FreeEarly access now open
Security policies that name the tools your agency actually uses
FedXchange reads your FedRAMP authorizations, proposes the service you use for each of 18 security functions, and builds your policies, procedures, and plans around your answers. When CISA, OMB, or NIST changes something, it shows you which documents are affected.
Free to use. Built and run by Varry LLC.
Setup proposal
18 of 18 options
Identity provider
Your authorizationMatched to your FedRAMP authorization
SIEM and log management
Your platformCovered by your cloud platform's authorization
Vulnerability disclosure
Shared serviceCISA Vulnerability Disclosure Policy Platform
Learning management
Generic name until you choose“the learning management system”
The problem
Generic policies don't say what you actually do
Templates name nothing
Most policy templates say “the organization employs an automated tool.” Staff can't follow that, and assessors ask which tool you mean.
Guidance never stops moving
New CISA directives, OMB memoranda, and NIST revisions arrive all year. Finding which of your documents each one touches takes days.
Shared services go unnoticed
Services such as CDM, CISA's vulnerability disclosure platform, and Login.gov don't show up in your own FedRAMP authorizations, so tools that read only those miss them.
How it works
From your authorizations to a policy set in four steps
- 1Works today
Name your agency
FedXchange reads your agency's authorizations on the FedRAMP Marketplace and proposes the service you use for each security function, with government shared services listed beside each one.
- 2Works today
Confirm your choices
Accept or change each proposal, and tell FedXchange what your agency calls its offices and roles. Anything you leave open keeps a generic name, such as “the ticketing system”.
- 3Coming next
Get your documents
FedXchange writes 61 policies, procedures, and plans around your choices, checks each one against a plain-language writing standard, and exports Word files with your cover and headers.
- 4Works today
Stay current
A watch checks 9 groups of federal sources, most of them daily. When one changes, you see which of your documents cite it, and you decide what to do.
What you get
61 documents, written in plain language
- Word files with your agency's cover, running header, page numbers, and a filled table of contents
- Roles, not people: “the Chief Information Security Officer”, in your agency's own titles
- Every requirement traced to its source: 118 federal sources today
- Drafts only. Nothing is published until a person at your agency approves it
27
Policies
21
Procedures
7
Plans
6
Templates, rules of behavior, and references
Including
- Information Security Program Plan
- Incident Response Plan
- Information Security Continuous Monitoring (ISCM) Strategy
- Post-Quantum Cryptography Migration Plan
- Rules of Behavior — Privileged Users
Government shared services
10 of 18 functions have a government option
Identity and Access Management
USAccess
General Services Administration (GSA)
Identity and Access Management
Login.gov
General Services Administration (GSA)
Endpoint Detection and Response
CDM endpoint detection and response
CISA
Vulnerability Management
CDM vulnerability and configuration monitoring
CISA
Vulnerability Management
Cyber Hygiene Vulnerability Scanning and Web Application Scanning
CISA
SIEM and Log Management
CDM SIEM as a Service
CISA
SIEM and Log Management
Logging Made Easy
CISA
Network Security and Web Gateway
Protective DNS
CISA
Governance, Risk, and Compliance
JCAM (formerly CSAM)
Department of Justice
Asset Management and Discovery
CDM asset and device visibility
CISA
Continuous Monitoring and Posture Management
CDM agency and federal dashboards
CISA
Continuous Monitoring and Posture Management
ScubaGear (Secure Cloud Business Applications)
CISA
Vulnerability Disclosure Platform
Vulnerability Disclosure Policy Platform
CISA
Learning Management System
FedTalent
Department of the Interior, Interior Business Center
Governance watch
Know which documents a new directive touches
- FedRAMP Marketplacedaily
- CISA directivesdaily
- OMB memorandadaily
- NARA ISOO and CUI noticesdaily
- Executive orders (Federal Register)daily
- Proposed rules open for comment (Federal Register)daily
- Supply-chain orders and rules (FASCSA, Commerce ICTS, NDAA)daily
- NIST publication statusweekly
- FedRAMP and NIST sources on GitHubweekly
Works from your AI assistant
Set it up from a chat, if you prefer
You
Set up FedXchange for our agency and show me what you'd propose.
Assistant
I found your agency on the FedRAMP Marketplace. Here are 18 proposals and why each was chosen. 10 of them also have a government shared service you could use instead. Which should I change?
You
Vulnerability disclosure comes through CISA's platform.
Assistant
Here is the change. Shall I save it?
Free
Free to use, from the team behind RMF Coach
Also from Varry LLC
RMF Coach
Interactive NIST RMF and FedRAMP courses plus an authorization simulation for practitioners, teams, and students. Train the people who will use the policies FedXchange writes.
Be one of the first agencies to try it
Tell us who you are and we'll reply by email.