August 19, 2026
Christoph Puppe - Principal Enterprise Security Architect - NTT Data
OSCAL mostly lives in NIST/FedRAMP territory. This talk takes it elsewhere - BSI IT-Grundschutz and its next-generation Grundschutz++ - and reports what actually happens when you map a large, prose-heavy national baseline into OSCAL and JSON for real Compliance-as-Code. Having co-authored Grundschutz modules and advised the BSI transformation from the start, I offer a view from inside the source standard. A core focus: semantic pruning to fit large catalogs into AI models (the open-source OSCAL Pruner), plus practical tooling - viewers, SSP builders, compliance checkers, conversion pipelines - and the path from annual audit panic to continuous compliance, including where AI helps and where human judgment stays essential.