Book an Appointment

OSCAL: Frameworks as Code

The NIST standard that turns regulations, standards, and frameworks from PDF into data: catalogs, profiles, mappings, and evidence — machine-readable, versionable, automatable.

8OSCAL models across three layers — from Catalog to POA&M
500+FedRAMP Rev5 providers that must deliver machine-readable or semi-structured packages by November 1, 2027
~1,000requirements in the OSCAL-first catalog of Grundschutz++ (pilot build mid-2026)
168criteria in C5:2026 — machine-readable for the first time

Compliance frameworks arrive as documents — read, mapped, and maintained by hand. NIST's Open Security Controls Assessment Language (OSCAL) inverts that: a framework becomes structured data in which every control, every requirement, and every identifier is an addressable object. In 2026 this has become regulatory reality: FedRAMP requires more than 500 cloud providers to deliver machine-readable or semi-structured authorization packages, the BSI publishes its Stand der Technik (state-of-the-art) library natively in OSCAL, and the IT-Grundschutz successor Grundschutz++ appears OSCAL-first. This page explains the standard from the ground up — and shows how it turns into combined compliance across NIS2, the AI Act, ISO 27001, ISO 42001, and the CRA.

From NIST release to regulatory reality

How OSCAL went from standard to mandatory format in five years — tap a milestone for details.

The Essentials at a Glance

Nine topic blocks — tap to expand.

Three layers, eight models

From the framework's text to the assessment result — tap a layer.

What the framework says
  • Catalog: the framework as data — groups, controls, verbatim requirement texts, and parameters.
  • Profile: the selection and tailoring — a baseline across one or more catalogs.
  • Control Mapping (since v1.2.0): relationships between frameworks — typed, justified, machine-readable.
CatalogProfileControl MappingStable IDsParams
Our platform · OSCAL in production

VamiGRC: from framework PDF to combined control set

In VamiGRC, OSCAL is the backbone of the platform: all regulations, standards, and frameworks are managed as structured OSCAL catalogs — imported via a Bring-Your-Own-Framework pipeline that learns each document's identifier scheme on its own, captures requirement texts verbatim, and publishes them as schema-valid catalogs (v1.1.2) only after review approval. Building on this, cross-framework catalogs combine multiple regulations — for example NIS2 + AI Act + ISO 27001 + ISO 42001 + CRA — into one consolidated control set: gap analysis, audit preparation, and implementation run as one project instead of five, and evidence is assigned to controls in a structured way — verifiable all the way into the supply chain.

25+standards and regulations as OSCAL catalogs
5 → 1one combined gap analysis instead of five separate projects
v1.1.2schema-valid catalogs, validated against NIST tooling
BYOFany framework document can be imported
  • Cross-framework catalogs: NIS2, AI Act, ISO 27001, ISO 42001, and CRA in one consolidated control set
  • Evidence structured along the controls — audit-ready, reusable, including for supplier attestations
  • Verbatim extraction with a review gate: only what has been verified gets published

Shown live in the VamiSec webinar “Frameworks as Code” (August 25, 2026): from raw PDF to published OSCAL catalog.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

NIST · ongoing

OSCAL — Open Security Controls Assessment Language

Official project site: concepts, models, tutorials, and reference documentation.

NIST / GitHub · 2021–2026

OSCAL Releases (v1.0.0 to v1.2.3)

Version history: v1.0.0 (June 7, 2021), v1.2.0 (December 12, 2025) with the new Control Mapping model, currently v1.2.3 (August 7, 2026).

NIST · ongoing

OSCAL Layers and Models Reference

The three layers (Control, Implementation, Assessment) and the eight models at a glance.

NIST · 2024

NIST IR 8477 — Mapping Relationships Between Documentary Standards, Regulations, Frameworks, and Guidelines

Set-theoretic relationship types and mandatory rationales — the methodological basis of the OSCAL mapping model.

NIST · ongoing

National Online Informative References (OLIR) Program

Official framework references, including CSF 2.0 ↔ SP 800-53, ISO/IEC 27001:2022, CIS Controls, PCI DSS.

BSI · 2025

Press release: Stand-der-Technik-Bibliothek

Since September 30, 2025, the BSI has been publishing its rulebooks in machine-readable form on an OSCAL basis.

BSI / GitHub · 2025–2026

Stand-der-Technik-Bibliothek (repository)

CC BY-SA 4.0 repository, organized along OSCAL layers — includes, among others, the Grundschutz++ catalogs.

FedRAMP / GSA · 2026

FedRAMP Notice NTC-0009 — Machine-Readable Authorization Packages

Binding deadlines for machine-readable authorization packages; final deadline November 1, 2027 for more than 500 Rev5 providers.

FedRAMP / GSA · 2026

FedRAMP 20x

Automation program with Key Security Indicators and completed pilot phases for machine-readable packages.

CNCF · ongoing

OSCAL Compass

CNCF Sandbox project: compliance-trestle (OSCAL as code), Agile Authoring, and Compliance-to-Policy.

European Commission / CORDIS · 2023–2026

EMERALD — Certification-as-a-Service (Horizon Europe, GA 101120688)

EU project for continuous cloud certification on an OSCAL basis, evolved from MEDINA/EUROSCAL.

Adopt Frameworks as Code — with a clear roadmap

VamiSec supports you from catalog strategy through cross-framework consolidation to evidence automation — as advisors and with VamiGRC as the platform on which your regulations are already structured as OSCAL catalogs.