Skip to content

Introduction

The macOS Security Compliance Project (mSCP) is an open source effort to provide a programmatic approach to generating security guidance for Apple platforms (macOS, iOS/iPadOS, and visionOS).

The project maintains a library of security rules, each mapped to one or more compliance frameworks (NIST 800-53, CIS Benchmarks, DISA STIG, and others). You select a framework, run a script, and generate tailored outputs: baseline YAML files, human-readable guidance documents, MDM configuration profiles, and shell scripts for checking and remediating settings.

mSCP was created by a collaboration of federal agencies including NIST, NASA, DISA, and Los Alamos National Lab. It is recognized by Apple and updated with each major macOS release to ensure guidance stays current.


Run the scripts and generate:

  • Security baselines - YAML files defining which rules apply to your environment
  • Guidance documents - HTML and PDF documentation for auditors and teams
  • Configuration profiles - Ready-to-deploy .mobileconfig files for MDM
  • Compliance scripts - Shell scripts to check and fix settings on any Mac
  • SCAP/OVAL content - For compliance scanning tools

Role How You’ll Use It
System Administrators Generate profiles and scripts to harden Macs
Security Professionals Audit systems against compliance frameworks
Policy Authors Create or customize baselines for your org
MDM/Compliance Vendors Integrate trusted security guidance into products
Privacy Officers Verify privacy controls are in place

Government

Industry

International

  • indigoGermany, iOS only
  • BIONetherlands
  • NLMAPGOV Apple Baselines Base, Plus

  • Ready when you are - Guidance available for new macOS releases
  • Single source of truth - One project, many frameworks
  • Community-driven - Collaborate instead of duplicating effort
  • Recognized by Apple - Built with input from Apple’s security team

A collaboration between federal IT security staff and macOS administrators: