FedRAMP OSCAL SSP Lint

Validates a FedRAMP OSCAL system security plan JSON in your editor: required assemblies, RFC4122 UUID references, control-id format, timezone-stamped dates and the annual update clock. Runs entirely in your browser — nothing is uploaded.

Sweep the whole package and export the 3PAO report $29 once · one licence key per person or CI seat · 7-day full refund. Hand-review by a FedRAMP advisory consultant runs $150 to $300 an hour.

Same engine as the VS Code extension, byte for byte.

Get one email when this rule changes
We watch the regulation and vendor sources behind FedRAMP OSCAL SSP Lint every day. When a rule changes, you get a single email with what changed and the updated check. No newsletter.

Install free

Free for the file open in your editor - no key, no limit. The workspace sweep and the report ask for a key.

Open VSX (Cursor, VSCodium)npmMCP server (npx)Docker Hub
npx @readystack/fedramp-oscal-ssp-lint <file>
npx @readystack/fedramp-oscal-ssp-lint --mcp
docker run --rm -v "$PWD:/w" getreadystack/fedramp-oscal-ssp-lint /w

Team? One key for every ReadyStack linter, 5 seats, $149 once

Get the complete version $29

This page is the working piece. The full pack has everything below.

16 checks on a system-security-plan JSON, in your editor, before a validator returns the package

Hand-review by a FedRAMP advisory consultant runs $150 to $300 an hour

Buy the full version — $29

Questions people ask

What does FedRAMP OSCAL SSP Lint actually do?

It opens a system-security-plan JSON file and runs 16 checks against it: the five required OSCAL assemblies, metadata fields, RFC 4122 version 4 uuids, uuid references that must resolve inside the file, timezone offsets on last-modified, lower-dotted control ids such as ac-2.1, the FIPS 199 vocabulary, implementation-status props, and the 365-day continuous-monitoring clock. Each finding names a JSON path and the replacement text.

Who is this for?

Engineers and compliance leads at cloud service providers assembling a FedRAMP authorization package in OSCAL, and the 3PAO staff who read those packages. If you hand-write or generate system-security-plan JSON and the first thing that reads it is a validator rather than a person, this is aimed at you. It assumes no OSCAL tooling beyond a text editor.

Why is a free JSON schema validator not enough?

A schema validator answers with a pattern mismatch at a JSON pointer. It tells you that a string failed a regex, not that the uuid needs a version 4 nibble, nor which component the dangling component-uuid meant to name. It also has no opinion about a plan stamped 503 days ago, an overdue planned-completion-date, or the word TBD sitting in a narrative a reviewer reads.

What is free and what needs a licence key?

Free and offline: one system-security-plan JSON, all 16 checks, every finding with its JSON path, severity and the fix. That job is complete on its own. The licensed part is a different scope: it sweeps every OSCAL file in the workspace, resolves uuid references across files rather than within one, and writes a dated report to hand to your 3PAO.

What would this cost me otherwise?

Hand-review by a FedRAMP advisory consultant runs $150 to $300 an hour, and reading one package line by line is not a one-hour task. The alternative is free: submit, wait, and have the package returned with a schema path. The extension is $29 once, one licence key per person or CI seat, with a 7-day full refund.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.

ENDEJAESPT

Find a tool