Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Security Content Automation Protocol SCAP

SCAP 1.4

SCAP 1.4 is the current final release of the Security Content Automation Protocol (SCAP). This page lists the publications, schemas, tools, component specifications, identification schemes, metrics, and integrity specifications that comprise SCAP version 1.4.

SCAP 1.4 final release
Status: Final · Version: 1.4
Publications: NIST Special Publication (SP) 800-126 Rev. 4 and NIST Special Publication (SP) 800-126A Rev. 4.

Protocol

SCAP: Security Content Automation Protocol

Tools

SCAP Content Validation Tool (scapval)

  • Version: 1.4.1
  • Released: 12/22/2025
  • Download: SCAP Content Validation Tool
  • File hash (sha-256): ddafadba7a1682efad1c30f175ae2be139bd2d253610dcb3d29fd37966eacee6

The SCAP Content Validation Tool validates the technical correctness of an SCAP data stream against the requirements defined for a specific use case in NIST Special Publication (SP) 800-126. This version of the tool supports the validation of content conforming to SCAP versions 1.2, 1.3, and 1.4. For detailed usage instructions, execute the command scapval.bat -h.

Languages

Checklist and assessment languages

  • XCCDF: The Extensible Configuration Checklist Description Format
    Version: 1.2
    Website: XCCDF
  • OVAL®: Open Vulnerability and Assessment Language
    Version: 5.12.3
    Website: OVAL Community on GitHub
  • OCIL: Open Checklist Interactive Language
    Version: 2.0
    Website: OCIL
  • Asset Identification
    Version: 1.1
    Website: AI
  • ARF: Asset Reporting Format
    Version: 1.1
    Website: ARF

Identification schemes

Metrics

  • CVSS: Common Vulnerability Scoring System
  • CVSS v4.0 — preferred

Specification: CVSS v4.0 Specification
User Guide: CVSS v4.0 User Guide

  • CVSS v3.1 — supported

Specification: CVSS v3.1 Specification
User Guide: CVSS v3.1 User Guide

Website: http://www.first.org/cvss

  • CCSS: Common Configuration Scoring System

Version: 1.0

Specification: NIST IR 7502

Integrity

  • TMSAD: Trust Model for Security Automation Data
    Version: 1.0
    Website: TMSAD

Created December 07, 2016, Updated June 09, 2026