Skip to main content
—
Framework library
Framework module · oscal

OSCAL

NIST's machine-readable format for control catalogs, baselines, system security plans, and assessment results. An interchange layer, not a regime you comply with.

1.2.2 · NIST OSCAL · published 2026-04-30

Standing today
Directory entry

00Answer

from the registry record
What is OSCAL?
NIST's machine-readable format for control catalogs, baselines, system security plans, and assessment results. An interchange layer, not a regime you comply with.
Who does OSCAL apply to?
OSCAL applies to all sectors, global, per NIST OSCAL.
What is the current version of OSCAL?
The current edition is 1.2.2, issued by NIST OSCAL and published 2026-04-30. Source: https://pages.nist.gov/OSCAL/.
What does an assessment under OSCAL require?
No control catalog has been ingested for OSCAL yet — the registry tracks it as roadmap (Modeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

OSCAL is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Not a control regime — there is no verbatim control text to ingest.

02Registry record

checked 2026-08-06
Registry status
Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Catalog · Profile · Component definition · System security plan · Assessment plan · Assessment results · Control mapping
Applies to
all sectors · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-06

03Version ledger

4 editions
1.0.0Supersededdate not published
1.1.3Superseded · supersedes 1.0.0date not published
1.2.0Superseded · supersedes 1.1.32024-12-12
1.2.2Current edition · supersedes 1.2.02026-04-30

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to all sectors · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.

  2. UK Cyber EssentialsRequirements for IT infrastructure v3.3

    Also applies to all sectors · The UK government-backed certification scheme for five foundational technical controls. Cyber Essentials is questionnaire-based; Cyber Essentials Plus adds independent technical verification. Tracking the requirements does not claim either certificate.

  3. ASD Essential EightMaturity Model (November 2023)

    Also applies to all sectors · The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.

  4. GDPRRegulation (EU) 2016/679

    Also applies to all sectors · The EU's baseline for processing personal data — lawful basis, data-subject rights, controller and processor duties, and cross-border transfers.

OSCAL | ControlFrame