OSCAL Blog Posts
Explore the Latest Insights from Our OSCAL Community
Stay up-to-date with the newest blog posts from our OSCAL community members. Below you'll find a list of recent blog titles, simply click on any title to dive straight into the post you're interested in:
- Making ATO Smarter: ASSYST's Approach to OSCAL and AI -- 06/24/2026 -- Read More
- How OSCAL.io is Transforming the OSCAL Experience -- 05/29/2026 -- Read More
- Learn OSCAL Through an Immersive Online Escape Room Experience -- 04/24/2026 -- Read More
- OSCAL Adoption for FedRAMP: Insights Learned and Path Going Forward -- 04/23/2026 -- Read More
- A Student’s Take on OSCAL Innovation: Exploring the OSCAL Pocket Guide -- 04/02/2026 -- Read More
2026/07/01
Making ATO Smarter: ASSYST's Approach to OSCAL and AI
-- Presented By:
- Vijay Narasimhan, Chief Technology Officer, ASSYST
- Joe Anderson, Chief Operating Officer, ASSYST
- John Kimberl, Business Development Specialist, ASSYST
-- Blog by: Marilyn Nguyen (IT Cybersecurity Specialist, NIST) [email protected]
OSCAL's June workshop featured ASSYST's Vijay Narasimhan, Joe Anderson, and John Kimberl, who shared how their team adopted OSCAL through ComplySyncATO to address challenges in the federal authorization process. A key takeaway from the discussion was that their OSCAL journey started with a real operational problem. Long ATO timelines were slowing down DevSecOps projects because teams were relying on static documents, spreadsheets, and manual reviews to demonstrate compliance. Their presentation showed how adopting OSCAL helped transform that information into machine readable data that could move more easily between systems and support a more streamlined process.
It was especially interesting to see how they described using OSCAL alongside AI to help evaluate implementation statements and identify compliance gaps. Rather than spending valuable time reviewing lengthy documentation, ISSOs can focus more on managing risk while the platform helps organize and analyze the supporting evidence. The speakers emphasized that the goal was not to replace the people involved in the RMF process, but to give them better tools to work more efficiently.
The live demonstration of ComplySyncATO really helped bring those ideas together. Uploading an OSCAL formatted System Security Plan and seeing the platform analyze controls, highlight implementation status, and generate recommendations made it easier to understand how structured compliance data can simplify what has traditionally been a document-heavy process.
The workshop offered a practical look at OSCAL adoption from an organization's perspective. It highlighted how standardized, machine readable security data can support automation, improve collaboration across tools, and help organizations move toward a more continuous approach to authorization.
Workshop Location:
- Online
Workshop Date and Time:
- 24 June 2026, 11:00 AM - 12:00 PM EDT
View this June 2026 workshop recording and other files here.
Learn more about the OSCAL Monthly Workshop series here.
2026/05/29
How OSCAL.io is Transforming the OSCAL Experience
-- Presented By:
- Pirooz Javan, Cheif Technology Officer, Easy Dynamics
-- Blog by: Marilyn Nguyen (NIST Pathways, IT Student Trainee) [email protected]
In the recent May OSCAL Adopters' Workshop, Pirooz Javan, the CTO of Easy Dynamics, shared how his team is helping advance OSCAL adoption through the website OSCAL.io. Easy Dynamics developed OSCAL.io to serve as a hub for a variety of OSCAL-related tools and resources. The workshop focused on the OSCAL viewer, which is open source and designed to make OSCAL files easier to work with. The viewer can transform OSCAL JSON files into a format that is more understandable for users. It also allows users to publish, discover, and manage different versions of OSCAL documents. The registry includes features such as search filtering, role-based access control, user management, and options for favoriting, sharing, and controlling the visibility of documents.
To demonstrate these capabilities, Javan walked through an example using the Federal Space and Exploration Administration and its Orion Mission Platform. The example showed how the OSCAL Viewer and Registry could be used together to manage compliance information across a complex environment. The platform included several integrated systems, including an AWS FedRAMP environment, Gemini Enterprise ICAM, External Voyager Public Identity for user authentication, and Houston SOC integration for security monitoring. The OSCAL Viewer is open source, allowing anyone to contribute through pull requests. However, contributions are reviewed and governed carefully before being approved to maintain quality and consistency.
This workshop provided a helpful look at how OSCAL.io is making OSCAL artifacts more accessible and manageable. Seeing the practical demonstration helped the community better understand how these different tools can support compliance workflows and encourage collaboration among the OSCAL community.
Workshop Location:
- Online
Workshop Date and Time:
- 20 May 2026, 11:00 AM - 12:00 PM EDT
View this May 2026 workshop recording and other files here.
Learn more about the OSCAL Monthly Workshop series here.
2026/04/24
Learn OSCAL Through an Immersive Online Escape Room Experience
-- Blog by: Marilyn Nguyen (NIST Pathways, IT Student Trainee) [email protected]
The NIST OSCAL Team is excited to share an immersive online escape room experience designed to help community members learn OSCAL in a hands-on, engaging way. Rather than traditional presentations or documentation walkthroughs, this escape room invites participants to actively apply OSCAL concepts in realistic scenarios. By solving challenges and progressing through the experience, users will gain a deeper, more practical understanding of how OSCAL supports modern security assessment and authorization workflows.
The escape room was introduced on April 16, 2026, at the ISACA Future Tech DC 2026 event at George Mason University (Arlington, VA Campus). Hosted and presented by Dr. Michaela Iorga (NIST) and Selena Xiao (NIST), the OSCAL Escape Room workshop involved hands-on training that allowed participants to codify regulations, implemented controls, and assessment results using OSCAL. Through guided interactive exercises, attendees learned how OSCAL enables repeatable, automatable, and scalable security assessments, transforming compliance into a continuous, data-driven process.
