Skip to main content

OSCAL Blog Posts

Explore the Latest Insights from Our OSCAL Community

Stay up-to-date with the newest blog posts from our OSCAL community members. Below you'll find recent blog posts presented as cards for easy browsing. Use the quick links below to jump to a specific post, or simply scroll down to explore all posts:



One of the most interesting parts of this week's OSCAL monthly workshop was hearing how Container Solutions turned OSCAL into something that solves everyday challenges for their customers. Instead of building a product first and searching for a problem later, their Continuous Compliance Framework (CCF) grew directly from conversations they had with their users who needed a better way to manage compliance throughout the development process.

A big takeaway was the idea of shifting compliance closer to developers. Rather than treating compliance as the final step before deployment, the CCF integrates it into the development process itself. That approach felt especially practical because it helps engineering teams find issues earlier while keeping compliance connected to the work they are already doing. Another highlight was seeing how OSCAL provided the foundation without limiting the innovation within the CCF. Container Solutions made sure to follow the standards where it made sense, but they also customized parts of the CCF to make it more approachable and usable for engineers. They adjusted the terminology to make it easier to understand, simplified the interface, and introduced their own custom logic so that users could focus on understanding and proving compliance instead of learning OSCAL concepts that they might be unfamiliar with. It was a good reminder that successful adoption is not just about following a specific standard. It is also about making sure that standard is useful for the people who use and rely on it every day.

The live demo tied the purpose of the CCF together. Watching evidence flow directly into control implementations, seeing risks generated from failed evidence, and exploring the automated workflows made it easier to connect OSCAL's structure to real-world compliance activities. The platform showed how compliance information can stay organized, traceable, and actionable instead of becoming another set of documents that quickly fall out of date.

This workshop offered a valuable look at what OSCAL adoption can look like. Seeing how Container Solutions adapted the project to fit real customer needs and concerns highlighted the flexibility of OSCAL and the impact of what thoughtful implementation can have. It was an engaging example of how OSCAL's open source nature can be leveraged and really gave a glimpse into how organizations are continuing to build on the OSCAL ecosystem.


OSCAL's June workshop featured ASSYST's Vijay Narasimhan, Joe Anderson, and John Kimberl, who shared how their team adopted OSCAL through ComplySyncATO to address challenges in the federal authorization process. A key takeaway from the discussion was that their OSCAL journey started with a real operational problem. Long ATO timelines were slowing down DevSecOps projects because teams were relying on static documents, spreadsheets, and manual reviews to demonstrate compliance. Their presentation showed how adopting OSCAL helped transform that information into machine readable data that could move more easily between systems and support a more streamlined process.

It was especially interesting to see how they described using OSCAL alongside AI to help evaluate implementation statements and identify compliance gaps. Rather than spending valuable time reviewing lengthy documentation, ISSOs can focus more on managing risk while the platform helps organize and analyze the supporting evidence. The speakers emphasized that the goal was not to replace the people involved in the RMF process, but to give them better tools to work more efficiently.

The live demonstration of ComplySyncATO really helped bring those ideas together. Uploading an OSCAL formatted System Security Plan and seeing the platform analyze controls, highlight implementation status, and generate recommendations made it easier to understand how structured compliance data can simplify what has traditionally been a document-heavy process.

The workshop offered a practical look at OSCAL adoption from an organization's perspective. It highlighted how standardized, machine readable security data can support automation, improve collaboration across tools, and help organizations move toward a more continuous approach to authorization.


In the recent May OSCAL Adopters' Workshop, Pirooz Javan, the CTO of Easy Dynamics, shared how his team is helping advance OSCAL adoption through the website OSCAL.io. Easy Dynamics developed OSCAL.io to serve as a hub for a variety of OSCAL-related tools and resources. The workshop focused on the OSCAL viewer, which is open source and designed to make OSCAL files easier to work with. The viewer can transform OSCAL JSON files into a format that is more understandable for users. It also allows users to publish, discover, and manage different versions of OSCAL documents. The registry includes features such as search filtering, role-based access control, user management, and options for favoriting, sharing, and controlling the visibility of documents.

To demonstrate these capabilities, Javan walked through an example using the Federal Space and Exploration Administration and its Orion Mission Platform. The example showed how the OSCAL Viewer and Registry could be used together to manage compliance information across a complex environment. The platform included several integrated systems, including an AWS FedRAMP environment, Gemini Enterprise ICAM, External Voyager Public Identity for user authentication, and Houston SOC integration for security monitoring. The OSCAL Viewer is open source, allowing anyone to contribute through pull requests. However, contributions are reviewed and governed carefully before being approved to maintain quality and consistency.

This workshop provided a helpful look at how OSCAL.io is making OSCAL artifacts more accessible and manageable. Seeing the practical demonstration helped the community better understand how these different tools can support compliance workflows and encourage collaboration among the OSCAL community.


The NIST OSCAL Team is excited to share an immersive online escape room experience designed to help community members learn OSCAL in a hands-on, engaging way. Rather than traditional presentations or documentation walkthroughs, this escape room invites participants to actively apply OSCAL concepts in realistic scenarios. By solving challenges and progressing through the experience, users will gain a deeper, more practical understanding of how OSCAL supports modern security assessment and authorization workflows.

The escape room was introduced on April 16, 2026, at the ISACA Future Tech DC 2026 event at George Mason University (Arlington, VA Campus). Hosted and presented by Dr. Michaela Iorga (NIST) and Selena Xiao (NIST), the OSCAL Escape Room workshop involved hands-on training that allowed participants to codify regulations, implemented controls, and assessment results using OSCAL. Through guided interactive exercises, attendees learned how OSCAL enables repeatable, automatable, and scalable security assessments, transforming compliance into a continuous, data-driven process.

In the virtual escape room, participants have just 30 minutes to unravel corrupted OSCAL data, solve complex challenges, and restore critical artifacts after a devastating cyberattack. As the damage escalates and the workload spirals out of control, every second counts.

→ Take a shot at the OSCAL Escape Room by visiting: https://pages.nist.gov/OSCALER/

→ Visit OSCAL's CSRC webpage to access the workshop presentation and additional resources related to the escape room.

This page was last updated on July 23, 2026.