ISO 27001, NIS2, DORA, CRA, AI Act, BSI C5, PCI DSS — every framework is published in its own format, its own language, and its own numbering scheme. Teams work through lengthy PDFs by hand, spreadsheets map framework to framework cell by cell, and every new version restarts the work from scratch. The documents do not interoperate — every mapping is human glue. At the same time, regulators themselves have long been demanding structured data: since 2025, the DORA register of information on ICT third-party providers must be submitted annually in xBRL-CSV format. Compliance as a stack of documents no longer scales — neither for companies nor for auditors.
OSCAL: Frameworks as Code
The NIST standard that turns regulations, standards, and frameworks from PDF into data: catalogs, profiles, mappings, and evidence — machine-readable, versionable, automatable.
8OSCAL models across three layers — from Catalog to POA&M
500+FedRAMP Rev5 providers that must deliver machine-readable or semi-structured packages by November 1, 2027
~1,000requirements in the OSCAL-first catalog of Grundschutz++ (pilot build mid-2026)
168criteria in C5:2026 — machine-readable for the first time
Compliance frameworks arrive as documents — read, mapped, and maintained by hand. NIST's Open Security Controls Assessment Language (OSCAL) inverts that: a framework becomes structured data in which every control, every requirement, and every identifier is an addressable object. In 2026 this has become regulatory reality: FedRAMP requires more than 500 cloud providers to deliver machine-readable or semi-structured authorization packages, the BSI publishes its Stand der Technik (state-of-the-art) library natively in OSCAL, and the IT-Grundschutz successor Grundschutz++ appears OSCAL-first. This page explains the standard from the ground up — and shows how it turns into combined compliance across NIS2, the AI Act, ISO 27001, ISO 42001, and the CRA.
From NIST release to regulatory reality
How OSCAL went from standard to mandatory format in five years — tap a milestone for details.
June 2021
OSCAL 1.0.0
First stable release after three milestone releases and two release candidates: Catalog, Profile, Implementation, and Assessment models.
Sep 2025
BSI Stand der Technik library
The BSI publishes its rulebooks natively in OSCAL on GitHub for the first time — under the free CC BY-SA 4.0 license.
Dec 2025
OSCAL 1.2.0: the mapping model
Control Mapping becomes the eighth OSCAL model — relationships between frameworks become part of the standard, typed and justified.
Mar 2026
FedRAMP mandates machine-readable packages
The RFC-0024 decision sets deadlines: more than 500 Rev5 providers must deliver machine-readable or semi-structured packages by November 1, 2027.
The Essentials at a Glance
Nine topic blocks — tap to expand.
Three layers, eight models
From the framework's text to the assessment result — tap a layer.
- Catalog: the framework as data — groups, controls, verbatim requirement texts, and parameters.
- Profile: the selection and tailoring — a baseline across one or more catalogs.
- Control Mapping (since v1.2.0): relationships between frameworks — typed, justified, machine-readable.
CatalogProfileControl MappingStable IDsParams
- Component Definition: how a product or service supports controls — the reusable compliance building block, including from suppliers.
- System Security Plan: how a specific system implements the selected baseline.
Component DefinitionSSPSupply chain
- Assessment Plan and Assessment Results: what is tested and what was found — observations with evidence references and hash protection.
- POA&M: known gaps with owners and deadlines — the machine-readable remediation plan.
Assessment PlanAssessment ResultsPOA&MEvidenceContinuous ATO
Our platform · OSCAL in production
VamiGRC: from framework PDF to combined control set
In VamiGRC, OSCAL is the backbone of the platform: all regulations, standards, and frameworks are managed as structured OSCAL catalogs — imported via a Bring-Your-Own-Framework pipeline that learns each document's identifier scheme on its own, captures requirement texts verbatim, and publishes them as schema-valid catalogs (v1.1.2) only after review approval. Building on this, cross-framework catalogs combine multiple regulations — for example NIS2 + AI Act + ISO 27001 + ISO 42001 + CRA — into one consolidated control set: gap analysis, audit preparation, and implementation run as one project instead of five, and evidence is assigned to controls in a structured way — verifiable all the way into the supply chain.
25+standards and regulations as OSCAL catalogs
5 → 1one combined gap analysis instead of five separate projects
v1.1.2schema-valid catalogs, validated against NIST tooling
BYOFany framework document can be imported
- Cross-framework catalogs: NIS2, AI Act, ISO 27001, ISO 42001, and CRA in one consolidated control set
- Evidence structured along the controls — audit-ready, reusable, including for supplier attestations
- Verbatim extraction with a review gate: only what has been verified gets published
Shown live in the VamiSec webinar “Frameworks as Code” (August 25, 2026): from raw PDF to published OSCAL catalog.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
OSCAL — Open Security Controls Assessment Language
Official project site: concepts, models, tutorials, and reference documentation.
OSCAL Releases (v1.0.0 to v1.2.3)
Version history: v1.0.0 (June 7, 2021), v1.2.0 (December 12, 2025) with the new Control Mapping model, currently v1.2.3 (August 7, 2026).
OSCAL Layers and Models Reference
The three layers (Control, Implementation, Assessment) and the eight models at a glance.
NIST IR 8477 — Mapping Relationships Between Documentary Standards, Regulations, Frameworks, and Guidelines
Set-theoretic relationship types and mandatory rationales — the methodological basis of the OSCAL mapping model.
National Online Informative References (OLIR) Program
Official framework references, including CSF 2.0 ↔ SP 800-53, ISO/IEC 27001:2022, CIS Controls, PCI DSS.
Press release: Stand-der-Technik-Bibliothek
Since September 30, 2025, the BSI has been publishing its rulebooks in machine-readable form on an OSCAL basis.
Stand-der-Technik-Bibliothek (repository)
CC BY-SA 4.0 repository, organized along OSCAL layers — includes, among others, the Grundschutz++ catalogs.
FedRAMP Notice NTC-0009 — Machine-Readable Authorization Packages
Binding deadlines for machine-readable authorization packages; final deadline November 1, 2027 for more than 500 Rev5 providers.
FedRAMP 20x
Automation program with Key Security Indicators and completed pilot phases for machine-readable packages.
OSCAL Compass
CNCF Sandbox project: compliance-trestle (OSCAL as code), Agile Authoring, and Compliance-to-Policy.
EMERALD — Certification-as-a-Service (Horizon Europe, GA 101120688)
EU project for continuous cloud certification on an OSCAL basis, evolved from MEDINA/EUROSCAL.
Adopt Frameworks as Code — with a clear roadmap
VamiSec supports you from catalog strategy through cross-framework consolidation to evidence automation — as advisors and with VamiGRC as the platform on which your regulations are already structured as OSCAL catalogs.