Skip to content

Security policies, procedures, and plans that name the tools your agency actually runs

FedXchange reads your agency's FedRAMP authorizations, proposes a service for each of 18 security functions, and writes 61 plain-language documents that name the services and titles you confirm. Download them as Word files, ready for your review. Then it tells you when federal guidance changes one of them.

Free to use. Built and run by Varry LLC.

Setup proposal

Example

  • Identity provider

    Your authorization

    Matched to your FedRAMP authorization

  • SIEM and log management

    Your platform

    Covered by your cloud platform's authorization

  • Vulnerability disclosure

    Shared service

    CISA Vulnerability Disclosure Policy Platform

  • Learning management

    Generic name until you choose

    “the learning management system”

Nothing is used until you confirm it.How proposals are chosen
An example of the setup proposal an agency sees after it signs up: each security function shows the proposed service and why it was proposed.

Generic policies don't say what you actually do

  • Templates name nothing

    Most policy templates say “the organization employs an automated tool.” Staff can't follow that, and assessors ask which tool you mean.

  • Guidance never stops moving

    New CISA directives, OMB memoranda, and NIST revisions arrive all year. Finding which of your documents each one touches takes days.

  • What you really run gets missed

    Services the government runs, such as USAccess and CISA's Protective DNS, don't show up in your FedRAMP authorizations. A product you get through Continuous Diagnostics and Mitigation (CDM) often isn't listed under your agency either. Tools that read only your authorizations miss both.

From sign-up to a policy set in four steps

  1. Name your agency

    FedXchange finds your agency's FedRAMP authorizations on the Marketplace and proposes a service for each security function.

    How proposals are chosen
  2. Confirm your choices

    Confirm a service for each of 18 functions, including services the government runs, and set your own titles for 46 offices and roles.

    See the functions
  3. Get your documents

    FedXchange writes 61 policies, procedures, and plans that name what you confirmed. Download each one as a Word file.

    How the documents are made
  4. Stay current

    The governance watch checks federal sources every day and tells you which of your documents a change touches.

    What the watch checks

What you can use today

The governance tracker, the Marketplace tracker, and the newsletter are open to anyone, with no account. Document writing, agency setup, the governance watch, and AI assistants work today with a free account. Sign up with a work email or Google account.
  • Free account

    Your policies, procedures, and plans

    61 documents written from the services and role titles you confirmed, each checked against a plain-language writing standard and downloaded as a Word file with a filled table of contents. Change an answer and write them again.

    What you getHow they are made

  • Open to anyone

    Governance tracker

    Federal cybersecurity, privacy, and technology governance from the Privacy Act of 1974 to today: laws, executive orders, OMB memoranda, CISA directives, NIST publications, and contract rules, each with its status. Search it, filter it, follow it by feed, or download it as a spreadsheet.

    Documents
    632
    In effect
    371
    Proposed
    20
    No longer in effect
    241

    Counted from the tracker on October 10, 2026.

    Open the governance trackerOpen the Marketplace tracker

  • Open to anyone

    Newsletter and alerts

    A weekly email on Fridays with what FedXchange's daily check of federal sources found, and an alert on the day it finds something new, if you want one. Free, with a one-click unsubscribe.

    Sign up belowAbout the newsletter

  • Free account

    Agency setup

    FedXchange reads your agency's FedRAMP authorizations, proposes a service for each of 18 security functions, and lists the government's shared services beside each one. You confirm every choice and set your own titles for 46 offices and roles.

    How setup works

  • Free account

    Governance watch

    The watch checks 10 groups of federal sources, most of them daily. When one changes, your agency sees which of the 61 planned documents cite it, and acts on it or dismisses it.

    What the watch checks

  • Free account

    AI assistants

    Connect Claude, Cursor, VS Code, or any assistant that supports the Model Context Protocol (MCP) to review proposals and record your choices. Every change shows a preview and waits for your yes.

    How assistants connect

61 documents, written in plain language

FedXchange writes your policies, procedures, and plans from the choices you confirmed. Each one names your services and your roles, cites the federal sources it rests on, and passes a fixed series of checks, from source currency to a review board of 16 reviewer roles. They are drafts: nothing is final until a person at your agency approves it.

Works todayFree account

  • Your names, not placeholders. Where a template says “the organization employs an automated tool,” yours names the service you confirmed and the office that runs it.
  • Word files you can edit. Each document comes with your agency's cover and a filled table of contents, ready for your review cycle.
  • Written again when you change an answer. Pick a new service or retitle an office, and the next draft says so everywhere it matters.
  • No AI writes them. A fixed generator writes every document, so the same answers always give the same text.

Coming nextDrafted updates: when a source changes, FedXchange proposes new wording for a person to approve.

Sign up and write your documentsHow the documents are made

Incident Response Plan, section 4

Example

The Security Operations Center watches alerts from your log management service around the clock.

When an alert may be an incident, the analyst opens a ticket in your ticketing service and tells the Information System Security Officer within one hour.

The highlighted words come from your answers: the services you confirmed and the titles your agency uses.

27 policies · 21 procedures · 7 plans · 6 templates, rules of behavior, and references

Including

  • Information Security Program Plan
  • Incident Response Plan
  • Information Security Continuous Monitoring (ISCM) Strategy
  • Post-Quantum Cryptography Migration Plan
  • Rules of Behavior — Privileged Users

Every real option, side by side

For each function, FedXchange lists the FedRAMP Marketplace products that fit it (157 listings in all, as of October 10, 2026), your agency's own first, and the services the government runs itself. Pick one and FedXchange records it for your agency.

FedRAMP Marketplace products

Software, platform, and infrastructure services with a FedRAMP authorization, including the products many agencies get through Continuous Diagnostics and Mitigation (CDM): choose the product and FedXchange records that it comes through CDM.

See the 18 functions

Run by the government: 9 services in 8 of the 18 functions

Most never appear among your FedRAMP authorizations, so FedXchange lists them beside every choice.

Identity and Access Management
USAccess, General Services Administration (GSA)Login.gov, General Services Administration (GSA)
Vulnerability Management
Cyber Hygiene Vulnerability Scanning and Web Application Scanning, CISA
SIEM and Log Management
Logging Made Easy, CISA
Network Security and Web Gateway
Protective DNS, CISA
Governance, Risk, and Compliance
JCAM (formerly CSAM), Department of Justice
Continuous Monitoring and Posture Management
ScubaGear (Secure Cloud Business Applications), CISA
Vulnerability Disclosure Platform
Vulnerability Disclosure Policy Platform, CISA
Learning Management System
FedTalent, Department of the Interior, Interior Business Center

Get new federal governance by email

Each Friday, a short email lists what the watch found that week: new documents, changes in status, and comment deadlines, and, if you follow the Marketplace tracker, products that changed stage on the FedRAMP Marketplace. Add instant alerts if you want them. No account needed.

Sign up

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me
About

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.

Who runs FedXchange

Free to use. FedXchange is built by Varry LLC, which also makes RMF Coach, hands-on courses and an authorization simulation for learning NIST RMF and FedRAMP.

Write your agency's policy set today

Anyone can sign up free with a work email or Google account. The trackers need no account.