SecBaseline/SSP Studio
For federal information systems · NIST SP 800-53 Rev 5 · FIPS 199 · OSCAL
RMF · 800-53 Rev 5 · OSCAL

Your System Security Plan,
drafted right.

SSP Studio guides ISSOs and ISSMs through an RMF-ready System Security Plan — FIPS 199 categorization, NIST 800-53 control implementation narratives, and OSCAL-ready output. Categorization and baseline selection are computed in code, not guessed.

System Security Plan
Acme Federal System
AFS-001 · Major Application
Confidentiality
Moderate
Integrity
Moderate
Availability
Low
Overall (FIPS 199 high-water mark)
Moderate
AC-2Account Management
Implemented
IA-2Identification & Authentication
Implemented
AU-2Event Logging
Partial
SC-8Transmission Confidentiality
Inherited
CP-9System Backup
Planned

FIPS 199 categorization

Add information types, set C / I / A impact for each. The overall impact level is computed as the high-water mark — never guessed.

AI-assisted control narratives

Draft 800-53 implementation statements from your system description and details. Gaps render as explicit 'needs information' placeholders.

OSCAL-ready export

Export PDF, DOCX, Markdown, and OSCAL SSP JSON, or hand off to the OSCAL Bridge for machine-readable validation.