Skip to content

FreeEarly access now open

Security policies that name the tools your agency actually uses

FedXchange reads your FedRAMP authorizations, proposes the service you use for each of 18 security functions, and builds your policies, procedures, and plans around your answers. When CISA, OMB, or NIST changes something, it shows you which documents are affected.

Free to use. Built and run by Varry LLC.

Setup proposal

18 of 18 options

  • Identity provider

    Your authorization

    Matched to your FedRAMP authorization

  • SIEM and log management

    Your platform

    Covered by your cloud platform's authorization

  • Vulnerability disclosure

    Shared service

    CISA Vulnerability Disclosure Policy Platform

  • Learning management

    Generic name until you choose

    “the learning management system”

Nothing is used until you confirm it.Review and confirm
An example of the setup proposal: each security function shows the proposed service and why it was proposed.

The problem

Generic policies don't say what you actually do

Templates name nothing

Most policy templates say “the organization employs an automated tool.” Staff can't follow that, and assessors ask which tool you mean.

Guidance never stops moving

New CISA directives, OMB memoranda, and NIST revisions arrive all year. Finding which of your documents each one touches takes days.

Shared services go unnoticed

Services such as CDM, CISA's vulnerability disclosure platform, and Login.gov don't show up in your own FedRAMP authorizations, so tools that read only those miss them.

How it works

From your authorizations to a policy set in four steps

FedXchange is in early access. Steps marked “Coming next” are being built now.
  1. 1Works today

    Name your agency

    FedXchange reads your agency's authorizations on the FedRAMP Marketplace and proposes the service you use for each security function, with government shared services listed beside each one.

  2. 2Works today

    Confirm your choices

    Accept or change each proposal, and tell FedXchange what your agency calls its offices and roles. Anything you leave open keeps a generic name, such as “the ticketing system”.

  3. 3Coming next

    Get your documents

    FedXchange writes 61 policies, procedures, and plans around your choices, checks each one against a plain-language writing standard, and exports Word files with your cover and headers.

  4. 4Works today

    Stay current

    A watch checks 9 groups of federal sources, most of them daily. When one changes, you see which of your documents cite it, and you decide what to do.

Read the full walkthrough

What you get

61 documents, written in plain language

Every document names your services and your roles, cites the federal sources it rests on, and must pass a plain-language writing check before you see it.
  • Word files with your agency's cover, running header, page numbers, and a filled table of contents
  • Roles, not people: “the Chief Information Security Officer”, in your agency's own titles
  • Every requirement traced to its source: 118 federal sources today
  • Drafts only. Nothing is published until a person at your agency approves it
Coming next

27

Policies

21

Procedures

7

Plans

6

Templates, rules of behavior, and references

Including

  • Information Security Program Plan
  • Incident Response Plan
  • Information Security Continuous Monitoring (ISCM) Strategy
  • Post-Quantum Cryptography Migration Plan
  • Rules of Behavior — Privileged Users

Government shared services

10 of 18 functions have a government option

Shared services don't appear in your own FedRAMP authorizations, so FedXchange lists them beside every choice. Pick one and your documents name it.
  • Identity and Access Management

    USAccess

    General Services Administration (GSA)

  • Identity and Access Management

    Login.gov

    General Services Administration (GSA)

  • Endpoint Detection and Response

    CDM endpoint detection and response

    CISA

  • Vulnerability Management

    CDM vulnerability and configuration monitoring

    CISA

  • Vulnerability Management

    Cyber Hygiene Vulnerability Scanning and Web Application Scanning

    CISA

  • SIEM and Log Management

    CDM SIEM as a Service

    CISA

  • SIEM and Log Management

    Logging Made Easy

    CISA

  • Network Security and Web Gateway

    Protective DNS

    CISA

  • Governance, Risk, and Compliance

    JCAM (formerly CSAM)

    Department of Justice

  • Asset Management and Discovery

    CDM asset and device visibility

    CISA

  • Continuous Monitoring and Posture Management

    CDM agency and federal dashboards

    CISA

  • Continuous Monitoring and Posture Management

    ScubaGear (Secure Cloud Business Applications)

    CISA

  • Vulnerability Disclosure Platform

    Vulnerability Disclosure Policy Platform

    CISA

  • Learning Management System

    FedTalent

    Department of the Interior, Interior Business Center

Governance watch

Know which documents a new directive touches

FedXchange checks the sources your policies cite. When one changes, it lists the documents that cite that source and waits for your decision. Nothing in your documents changes on its own.Works today
  • FedRAMP Marketplacedaily
  • CISA directivesdaily
  • OMB memorandadaily
  • NARA ISOO and CUI noticesdaily
  • Executive orders (Federal Register)daily
  • Proposed rules open for comment (Federal Register)daily
  • Supply-chain orders and rules (FASCSA, Commerce ICTS, NDAA)daily
  • NIST publication statusweekly
  • FedRAMP and NIST sources on GitHubweekly

Works from your AI assistant

Set it up from a chat, if you prefer

Connect Claude, Cursor, VS Code, or any assistant that supports the Model Context Protocol (MCP). Your assistant can review proposals, record your choices, and check for changes. Every change shows a preview and waits for your yes.

You

Set up FedXchange for our agency and show me what you'd propose.

Assistant

I found your agency on the FedRAMP Marketplace. Here are 18 proposals and why each was chosen. 10 of them also have a government shared service you could use instead. Which should I change?

You

Vulnerability disclosure comes through CISA's platform.

Assistant

Here is the change. Shall I save it?

How assistants connect, and what they can do

Free

Free to use, from the team behind RMF Coach

FedXchange costs nothing to use. It's built by Varry LLC, which also makes RMF Coach, a hands-on way to learn NIST RMF and FedRAMP.

Also from Varry LLC

RMF Coach

Interactive NIST RMF and FedRAMP courses plus an authorization simulation for practitioners, teams, and students. Train the people who will use the policies FedXchange writes.

Be one of the first agencies to try it

Tell us who you are and we'll reply by email.

Request early access