By Chor-Ching Fan
FedRAMP automation is on its way. The Open Security Controls Assessment Language (OSCAL) is a machine-readable information exchange format developed by the National Institute of Standards and Technology (NIST) to enable automation of risk management and compliance frameworks based on security controls and functional requirements. OSCAL support the expression of compliance information through XML, JSON and YAML formats. OSCAL was released in June 2021 and is currently in Version 1.1.0 (late July 2023)
The FedRAMP cybersecurity management program is the first key adopter of the OSCAL standard. OSCAL promises to enable FedRAMP automation (and other frameworks that adopt it) improving the efficiency and effectiveness of compliance management by providing a standardized, machine-readable format for capturing and sharing security information. Rizkly offers OSCAL automation features that simplify many of the manual tasks involved in compliance including:
- Generating security documentation such as SSPs, SAP and SAR in OSCAL format
- Importing FedRAMP 20X OSCAL packages so they are in human-readable format and easily read and/or assessed by a government agency
- Generating machine-readable authorization packages in custom electronic formats that by differ from OSCAL
- Reporting on compliance status either using OSCAL or other acceptable formats ahead of Rev 5 deadline set for September 30, 2027
OSCAL can be used to support a wide range of compliance frameworks, including:
- FedRAMP /FedRAMP 20X (early adoption in progress)
- NIST Cybersecurity Framework (CSF)
- ISO/IEC 27001
- SOC 2
- HIPAA
- PCI DSS
FedRAMP automation with OSCAL promises to be significant improvement over previous approaches to compliance automation. As proven by similar information exchange automation initiatives in other industries i.e. ecommerce supply chain documents or financial filing with the SEC, OSCAL should make compliance management be more efficient, more effective, and more scalable.
Here are some of the benefits of using the new OSCAL compliance framework:
- Efficiency: OSCAL automation will reduce manual tasks involved in compliance, such as generating security documentation, conducting assessments, and tracking remediation activities. This can save organizations a significant amount of time and money. FedRAMP SSPs can easily run 300+ pages in Microsoft Word. With continual updates and document submissions to the FedRAMP PMO, this task alone will benefit greatly from OSCAL.
- Effectiveness: OSCAL provides a standardized, machine-readable format for capturing and sharing security information. This makes it easier to identify, evaluate and determine next steps to remediate key risks for the US government and cloud service providers.
- Scalability & Extensibility: OSCAL is a scalable framework that can be used to support a wide range of compliance frameworks. OSCAL is extensible so any user or standards body can leverage the reference models while ensuring it supports the unique elements of their own privacy and security risk program.
Since its 1.0 release in 2021, Rizkly has supported the OSCAL standard with the goal of providing the best software for FedRAMP automation. We love OSCAL and think its great for the cybersecurity compliance world. Companies (CSPs) can import their existing Word SSPs and generate OSCAL with one-click in Rizkly. It will not be practical for most organizations to use XML editors and handcraft OSCAL files each time there are updates or submission requirements. While still in a pre-commercialization status for FedRAMP, we recommend that CSPs explore the transition to OSCAL along with their FedRAMP R4 to R5 gap analysis and planning efforts. If you’re wondering about a FedRAMP R4 vs R5 gap analysis, Rizkly, compliance automation software with dedicated FedRAMP OSCAL compliance experts, is ready to assist…just contact us.





