FAQ
Questions people ask about FedXchange
Is FedXchange free?
Yes. There's no charge to use FedXchange. It's run by Varry LLC, which also makes RMF Coach, a training product for NIST RMF and FedRAMP. FedXchange is one way people find our other work.
Who is it for?
Federal security teams that write and maintain security policies: CISOs, information system security officers and managers, GRC staff, and the contractors who support them.
What works today?
FedXchange is in early access. Today it proposes a service for each of 18 security functions from your FedRAMP authorizations, records your choices and your titles for offices and roles, connects to AI assistants, and watches 9 groups of federal sources for changes. Writing the documents in the app, Word export, and drafted updates are coming next.
Which agencies can use it?
Any agency that appears on the FedRAMP Marketplace can start from its own authorizations. An agency with few or none still gets a full proposal: every function it hasn't chosen keeps a generic name until it does.
Is FedXchange FedRAMP authorized?
No. It runs on a standard Cloudflare account owned by Varry LLC. It's designed for content that can sit in an outside service: policies drafted from public sources, plus your choice of services and your role titles. Don't put Controlled Unclassified Information, system details, or classified information in it.
Is it affiliated with the government?
No. FedXchange is not affiliated with or endorsed by CISA, GSA, OMB, NARA, NIST, or the FedRAMP Program Management Office. It reads their public information and links to their services.
Does it use AI to write the documents?
No. A fixed generator writes every document from your confirmed answers, and FedXchange runs no AI model of its own. If you want the wording tailored, you can use your own AI assistant, under your agency's own terms with that provider.
Are the documents ready to sign?
They're drafts for your agency to review. They pass a plain-language writing check and cite their sources, but your agency decides what it adopts. Nothing here is legal advice.
How is this different from a GRC tool?
A GRC tool tracks controls, assessments, and findings. FedXchange writes the policy documents those controls point to. It doesn't replace your GRC system; it can name it in your documents.
We get some tools through CDM. Does that work?
Yes. A product you get through Continuous Diagnostics and Mitigation (CDM) is a software, platform, or infrastructure service on the FedRAMP Marketplace, so you choose it from the FedRAMP listings for that function and mark it as provided through CDM. Your documents name the product.
What about services the government runs, like USAccess?
8 of the 18 functions also list services the government runs itself, such as USAccess, CISA's Protective DNS, and CISA's vulnerability disclosure platform. Most never appear among your FedRAMP authorizations, so FedXchange shows them beside every choice. Choose one and your documents name it.
Can my whole team use it?
Yes. Invite colleagues to your agency as owners, editors, reviewers, or viewers. Each person signs in with their own work email.
When can we start?
We're opening access in stages. Request early access and we'll reply by email.