FedRAMP OSCAL SSP Lint

Validates a FedRAMP OSCAL system security plan JSON in your editor: required assemblies, RFC4122 UUID references, control-id format, timezone-stamped dates and the annual update clock. Runs entirely in your browser — nothing is uploaded.

Sweep the whole package and export the 3PAO report $29 once · one licence key per person or CI seat · 7-day full refund. Hand-review by a FedRAMP advisory consultant runs $150 to $300 an hour.

Same engine as the VS Code extension, byte for byte.

Install free

Free for the file open in your editor - no key, no limit. The workspace sweep and the report ask for a key.

Open VSX (Cursor, VSCodium)npmDocker Hub
npx @readystack/fedramp-oscal-ssp-lint <file>
docker run --rm -v "$PWD:/w" getreadystack/fedramp-oscal-ssp-lint /w

Team? One key for every ReadyStack linter, 5 seats, $149 once

Get one email when this rule changes
We watch the regulation and vendor sources behind FedRAMP OSCAL SSP Lint every day. When a rule changes, you get a single email with what changed and the updated check. No newsletter.

Get the complete version $29

This page is the working piece. The full pack has everything below.

16 checks on a system-security-plan JSON, in your editor, before a validator returns the package

Hand-review by a FedRAMP advisory consultant runs $150 to $300 an hour

Buy the full version — $29

Questions people ask

What does FedRAMP OSCAL SSP Lint actually do?

It opens a system-security-plan JSON file and runs 16 checks against it: the five required OSCAL assemblies, metadata fields, RFC 4122 version 4 uuids, uuid references that must resolve inside the file, timezone offsets on last-modified, lower-dotted control ids such as ac-2.1, the FIPS 199 vocabulary, implementation-status props, and the 365-day continuous-monitoring clock. Each finding names a JSON path and the replacement text.

Who is this for?

Engineers and compliance leads at cloud service providers assembling a FedRAMP authorization package in OSCAL, and the 3PAO staff who read those packages. If you hand-write or generate system-security-plan JSON and the first thing that reads it is a validator rather than a person, this is aimed at you. It assumes no OSCAL tooling beyond a text editor.

Why is a free JSON schema validator not enough?

A schema validator answers with a pattern mismatch at a JSON pointer. It tells you that a string failed a regex, not that the uuid needs a version 4 nibble, nor which component the dangling component-uuid meant to name. It also has no opinion about a plan stamped 503 days ago, an overdue planned-completion-date, or the word TBD sitting in a narrative a reviewer reads.

What is free and what needs a licence key?

Free and offline: one system-security-plan JSON, all 16 checks, every finding with its JSON path, severity and the fix. That job is complete on its own. The licensed part is a different scope: it sweeps every OSCAL file in the workspace, resolves uuid references across files rather than within one, and writes a dated report to hand to your 3PAO.

What would this cost me otherwise?

Hand-review by a FedRAMP advisory consultant runs $150 to $300 an hour, and reading one package line by line is not a one-hour task. The alternative is free: submit, wait, and have the package returned with a schema path. The extension is $29 once, one licence key per person or CI seat, with a 7-day full refund.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.

ENDEJAESPT

Find a tool