OSCAL is NIST’s machine-readable format for compliance documentation — control catalogs, control baselines, system security plans, assessment plans and assessment results, expressed in XML, JSON and YAML rather than in prose. It is the most developed attempt anywhere to make compliance evidence exchangeable between systems instead of re-keyed.
OSCAL
OSCAL takes the artifacts of compliance — the control catalog, the system security plan, the assessment result — and gives them a schema. That is a small idea with large consequences: a control implemented once can be described once, and the description can travel to every framework, auditor and customer that asks about it.
- Control catalogs and baselines - A framework’s controls as data, so a mapping between frameworks is a computation rather than a spreadsheet.
- System security plans - The document at the centre of every authorisation, in a form a machine can validate.
- Assessment plans and results - Evidence and findings as structured output rather than a PDF appendix.
- Three serialisations - XML, JSON and YAML from one model, which is a deliberate accommodation of the audiences involved.
- From the security world - Built by NIST for federal authorisation, and applicable well beyond it.
OSCAL matters to the legal and compliance market more than that market currently reflects. The State of Legal & Compliance APIs scores a GRC, audit and policy segment averaging 24.1 with 28.6% publishing a machine-readable contract, in a market whose governance facet is 9.1 with two-thirds at zero. OSCAL is the artifact that would let compliance evidence flow between those systems instead of being re-entered — and it arrived from the security world rather than the legal one, which is part of why adoption is early.
Referenced in API Evangelist papers
This standard shows up in my published research. These reports read the machine-readable evidence provider by provider — and put this standard in the context of a real sector.
The State of Legal & Compliance APIs
The closest thing to machine-readable compliance anyone has built — arriving from the security world into a GRC segment averaging 24.1 with 28.6% publishing a contract.