Know which federal guidance changed, and map the tools your agency actually runs
Today, anyone can search federal cybersecurity, privacy, and technology governance from 1974 on, and agencies in early access can map their FedRAMP authorizations to 18 security functions. Next, FedXchange will write 61 plain-language policies, procedures, and plans that name the services you confirm.
Free to use. Built and run by Varry LLC.
Setup proposal
Example · early access
Identity provider
Your authorizationMatched to your FedRAMP authorization
SIEM and log management
Your platformCovered by your cloud platform's authorization
Vulnerability disclosure
Shared serviceCISA Vulnerability Disclosure Policy Platform
Learning management
Generic name until you choose“the learning management system”
Generic policies don't say what you actually do
Templates name nothing
Most policy templates say “the organization employs an automated tool.” Staff can't follow that, and assessors ask which tool you mean.
Guidance never stops moving
New CISA directives, OMB memoranda, and NIST revisions arrive all year. Finding which of your documents each one touches takes days.
What you really run gets missed
Services the government runs, such as USAccess and CISA's Protective DNS, don't show up in your FedRAMP authorizations. A product you get through Continuous Diagnostics and Mitigation (CDM) often isn't listed under your agency either. Tools that read only your authorizations miss both.
What you can use today
- Open to anyone
Governance tracker
Federal cybersecurity, privacy, and technology governance from the Privacy Act of 1974 to today: laws, executive orders, OMB memoranda, CISA directives, NIST publications, and contract rules, each with its status. Search it, filter it, follow it by feed, or download it as a spreadsheet.
- Documents
- 631
- In effect
- 371
- Proposed
- 19
- No longer in effect
- 241
Counted from the tracker on October 5, 2026.
- Open to anyone
Newsletter and alerts
A weekly email on Fridays with what FedXchange's daily check of federal sources found, and an alert on the day it finds something new, if you want one. Free, with a one-click unsubscribe.
- Early access
Agency setup
FedXchange reads your agency's FedRAMP authorizations, proposes a service for each of 18 security functions, and lists the government's shared services beside each one. You confirm every choice and set your own titles for 46 offices and roles.
- Early access
Governance watch
The watch checks 9 groups of federal sources, most of them daily. When one changes, your agency sees which of the 61 planned documents cite it, and acts on it or dismisses it.
- Early access
AI assistants
Connect Claude, Cursor, VS Code, or any assistant that supports the Model Context Protocol (MCP) to review proposals and record your choices. Every change shows a preview and waits for your yes.
61 documents, written in plain language
After that: drafted updates. When a source changes, FedXchange will propose new wording for a person to approve.
27 policies · 21 procedures · 7 plans · 6 templates, rules of behavior, and references
Including
- Information Security Program Plan
- Incident Response Plan
- Information Security Continuous Monitoring (ISCM) Strategy
- Post-Quantum Cryptography Migration Plan
- Rules of Behavior — Privileged Users
Planned export: Word files with your agency's cover, running header, page numbers, and a filled table of contents.
Every real option, side by side
FedRAMP Marketplace products
Software, platform, and infrastructure services with a FedRAMP authorization, including the products many agencies get through Continuous Diagnostics and Mitigation (CDM): choose the product and FedXchange records that it comes through CDM.
See every FedRAMP product by function (open to anyone)
Run by the government: 9 services in 8 of the 18 functions
Most never appear among your FedRAMP authorizations, so FedXchange lists them beside every choice.
- Identity and Access Management
- USAccess, General Services Administration (GSA)Login.gov, General Services Administration (GSA)
- Vulnerability Management
- Cyber Hygiene Vulnerability Scanning and Web Application Scanning, CISA
- SIEM and Log Management
- Logging Made Easy, CISA
- Network Security and Web Gateway
- Protective DNS, CISA
- Governance, Risk, and Compliance
- JCAM (formerly CSAM), Department of Justice
- Continuous Monitoring and Posture Management
- ScubaGear (Secure Cloud Business Applications), CISA
- Vulnerability Disclosure Platform
- Vulnerability Disclosure Policy Platform, CISA
- Learning Management System
- FedTalent, Department of the Interior, Interior Business Center
Get new federal governance by email
Sign up
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.
Who runs FedXchange
Free to use. FedXchange is built by Varry LLC, which also makes RMF Coach, hands-on courses and an authorization simulation for learning NIST RMF and FedRAMP.
Be one of the first agencies to try it
Tell us who you are and we'll reply by email. The governance tracker is open to everyone now.