Glossary

What is OSCAL?

OSCAL stands for Open Security Controls Assessment Language.

OSCAL, or Open Security Controls Assessment Language, is a NIST-maintained set of machine-readable formats for security control catalogues, system security plans, assessment plans, and assessment results — designed so that control information can move between systems without being retyped.

In depth

Understanding OSCAL

Compliance documentation has historically been prose in documents. A control catalogue is a document, a system security plan is a document, and assessment results are a document, so tracking one control across all three is manual work repeated every cycle.

OSCAL models each of those as structured data with stable identifiers, so a control can be traced from catalogue to implementation to assessment result programmatically. Governance and risk platforms can ingest results directly instead of a person transcribing findings.

Its centre of gravity is US federal and public sector work, where NIST catalogues are the baseline, but nothing about the format is exclusive to that context.

In RedStrike

How RedStrike handles OSCAL

RedStrike exports assessment results as OSCAL, alongside SARIF, OpenVEX, PDF, HTML, Markdown, JSON, and CSV. This means findings enter a control-management process as structured data rather than as a report somebody re-keys.

FAQ

Frequently asked questions

Common questions about OSCAL.

Do I need OSCAL if I am not a government supplier?

Usually not. Its main advantage — moving control data between systems without transcription — matters most where control catalogues are large and assessments are frequent, which describes federal work more than a first SOC 2.

Is OSCAL the same as FedRAMP?

No. FedRAMP is an authorization programme for cloud services used by US federal agencies. OSCAL is a data format that FedRAMP and other programmes use to express control information. Supporting the format is not the same as holding the authorization.

See OSCAL in practice

Run continuous, verified security testing across your applications, APIs, and cloud accounts.