Date Published: December 2, 2025
Comments Due: January 13, 2026 (public comment period is CLOSED)
Email Questions to:
oscal@ nist.gov
This paper introduces the Open Security Controls Assessment Language (OSCAL) — an open-source, machine-readable language that standardizes security documentation for better monitoring and risk management.
OSCAL was developed to modernize manual, paper-based cybersecurity compliance through automated, scalable processes and continuous assessments. This draft describes OSCAL’s layered architecture, its growing global adoption, and its future integration with emerging technologies (e.g., digital twins, agentic AI) for autonomous risk reasoning and continuous assurance.
We strongly encourage you to use this comment template to prepare your comments before submitting them to [email protected] by January 13, 2026. Thank you.
None selected
Publication:
https://doi.org/10.6028/NIST.CSWP.53.ipd
Download URL
Supplemental Material:
Comment template (xlsx)
Open Security Controls Assessment Language
Document History:
12/02/25: CSWP 53 (Draft)
assurance, audit & accountability, controls assessment, security automation