Skip to content

Know which federal guidance changed, and map the tools your agency actually runs

Today, anyone can search federal cybersecurity, privacy, and technology governance from 1974 on, and agencies in early access can map their FedRAMP authorizations to 18 security functions. Next, FedXchange will write 61 plain-language policies, procedures, and plans that name the services you confirm.

Free to use. Built and run by Varry LLC.

Setup proposal

Example · early access

  • Identity provider

    Your authorization

    Matched to your FedRAMP authorization

  • SIEM and log management

    Your platform

    Covered by your cloud platform's authorization

  • Vulnerability disclosure

    Shared service

    CISA Vulnerability Disclosure Policy Platform

  • Learning management

    Generic name until you choose

    “the learning management system”

Nothing is used until you confirm it.How proposals are chosen
An example of the setup proposal agencies in early access see: each security function shows the proposed service and why it was proposed.

Generic policies don't say what you actually do

  • Templates name nothing

    Most policy templates say “the organization employs an automated tool.” Staff can't follow that, and assessors ask which tool you mean.

  • Guidance never stops moving

    New CISA directives, OMB memoranda, and NIST revisions arrive all year. Finding which of your documents each one touches takes days.

  • What you really run gets missed

    Services the government runs, such as USAccess and CISA's Protective DNS, don't show up in your FedRAMP authorizations. A product you get through Continuous Diagnostics and Mitigation (CDM) often isn't listed under your agency either. Tools that read only your authorizations miss both.

What you can use today

The governance tracker and the newsletter are open to anyone, with no account. Agency setup, the governance watch, and AI assistants work today for agencies in early access.
  • Open to anyone

    Governance tracker

    Federal cybersecurity, privacy, and technology governance from the Privacy Act of 1974 to today: laws, executive orders, OMB memoranda, CISA directives, NIST publications, and contract rules, each with its status. Search it, filter it, follow it by feed, or download it as a spreadsheet.

    Documents
    631
    In effect
    371
    Proposed
    19
    No longer in effect
    241

    Counted from the tracker on October 5, 2026.

    Open the governance tracker

  • Open to anyone

    Newsletter and alerts

    A weekly email on Fridays with what FedXchange's daily check of federal sources found, and an alert on the day it finds something new, if you want one. Free, with a one-click unsubscribe.

    Sign up belowAbout the newsletter

  • Early access

    Agency setup

    FedXchange reads your agency's FedRAMP authorizations, proposes a service for each of 18 security functions, and lists the government's shared services beside each one. You confirm every choice and set your own titles for 46 offices and roles.

    How setup works

  • Early access

    Governance watch

    The watch checks 9 groups of federal sources, most of them daily. When one changes, your agency sees which of the 61 planned documents cite it, and acts on it or dismisses it.

    What the watch checks

  • Early access

    AI assistants

    Connect Claude, Cursor, VS Code, or any assistant that supports the Model Context Protocol (MCP) to review proposals and record your choices. Every change shows a preview and waits for your yes.

    How assistants connect

61 documents, written in plain language

Next, FedXchange will write policies, procedures, and plans from the choices you confirmed. Each will name your services and your roles, cite the federal sources it rests on, and pass a plain-language writing check. They will be drafts: nothing is final until a person at your agency approves it.
Coming next

After that: drafted updates. When a source changes, FedXchange will propose new wording for a person to approve.

27 policies · 21 procedures · 7 plans · 6 templates, rules of behavior, and references

Including

  • Information Security Program Plan
  • Incident Response Plan
  • Information Security Continuous Monitoring (ISCM) Strategy
  • Post-Quantum Cryptography Migration Plan
  • Rules of Behavior — Privileged Users

Planned export: Word files with your agency's cover, running header, page numbers, and a filled table of contents.

Every real option, side by side

For each function, FedXchange lists the FedRAMP Marketplace products that fit it (157 listings in all, as of October 5, 2026), your agency's own first, and the services the government runs itself. Pick one and FedXchange records it for your agency.

FedRAMP Marketplace products

Software, platform, and infrastructure services with a FedRAMP authorization, including the products many agencies get through Continuous Diagnostics and Mitigation (CDM): choose the product and FedXchange records that it comes through CDM.

See every FedRAMP product by function (open to anyone)

Run by the government: 9 services in 8 of the 18 functions

Most never appear among your FedRAMP authorizations, so FedXchange lists them beside every choice.

Identity and Access Management
USAccess, General Services Administration (GSA)Login.gov, General Services Administration (GSA)
Vulnerability Management
Cyber Hygiene Vulnerability Scanning and Web Application Scanning, CISA
SIEM and Log Management
Logging Made Easy, CISA
Network Security and Web Gateway
Protective DNS, CISA
Governance, Risk, and Compliance
JCAM (formerly CSAM), Department of Justice
Continuous Monitoring and Posture Management
ScubaGear (Secure Cloud Business Applications), CISA
Vulnerability Disclosure Platform
Vulnerability Disclosure Policy Platform, CISA
Learning Management System
FedTalent, Department of the Interior, Interior Business Center

Get new federal governance by email

Each Friday, a short email lists what the watch found that week: new documents, changes in status, and comment deadlines. Add instant alerts if you want them; after you confirm, you can limit alerts to the issuers or topics you follow. No account needed.

Sign up

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.

Who runs FedXchange

Free to use. FedXchange is built by Varry LLC, which also makes RMF Coach, hands-on courses and an authorization simulation for learning NIST RMF and FedRAMP.

Be one of the first agencies to try it

Tell us who you are and we'll reply by email. The governance tracker is open to everyone now.