Validates a FedRAMP OSCAL system security plan JSON in your editor: required assemblies, RFC4122 UUID references, control-id format, timezone-stamped dates and the annual update clock. Runs entirely in your browser — nothing is uploaded.
Same engine as the VS Code extension, byte for byte.
Free for the file open in your editor - no key, no limit. The workspace sweep and the report ask for a key.
Open VSX (Cursor, VSCodium)npmDocker Hubnpx @readystack/fedramp-oscal-ssp-lint <file> docker run --rm -v "$PWD:/w" getreadystack/fedramp-oscal-ssp-lint /w
Team? One key for every ReadyStack linter, 5 seats, $149 once
This page is the working piece. The full pack has everything below.
16 checks on a system-security-plan JSON, in your editor, before a validator returns the package
Hand-review by a FedRAMP advisory consultant runs $150 to $300 an hour
Buy the full version — $29It opens a system-security-plan JSON file and runs 16 checks against it: the five required OSCAL assemblies, metadata fields, RFC 4122 version 4 uuids, uuid references that must resolve inside the file, timezone offsets on last-modified, lower-dotted control ids such as ac-2.1, the FIPS 199 vocabulary, implementation-status props, and the 365-day continuous-monitoring clock. Each finding names a JSON path and the replacement text.
Engineers and compliance leads at cloud service providers assembling a FedRAMP authorization package in OSCAL, and the 3PAO staff who read those packages. If you hand-write or generate system-security-plan JSON and the first thing that reads it is a validator rather than a person, this is aimed at you. It assumes no OSCAL tooling beyond a text editor.
A schema validator answers with a pattern mismatch at a JSON pointer. It tells you that a string failed a regex, not that the uuid needs a version 4 nibble, nor which component the dangling component-uuid meant to name. It also has no opinion about a plan stamped 503 days ago, an overdue planned-completion-date, or the word TBD sitting in a narrative a reviewer reads.
Free and offline: one system-security-plan JSON, all 16 checks, every finding with its JSON path, severity and the fix. That job is complete on its own. The licensed part is a different scope: it sweeps every OSCAL file in the workspace, resolves uuid references across files rather than within one, and writes a dated report to hand to your 3PAO.
Hand-review by a FedRAMP advisory consultant runs $150 to $300 an hour, and reading one package line by line is not a one-hour task. The alternative is free: submit, wait, and have the package returned with a schema path. The extension is $29 once, one licence key per person or CI seat, with a 7-day full refund.
One question, answered by the person who built it. Your email only if you want the answer sent.