Compliance Framework

FedRAMP Moderate — code controls for federal authorization.

FedRAMP authorization requires demonstrating that NIST SP 800-53 controls are implemented and operating continuously. MergeGuide enforces the software development controls from the FedRAMP Moderate baseline at the code layer — with OSCAL-native evidence artifacts compatible with federal authorization workflows.

FedRAMP and the software development challenge

FedRAMP Moderate authorization requires implementing 325 NIST SP 800-53 controls across the System Security Plan. The SA (System and Services Acquisition) and SI (System and Information Integrity) control families require demonstrable secure development practices — including continuous testing, code reviews, and vulnerability detection.

For software vendors pursuing FedRAMP authorization, the hardest part is producing continuous evidence that code-level controls operate across the entire audit period — not just at assessment time. MergeGuide generates that evidence automatically.

MergeGuide includes policies that guide implementation of FedRAMP Moderate software development controls — with OSCAL-formatted evidence artifacts compatible with eMASS, Xacta, and agency authorization workflows.

FedRAMP Moderate control coverage

MergeGuide templates cover key FedRAMP Moderate software development controls:

  • SA-11 — Developer Testing and Evaluation: automated security testing at PR gate
  • SA-15 — Development Process, Standards, and Tools: enforced secure SDLC
  • SI-3 — Malicious Code Protection: detecting injection and code execution patterns
  • SI-10 — Information Input Validation: detecting missing input validation
  • IA-5 — Authenticator Management: detecting hardcoded credentials
  • AC-3 — Access Enforcement: detecting overprivileged access in code
  • SC-28 — Protection of Information at Rest: detecting unencrypted data handling

FedRAMP-mapped detection patterns

800-53 Control (FedRAMP Mod.) What MergeGuide Detects Severity
IA-5 — Authenticator ManagementHardcoded credentials, API keys, and secrets in source codeCritical
SI-10 — Input ValidationSQL injection — unparameterized queries with user-controlled dataCritical
SI-10 — Input ValidationCommand injection via unsanitized shell executionCritical
SC-28 — Protection at RestSensitive data stored without encryption in application codeHigh
SC-8 — Transmission ConfidentialityData transmitted over HTTP or deprecated TLS protocolsHigh
AC-3 — Access EnforcementWildcard IAM permissions in infrastructure-as-code definitionsHigh
SA-11 — Developer TestingMissing security test coverage detected at PR evaluation gateMedium
📄

OSCAL-native evidence

MergeGuide generates OSCAL Assessment Results and Component Definitions natively — the format required by federal agencies for FedRAMP authorization packages. Evidence is importable directly into eMASS, RegScale, and Xacta without transformation.

🔄

Continuous authorization support

FedRAMP's move toward Continuous Authorization (ConMon) requires ongoing evidence of control operation. MergeGuide generates signed evidence artifacts at every commit and PR merge, creating a continuous audit trail that satisfies ConMon reporting requirements.

🏛️

GovCloud deployment

Enterprise customers pursuing FedRAMP High or IL4/IL5 authorization can deploy MergeGuide in a dedicated GovCloud environment. Air-gapped deployment is available for the most restrictive government tenants. Contact sales for GovCloud configuration details.

Pursuing FedRAMP authorization?

See how MergeGuide enforces FedRAMP Moderate software development controls and generates OSCAL-compatible evidence artifacts in a live demo.

Book a demo Talk to sales