Skip to content

FedRAMP Export

The FedRAMP surface produces OSCAL exports from your system security documentation, in the machine-readable format assessors expect.

OSCAL, Open Security Controls Assessment Language, is a NIST file format (XML, JSON, or YAML) for security paperwork. The information inside an OSCAL file is the same information that has always lived in security documents: what your system is, which controls apply, how each is implemented, and what gaps remain. The difference is structure: instead of free-form pages a human has to read, an OSCAL file lays the facts out so a computer can read, validate, and compare them automatically.

Why it matters: assessors and agencies increasingly consume security documentation this way. The platform exports real OSCAL packages (RFC-0024-compliant SSP and POA&M structures) from the system details you maintain here. That saves retyping the same facts into another tool’s format, but it does not change who signs anything.

  1. Maintain your system details and control implementations in the platform.
  2. Export the OSCAL package.
  3. Validate and submit it yourself.

Exporting OSCAL does not make a system FedRAMP authorized. Authorization comes from the government’s process, not from a file format. An OSCAL file is evidence, not an ATO. See Shared Responsibility and the Glossary.

Try this in the platform