SSP Studio guides ISSOs and ISSMs through an RMF-ready System Security Plan: FIPS 199 categorization, NIST 800-53 control implementation narratives, and OSCAL-ready output. Categorization and baseline selection are computed in code, not guessed.
Add information types, set C / I / A impact for each. The overall impact level is computed as the high-water mark, never guessed.
Draft 800-53 implementation statements from your system description and details. Gaps render as explicit 'needs information' placeholders.
Export PDF, DOCX, Markdown, and OSCAL SSP JSON, or hand off to the OSCAL Bridge for machine-readable validation.
Identify Controlled Unclassified Information, map it to the CUI Registry, and document it in your FIPS 199 security categorization.
Read the guideHow the Open Security Controls Assessment Language turns your System Security Plan into machine-readable data for automated compliance.
Read the guide