Security policies, procedures, and plans that name the tools your agency actually runs
FedXchange reads your agency's FedRAMP authorizations, proposes a service for each of 18 security functions, and writes 61 plain-language documents that name the services and titles you confirm. Download them as Word files, ready for your review. Then it tells you when federal guidance changes one of them.
Free to use. Built and run by Varry LLC.
Setup proposal
Example
Identity provider
Your authorizationMatched to your FedRAMP authorization
SIEM and log management
Your platformCovered by your cloud platform's authorization
Vulnerability disclosure
Shared serviceCISA Vulnerability Disclosure Policy Platform
Learning management
Generic name until you choose“the learning management system”
Generic policies don't say what you actually do
Templates name nothing
Most policy templates say “the organization employs an automated tool.” Staff can't follow that, and assessors ask which tool you mean.
Guidance never stops moving
New CISA directives, OMB memoranda, and NIST revisions arrive all year. Finding which of your documents each one touches takes days.
What you really run gets missed
Services the government runs, such as USAccess and CISA's Protective DNS, don't show up in your FedRAMP authorizations. A product you get through Continuous Diagnostics and Mitigation (CDM) often isn't listed under your agency either. Tools that read only your authorizations miss both.
From sign-up to a policy set in four steps
Name your agency
FedXchange finds your agency's FedRAMP authorizations on the Marketplace and proposes a service for each security function.
How proposals are chosenConfirm your choices
Confirm a service for each of 18 functions, including services the government runs, and set your own titles for 46 offices and roles.
See the functionsGet your documents
FedXchange writes 61 policies, procedures, and plans that name what you confirmed. Download each one as a Word file.
How the documents are madeStay current
The governance watch checks federal sources every day and tells you which of your documents a change touches.
What the watch checks
What you can use today
- Free account
Your policies, procedures, and plans
61 documents written from the services and role titles you confirmed, each checked against a plain-language writing standard and downloaded as a Word file with a filled table of contents. Change an answer and write them again.
- Open to anyone
Governance tracker
Federal cybersecurity, privacy, and technology governance from the Privacy Act of 1974 to today: laws, executive orders, OMB memoranda, CISA directives, NIST publications, and contract rules, each with its status. Search it, filter it, follow it by feed, or download it as a spreadsheet.
- Documents
- 632
- In effect
- 371
- Proposed
- 20
- No longer in effect
- 241
Counted from the tracker on October 10, 2026.
- Open to anyone
Newsletter and alerts
A weekly email on Fridays with what FedXchange's daily check of federal sources found, and an alert on the day it finds something new, if you want one. Free, with a one-click unsubscribe.
- Free account
Agency setup
FedXchange reads your agency's FedRAMP authorizations, proposes a service for each of 18 security functions, and lists the government's shared services beside each one. You confirm every choice and set your own titles for 46 offices and roles.
- Free account
Governance watch
The watch checks 10 groups of federal sources, most of them daily. When one changes, your agency sees which of the 61 planned documents cite it, and acts on it or dismisses it.
- Free account
AI assistants
Connect Claude, Cursor, VS Code, or any assistant that supports the Model Context Protocol (MCP) to review proposals and record your choices. Every change shows a preview and waits for your yes.
61 documents, written in plain language
Works todayFree account
- Your names, not placeholders. Where a template says “the organization employs an automated tool,” yours names the service you confirmed and the office that runs it.
- Word files you can edit. Each document comes with your agency's cover and a filled table of contents, ready for your review cycle.
- Written again when you change an answer. Pick a new service or retitle an office, and the next draft says so everywhere it matters.
- No AI writes them. A fixed generator writes every document, so the same answers always give the same text.
Coming nextDrafted updates: when a source changes, FedXchange proposes new wording for a person to approve.
Incident Response Plan, section 4
Example
The Security Operations Center watches alerts from your log management service around the clock.
When an alert may be an incident, the analyst opens a ticket in your ticketing service and tells the Information System Security Officer within one hour.
27 policies · 21 procedures · 7 plans · 6 templates, rules of behavior, and references
Including
- Information Security Program Plan
- Incident Response Plan
- Information Security Continuous Monitoring (ISCM) Strategy
- Post-Quantum Cryptography Migration Plan
- Rules of Behavior — Privileged Users
Every real option, side by side
FedRAMP Marketplace products
Software, platform, and infrastructure services with a FedRAMP authorization, including the products many agencies get through Continuous Diagnostics and Mitigation (CDM): choose the product and FedXchange records that it comes through CDM.
Run by the government: 9 services in 8 of the 18 functions
Most never appear among your FedRAMP authorizations, so FedXchange lists them beside every choice.
- Identity and Access Management
- USAccess, General Services Administration (GSA)Login.gov, General Services Administration (GSA)
- Vulnerability Management
- Cyber Hygiene Vulnerability Scanning and Web Application Scanning, CISA
- SIEM and Log Management
- Logging Made Easy, CISA
- Network Security and Web Gateway
- Protective DNS, CISA
- Governance, Risk, and Compliance
- JCAM (formerly CSAM), Department of Justice
- Continuous Monitoring and Posture Management
- ScubaGear (Secure Cloud Business Applications), CISA
- Vulnerability Disclosure Platform
- Vulnerability Disclosure Policy Platform, CISA
- Learning Management System
- FedTalent, Department of the Interior, Interior Business Center
Get new federal governance by email
Sign up
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.
Who runs FedXchange
Free to use. FedXchange is built by Varry LLC, which also makes RMF Coach, hands-on courses and an authorization simulation for learning NIST RMF and FedRAMP.
Write your agency's policy set today
Anyone can sign up free with a work email or Google account. The trackers need no account.