How it works
From your FedRAMP authorizations to a policy set
Step 1
Name your agency
How each proposal is chosen
- 1
A product your agency authorized
If one of your agency's FedRAMP authorizations matches the function by name or by the Marketplace's own tag, FedXchange proposes it.
- 2
A cloud platform that covers it
If not, and a cloud platform you authorized covers the capability, FedXchange proposes the platform and says why.
- 3
The generic name
Otherwise the documents use a plain generic name, such as “the vulnerability scanner”, until you choose.
Services the government runs itself, such as USAccess or CISA's Protective DNS, are never chosen for you, because the Marketplace doesn't record who uses them. They're listed beside each proposal. A product you get through CDM is different: it's on the Marketplace, so you choose it from the listings and mark it as provided through CDM.
Step 2
Confirm 18 choices
| Function | FedRAMP listings | Until you choose, documents say | Also available |
|---|---|---|---|
| Identity and Access Management | 17 listingsOkta IDaaS Regulated Cloud; Login.gov; Duo Federal; and more | “the identity provider” |
|
| Endpoint Detection and Response | 9 listingsCrowdStrike Falcon Platform for Government; SentinelOne Singularity Platform High; Trellix GovCloud Security Platform; and more | “the endpoint detection and response (EDR) tool” |
|
| Vulnerability Management | 4 listingsTenable Government Solutions; Qualys Cloud Platform; Qualys Government Platform; and more | “the vulnerability scanner” |
|
| SIEM and Log Management | 11 listingsSplunk Cloud Platform for FedRAMP Moderate; Datadog for Government; Dynatrace Platform; and more | “the security information and event management (SIEM) system” |
|
| Mobile Device Management / Endpoint Configuration | 5 listingsIvanti Neurons for MDM (Formerly MobileIron); NinjaOne for Government; Omnissa Government Services | “the mobile device management (MDM) tool” | None |
| Network Security and Web Gateway | 14 listingsContent Delivery Services; Palo Alto Networks Government Cloud Services; Cloudflare for Government - High; and more | “the secure web gateway” |
|
| IT Service Management / Ticketing | 6 listingsGovernment Community Cloud; Atlassian Government Cloud; Zendesk Customer Support and Help Desk Platform; and more | “the ticketing system” | None |
| Governance, Risk, and Compliance | 14 listingsDiligent One Platform (D1P); TalaTek intelligent Governance and Risk Integrated Solution (TiGRIS); RegScale CCM; and more | “the GRC system” |
|
| Cloud Infrastructure Platform | 8 listingsAzure Commercial Cloud; AWS US East/West; Azure Government (includes Dynamics 365); and more | “the cloud platform” | None |
| Backup and Recovery | 10 listingsDruva Data Resiliency Cloud; AvePoint Online Services for US Government (AOS-UG); Commvault Cloud for Government; and more | “the backup service” | None |
| Encryption and Key Management | 7 listingsKeyfactor for Government; Vaultara Flare Services; Virtru Data Security Platform | “the key management service” | None |
| Email and Communication Security | 11 listingsTrellix Email Security GovCloud; Proofpoint Email and Information Protection Service; Proofpoint Targeted Attack Protection; and more | “the email security gateway” | None |
| Asset Management and Discovery | 8 listingsArmis FedRAMP Edition (AFE); Tanium Cloud for US Government (TC-USG); Axonius Asset Cloud; and more | “the asset inventory tool” |
|
| Security Awareness Training | 2 listingsKnowBe4 Platform; Cofense PhishMe | “the security awareness platform” | None |
| Continuous Monitoring and Posture Management | 8 listingsWiz for U.S. Government; Aqua Platform for Government; Orca Cloud Security Platform; and more | “the cloud security posture tool” |
|
| Document Management / Policy Library | 7 listingsMicrosoft 365 Government Community Cloud & Supporting Services; Box Enterprise Cloud Content Collaboration Platform; Google Workspace; and more | “the document library” | None |
| Vulnerability Disclosure Platform | 3 listingsOn-Demand Security Testing Platform; HackerOne Continuous Security Testing Platform; Bugcrowd for Government (BCGOV) | “the vulnerability disclosure platform” |
|
| Learning Management System | 13 listingsCornerstone Galaxy; PowerTrain Government Learning Enclave - SaaS; Percipio; and more | “the learning management system (LMS)” |
|
Listings from the FedRAMP Marketplace as of October 3, 2026. See every product by function
Your offices and roles, in your words
The documents name roles, never people. FedXchange lists the 46 offices and roles they mention, from the Authorizing Official to the Senior Agency Official for Privacy, and you set the title and acronym your agency uses for each.
Step 3
Get your documents
Plain language, checked
Every document must pass a plain-language writing standard: short sentences, active voice, “must” rather than “shall”. A document that fails is not exported.
Your services and roles throughout
Where a template would say “an automated tool”, your document names the service you chose, or the generic name you left in place.
Sources you can check
Requirements come from 118 federal sources: OMB memoranda, CISA directives, NIST publications, executive orders, and laws. Each document lists the ones it cites.
Word files ready to route
Exports carry your agency's cover, running header, page numbers, and a table of contents that's already filled in.
Step 4
Stay current as guidance changes
| Source | Checked |
|---|---|
| FedRAMP Marketplace | daily |
| CISA directives | daily |
| OMB memoranda | daily |
| NARA ISOO and CUI notices | daily |
| Executive orders (Federal Register) | daily |
| Proposed rules open for comment (Federal Register) | daily |
| Supply-chain orders and rules (FASCSA, Commerce ICTS, NDAA) | daily |
| NIST publication status | weekly |
| FedRAMP and NIST sources on GitHub | weekly |
Drafted updates are coming next: FedXchange will propose the new wording, check it against the same writing standard, and show it side by side with the current text for a person to approve.
Optional
Tailor the wording with your own AI
- Service names, role names, control tags, and citations are locked; a draft that changes one is refused.
- Tailored text goes through the same writing check as everything else.
- A person approves each change from a side-by-side comparison.