Open Security Controls Assessment Language (OSCAL)
-
Updated
May 28, 2026 - XSLT
Open Security Controls Assessment Language (OSCAL)
Open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.
An opinionated tooling platform for managing compliance as code, using continuous integration and NIST's OSCAL standard.
A simple open source command line tool to support common operations over OSCAL content.
A library of React components and an example user interface application that provides a direct UI into NIST's Open Security Controls Assessment Language (OSCAL) data in JSON format.
A mirror of ISM OSCAL documents. The authoritative source can be found at https://www.cyber.gov.au/ism/oscal.
Open source tool for processing OSCAL based FedRAMP SSPs
OSCAL tools for AI agents
Create a domain specific (GRC) agent with the Claude Agent SDK
A case study for ACSAC 2022 utilizing OSCAL with a custom GitHub action to automate assessments.
Add a description, image, and links to the oscal topic page so that developers can more easily learn about it.
To associate your repository with the oscal topic, visit your repo's landing page and select "manage topics."