCAL, re-framed the Cognis way. Missing a credit? Open a PR.
Integrations
Pipes into your stack: SARIF for code-scanning, JSON for anything, an MCP server (checkpoint-ai mcp) for AI agents, and a webhook forwarder for SIEM/Slack/Jira. See docs/INTEGRATIONS.md.
Install — every way, every platform
pip install "git+https://github.com/cognis-digital/checkpoint-ai.git" # pip (works today)
pipx install "git+https://github.com/cognis-digital/checkpoint-ai.git" # isolated CLI
uv tool install "git+https://github.com/cognis-digital/checkpoint-ai.git" # uv
pip install cognis-checkpoint-ai # PyPI (when published)
docker run --rm ghcr.io/cognis-digital/checkpoint-ai:latest --help # Docker
brew install cognis-digital/tap/checkpoint-ai # Homebrew tap
curl -fsSL https://raw.githubusercontent.com/cognis-digital/checkpoint-ai/main/install.sh | sh
| Linux | macOS | Windows | Docker | Cloud |
|---|---|---|---|---|
scripts/setup-linux.sh |
scripts/setup-macos.sh |
scripts/setup-windows.ps1 |
docker run ghcr.io/cognis-digital/checkpoint-ai |
DEPLOY.md (AWS/Azure/GCP/k8s) |
Related Cognis tools
- cmmcmap — CMMC Level 2 practice mapper — stack-aware SSP skeleton generator
- fedramplens — FedRAMP boundary visualizer & OSCAL-format SSP/POAM generator
- sbirscout — SBIR/STTR topic discovery — DSIP + SBIR.gov + NIH digest with bid scoring
- gsafinder — GSA Schedule opportunity surveyor — SAM.gov + eBuy + FedConnect
- clearancepath — Personnel clearance hygiene tracker — SF-86, SEAD-3/4, training currency
Explore the suite → 🗂️ all 170+ tools · ⭐ awesome-cognis · 🔗 cognis-sources · 🤖 uncensored-fleet · 🧠 engram
Contributing
PRs, new rules, and demo scenarios are welcome under the collaboration-pull model — see CONTRIBUTING.md and SECURITY.md.
⭐ If
checkpoint-aisaved you time, star it — it genuinely helps others find it.
Interoperability
{} composes with the 300+ tool Cognis suite — JSON in/out and a shared
OpenAI-compatible /v1 backbone. See INTEROP.md for the
suite map, composition patterns, and reference stacks.
License
Source-available under the Cognis Open Collaboration License (COCL) v1.0 — free for personal, internal-evaluation, research, and educational use; commercial / production use requires a license ([email protected]). See LICENSE.
Installing Checkpoint Ai
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/cognis-digital/checkpoint-aiFAQ
Is Checkpoint Ai MCP free?
Yes, Checkpoint Ai MCP is free — one-click install via Unyly at no cost.
Does Checkpoint Ai need an API key?
No, Checkpoint Ai runs without API keys or environment variables.
Is Checkpoint Ai hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Checkpoint Ai in Claude Desktop, Claude Code or Cursor?
Open Checkpoint Ai on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
Fetch
Web content fetching and conversion for efficient LLM usage.
AWS KB Retrieval
Retrieval from AWS Knowledge Base using Bedrock Agent Runtime.
by modelcontextprotocolSpring AI MCP Server
Provides auto-configuration for setting up an MCP server in Spring Boot applications.
llm-analysis-assistant
A very streamlined mcp client that supports calling and monitoring stdio/sse/streamableHttp, and can also view request responses through the /logs page. It also
by xuzexin-hzMCP-Agent
A simple, composable framework to build agents using Model Context Protocol by [LastMile AI](https://www.lastmileai.dev)
by lastmile-aiSpring AI MCP Client
Provides auto-configuration for MCP client functionality in Spring Boot applications.
mcp.natoma.ai
A Hosted MCP Platform to discover, install, manage and deploy MCP servers by [Natoma Labs](https://www.natoma.ai)
MCPHub
Website to list high quality MCP servers and reviews by real users. Also provide online chatbot for popular LLM models with MCP server support.
MCP Servers Rating and User Reviews
Website to rate MCP servers, write authentic user reviews, and [search engine for agent & mcp](http://www.deepnlp.org/search/agent)
mkinf
An Open Source registry of hosted MCP Servers to accelerate AI agent workflows.
Compare Checkpoint Ai with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All ai MCPs
