Skip to content

FreeEarly access now open

Security policies that name the tools your agency actually uses

FedXchange reads your FedRAMP authorizations, proposes the service you use for each of 18 security functions, and builds your policies, procedures, and plans around your answers. When CISA, OMB, or NIST changes something, it shows you which documents are affected.

Free to use. Built and run by Varry LLC.

Setup proposal

18 of 18 options

  • Identity provider

    Your authorization

    Matched to your FedRAMP authorization

  • SIEM and log management

    Your platform

    Covered by your cloud platform's authorization

  • Vulnerability disclosure

    Shared service

    CISA Vulnerability Disclosure Policy Platform

  • Learning management

    Generic name until you choose

    “the learning management system”

Nothing is used until you confirm it.Review and confirm
An example of the setup proposal: each security function shows the proposed service and why it was proposed.

The problem

Generic policies don't say what you actually do

Templates name nothing

Most policy templates say “the organization employs an automated tool.” Staff can't follow that, and assessors ask which tool you mean.

Guidance never stops moving

New CISA directives, OMB memoranda, and NIST revisions arrive all year. Finding which of your documents each one touches takes days.

What you really run gets missed

Services the government runs, such as USAccess and CISA's Protective DNS, don't show up in your FedRAMP authorizations, and a product you get through CDM often isn't listed under your agency either. Tools that read only your authorizations miss both.

How it works

From your authorizations to a policy set in four steps

FedXchange is in early access. Steps marked “Coming next” are being built now.
  1. 1Works today

    Name your agency

    FedXchange reads your agency's authorizations on the FedRAMP Marketplace and proposes the service you use for each security function, with government shared services listed beside each one.

  2. 2Works today

    Confirm your choices

    Accept or change each proposal, and tell FedXchange what your agency calls its offices and roles. Anything you leave open keeps a generic name, such as “the ticketing system”.

  3. 3Coming next

    Get your documents

    FedXchange writes 61 policies, procedures, and plans around your choices, checks each one against a plain-language writing standard, and exports Word files with your cover and headers.

  4. 4Works today

    Stay current

    A watch checks 9 groups of federal sources, most of them daily. When one changes, you see which of your documents cite it, and you decide what to do.

Read the full walkthrough

What you get

61 documents, written in plain language

Every document names your services and your roles, cites the federal sources it rests on, and must pass a plain-language writing check before you see it.
  • Word files with your agency's cover, running header, page numbers, and a filled table of contents
  • Roles, not people: “the Chief Information Security Officer”, in your agency's own titles
  • Every requirement traced to its source: 118 federal sources today
  • Drafts only. Nothing is published until a person at your agency approves it
Coming next

27

Policies

21

Procedures

7

Plans

6

Templates, rules of behavior, and references

Including

  • Information Security Program Plan
  • Incident Response Plan
  • Information Security Continuous Monitoring (ISCM) Strategy
  • Post-Quantum Cryptography Migration Plan
  • Rules of Behavior — Privileged Users

FedRAMP products and government services

Every real option, side by side

For each function, FedXchange lists the FedRAMP Marketplace products that fit it (157 listings in all, as of October 3, 2026), your agency's own first, and the services the government runs itself. Pick one and your documents name it.

FedRAMP Marketplace

Software, platform, and infrastructure services with a FedRAMP authorization

Including the products many agencies get through Continuous Diagnostics and Mitigation (CDM): choose the product and FedXchange records that it comes through CDM.

See every FedRAMP product by function

Run by the government

9 services in 8 of the 18 functions

Most never appear among your FedRAMP authorizations, so FedXchange lists them beside every choice.

  • Identity and Access Management

    USAccess

    General Services Administration (GSA)

  • Identity and Access Management

    Login.gov

    General Services Administration (GSA)

  • Vulnerability Management

    Cyber Hygiene Vulnerability Scanning and Web Application Scanning

    CISA

  • SIEM and Log Management

    Logging Made Easy

    CISA

  • Network Security and Web Gateway

    Protective DNS

    CISA

  • Governance, Risk, and Compliance

    JCAM (formerly CSAM)

    Department of Justice

  • Continuous Monitoring and Posture Management

    ScubaGear (Secure Cloud Business Applications)

    CISA

  • Vulnerability Disclosure Platform

    Vulnerability Disclosure Policy Platform

    CISA

  • Learning Management System

    FedTalent

    Department of the Interior, Interior Business Center

Governance watch

Know which documents a new directive touches

FedXchange checks the sources your policies cite. When one changes, it lists the documents that cite that source and waits for your decision. Nothing in your documents changes on its own.Works today
  • FedRAMP Marketplacedaily
  • CISA directivesdaily
  • OMB memorandadaily
  • NARA ISOO and CUI noticesdaily
  • Executive orders (Federal Register)daily
  • Proposed rules open for comment (Federal Register)daily
  • Supply-chain orders and rules (FASCSA, Commerce ICTS, NDAA)daily
  • NIST publication statusweekly
  • FedRAMP and NIST sources on GitHubweekly

Works from your AI assistant

Set it up from a chat, if you prefer

Connect Claude, Cursor, VS Code, or any assistant that supports the Model Context Protocol (MCP). Your assistant can review proposals, record your choices, and check for changes. Every change shows a preview and waits for your yes.

You

Set up FedXchange for our agency and show me what you'd propose.

Assistant

I found your agency on the FedRAMP Marketplace. Here are 18 proposals and why each was chosen. Which should I change?

You

Our EDR tool comes through CDM, and vulnerability disclosure goes through CISA's platform.

Assistant

Which EDR product does CDM give you? I'll choose its FedRAMP listing and mark it as provided through CDM. Here are both changes. Shall I save them?

How assistants connect, and what they can do

Free

Free to use, from the team behind RMF Coach

FedXchange costs nothing to use. It's built by Varry LLC, which also makes RMF Coach, a hands-on way to learn NIST RMF and FedRAMP.

Also from Varry LLC

RMF Coach

Interactive NIST RMF and FedRAMP courses plus an authorization simulation for practitioners, teams, and students. Train the people who will use the policies FedXchange writes.

Be one of the first agencies to try it

Tell us who you are and we'll reply by email.

Request early access