In the virtual escape room, participants have just 30 minutes to unravel corrupted OSCAL data, solve complex challenges, and restore critical artifacts after a devastating cyberattack. As the damage escalates and the workload spirals out of control, every second counts.
→ Take a shot at the OSCAL Escape Room by visiting: https://pages.nist.gov/OSCALER/
→ Visit OSCAL's CSRC webpage to access the workshop presentation and additional resources related to the escape room.
2026/04/23
OSCAL Adoption for FedRAMP: Insights Learned and Path Going Forward
-- Presented By:
- Brian Ruf, FedRAMP Technology Focus Group Lead, OSCAL Foundation
- Stephen Banghart, Technical Coordinator, OSCAL Foundation
-- Blog by: Marilyn Nguyen (NIST Pathways, IT Student Trainee) [email protected]
In OSCAL's recent monthly workshop, Brian Ruf and Stephan Banghart from the OSCAL Foundation highlighted their efforts to make FedRAMP security artifacts machine-readable and OSCAL-compliant. A key theme throughout the session was improving interoperability and ensuring that security documentation can be consistently understood and used across different agencies and organizations.
One of the most interesting takeaways was the feedback gathered from various U.S. government agencies. While OSCAL offers a high degree of flexibility in how information can be structured and mapped, that same flexibility can make adoption a bit challenging. Agencies noted that transitioning from traditional formats like Word documents and spreadsheets to fully machine-readable OSCAL artifacts can feel like a big jump, especially with tooling being limited.
To address this challenge, the OSCAL Foundation is taking a phased approach. Their current focus is on the FedRAMP System Security Plan and their goal is to provide clearer guidance on how SSPs should be represented in OSCAL so that implementations are more consistent and interoperable.
Another aspect that stood out was the emphasis on incremental adoption. Instead of requiring organizations to fully convert their documentation all at once, the OSCAL Foundation introduced two adoption paths: a retrofit path for converting existing legacy documents and a native path for organizations that are starting fresh. This approach allows users to begin with simpler, flat representations of their data and gradually transition to more structured component-based models over time.
The presenters also shared several resources for the community to get support in adoption, including a GitHub repository containing examples of OSCAL representations. These tools aim to make it easier for organizations to get started and build familiarity with the standard.
Overall, this insightful workshop highlighted both the challenges and ongoing efforts to make OSCAL adoption more accessible by focusing on guidance and incremental progress.
Workshop Location:
- Online
Workshop Date and Time:
- 15 April 2026, 11:00 AM - 12:00 PM EDT
View this April 2026 workshop recording and other files here.
Learn more about the OSCAL Monthly Workshop series here.
2026/04/02
A Student’s Take on OSCAL Innovation: Exploring the OSCAL Pocket Guide
-- Presented By:
- Tevin Harris, Federal Employee, Founder of euCann
-- Blog by: Marilyn Nguyen (NIST Pathways, IT Student Trainee) [email protected]
During OSCAL's March 2026 workshop, Tevin Harris from euCann LLC delivered an insightful and engaging presentation, including a live demo of the OSCAL Pocket Guide, a mobile OSCAL-based application that provides on-demand access to the OSCAL Catalog. Harris opened by highlighting a familiar challenge faced by many cybersecurity professionals: the long, tedious process of manually assessing paper-based security artifacts such as PDFs and spreadsheets. With multiple versions and formats of security frameworks, some often spanning hundreds of pages, manual assessment becomes highly inefficient.
OSCAL addresses this issue by standardizing these artifacts into automatable, machine-readable formats, enabling continuous compliance and streamlined assessments. To further support OSCAL adoption and provide a more intuitive user experience, Harris developed the OSCAL Pocket Guide. The application allows users to easily browse OSCAL catalogs, analyze controls, navigate various framework models, review assessment objectives and artifacts, and explore parameters and implementation guidance.
Currently available on iOS, Android, and macOS devices, the application leverages data frameworks and formats based on OSCAL JSON documents. It does not require an internet connection, as it operates entirely offline with documents downloaded directly to the user's device. The app is powered by six core frameworks: SP 800-53 Revision 5, NIST CSF 2.0, SP 800-171 Revision 3, SP 800-218 (SSDF), the AI RMF Playbook, and Harris's own customized OSCAL SP 800-61 Volume II.
The OSCAL Pocket Guide features an intuitive interface that allows users to explore different frameworks and the modules that make them up. Built using a Flutter UI layer and core OSCAL services, the application supports document parsing, exporting, and secure local storage via encrypted SQLite. It is offered in two versions: a free version, and a Pro version priced at $10, which includes advanced multi-criteria filtering and control comparison capabilities.
During the demonstration, I was particularly impressed by the application's ease of use and thoughtful design. Clear navigation and well-organized tabs guide users through OSCAL-based frameworks and their respective control modules. Features such as favoriting frequently accessed controls, applying baseline filters, sorting by control IDs, and displaying parameters inline further enhance the app's usability.
The application continues to evolve, with future updates expected to include a web interface and cloud-based capabilities, such as a retrieval-augmented generation (RAG) chatbot. This feature will enable users to ask questions about NIST catalog items and receive real-time, OSCAL-informed responses related to controls and frameworks.
Overall, the OSCAL Pocket Guide is a promising tool that simplifies interaction with complex OSCAL data, making it more accessible through a clean, user-friendly interface while supporting deeper exploration of its technical capabilities.
Workshop Location:
- Online
Workshop Date and Time:
- 18 March 2026, 11:00 AM - 12:00 PM EDT
View this March 2026 workshop recording and other files here.
Learn more about the OSCAL Monthly Workshop series here.