SSP Studio guides ISSOs and ISSMs through an RMF-ready System Security Plan — FIPS 199 categorization, NIST 800-53 control implementation narratives, and OSCAL-ready output. Categorization and baseline selection are computed in code, not guessed.
Add information types, set C / I / A impact for each. The overall impact level is computed as the high-water mark — never guessed.
Draft 800-53 implementation statements from your system description and details. Gaps render as explicit 'needs information' placeholders.
Export PDF, DOCX, Markdown, and OSCAL SSP JSON, or hand off to the OSCAL Bridge for machine-readable validation.