Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Presentation

OSCAL Monthly Workshop Series - Event #36: OSCAL - A "FastTrack" to agency contracting

June 18, 2025

Presenters

Mats Nahlinder - CEO and Co-Founder , Sunstone Secure
Robert Ficcaglia - CTO & Co-Founder , Sunstone Secure

Description

Instead of the traditional CSP-to-agency push, we flip the model:

OSCAL isn’t just about making it easier for CSPs to generate compliance documents—it’s about enabling agencies to define what matters to them and driving the market to meet their needs. With OSCAL, agencies can create a fully automated, risk-driven acquisition and continuous monitoring model. They can tailor compliance profiles using threat models and OSCAL catalogs, while CSPs can leverage “digital twins” to accelerate contracting. The validations created through this process can be immediately applied to automated continuous validation and ConMon from day one of system deployment. OSCAL and digital twin technology shift compliance from a static document exercise to a dynamic, continuous operational advantage, transforming the way agencies procure, deploy, and manage systems.

Downloads

Created June 25, 2025