Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST CSWP 53 (Initial Public Draft)

Charting the Course for NIST OSCAL

Date Published: December 2, 2025
Comments Due: January 13, 2026 (public comment period is CLOSED)
Email Questions to: oscal@ nist.gov

Author(s)

Michaela Iorga (NIST), Marilyn Nguyen (NIST)

Announcement

This paper introduces the Open Security Controls Assessment Language (OSCAL) — an open-source, machine-readable language that standardizes security documentation for better monitoring and risk management.

OSCAL was developed to modernize manual, paper-based cybersecurity compliance through automated, scalable processes and continuous assessments. This draft describes OSCAL’s layered architecture, its growing global adoption, and its future integration with emerging technologies (e.g., digital twins, agentic AI) for autonomous risk reasoning and continuous assurance.

We strongly encourage you to use this comment template to prepare your comments before submitting them to [email protected] by January 13, 2026. Thank you.

Abstract

Keywords

Agentic AI; compliance; continuous assessment; digital twins; interoperability; machine-readable formats; Open Security Controls Assessment Language; OSCAL; risk management; security automation
Control Families

None selected