The Open Security Controls Assessment Language (OSCAL) is a NIST-led initiative created in partnership with industry to improve and automate security and compliance workflows. It introduces open, machine-readable formats in XML, JSON, and YAML that simplify control-based risk assessments and compliance activities. Through automation, OSCAL can reduce audit timelines from months to just minutes, decrease the likelihood of human error, and help organizations adapt more quickly to the changing regulatory requirements. OSCAL also supports hardware security by enabling machine-readable descriptions of hardware security controls and compliance data, which allows for automated assessment, continuous monitoring, and lifecycle risk management for hardware components alongside software assets. As a result, security teams can spend less time managing documentation and more time addressing actual cybersecurity risks.
Visit the OSCAL website, which provides a detailed overview of the OSCAL project, including tutorials, concepts, references, downloads, and much more.
OSCAL is organized in a series of layers that each provides a set of models.
A model represents an information structure supporting a specific operational purpose or concept.
Each model is comprised of information structures that form an information model for each OSCAL model. This information model is then bound to multiple serialization formats (i.e., XML, JSON, YAML), which represent a concrete data model. Thus, a data model defines how to represent an OSCAL information model in a serialized format. While the syntax of each format differs, all formats for a given model represent the same set of information or information model. In this way, OSCAL content expressed in one of the supported formats ( XML, JSON, or YAML) can be translated into any of the other supported formats without data loss.
The OSCAL layers and models are:
The release state of each model, along with download links for the latest versions of XML and JSON schema for each model are provided in the table, below. YAML is also supported through conversion between JSON and YAML. Since YAML is a superset of JSON, some YAML tooling allows JSON schema to be used for YAML validation. In this way, the provided JSON schema supports both JSON and YAML.
| Layer | Model | Current State | Reference | Schemas |
|---|---|---|---|---|
| Control | Catalog | Released | XML, JSON/YAML | XML, JSON/YAML |
| Control | Profile | Released | XML, JSON/YAML | XML, JSON/YAML |
| Control | Mapping | Released | XML, JSON/YAML | XML, JSON/YAML |
| Implementation | Component Definition | Released | XML, JSON/YAML | XML, JSON/YAML |
| Implementation | System Security Plan | Released | XML, JSON/YAML | XML, JSON/YAML |
| Assessment | Assessment Plan | Released | XML, JSON/YAML | XML, JSON/YAML |
| Assessment | Assessment Results | Released | XML, JSON/YAML | XML, JSON/YAML |
| Assessment | Plan of Action and Milestones | Released | XML, JSON/YAML | XML, JSON/YAML |
The OSCAL GitHub repository holds the actual OSCAL schemas, examples, documentation source files, and other resources. The NIST team welcomes public contributions to this project. If you are interested in contributing, please review the site for ideas and information on how to get started.
NIST also maintains several public GitHub repositories associated with the OSCAL project:
OSCAL content maintained by NIST:
OSCAL tools and libraries:
OSCAL Metaschema:
The NIST team welcomes public contributions to this project. If you are interested in contributing, please review the contributor documentation for ideas and information on how to get started.
The NIST OSCAL team is hosting several types of events:
In addition to the monthly OSCAL workshops, the NIST OSCAL team hosts meetings with the OSCAL community on different topics related to the OSCAL development. All meetings are announced through our mailing list. Please subscribe to NIST OSCAL mailing lists to stay informed and to receive invitations to OSCAL meetings.
OSCAL mailing lists:
-- [email protected] for communication among parties interested in contributing to the development of OSCAL or exchanging ideas. Subscribe by sending an email to [email protected]. To unsubscribe send an email to [email protected].
-- [email protected] for low-frequency updates on the status of the OSCAL project. Subscribe by sending an email to [email protected]. To unsubscribe send an email to [email protected].
NIST OSCAL GitHub (public): https://www.github.com/usnistgov/OSCAL and https://www.github.com/usnistgov/oscal-content
OSCAL lobby on Gitter (chat channel with the community): https://gitter.im/usnistgov-OSCAL/Lobby (STRONGLY RECOMMENDED)
OSCAL Community Websites:
US OSCAL Community-maintained: https://github.com/oscal-club/awesome-oscal
US OSCAL Community-maintained: https://oscal.io
EU OSCAL Community-maintained: https://euroscal.eu
Security and Privacy: assurance, audit & accountability, controls assessment, risk assessment, security automation, system authorization, systems security engineering
Technologies: cloud & virtualization