The OSCAL Foundation is a nonprofit organization bringing together leading industry and government stakeholders to advance the development and adoption of the OSCAL standard. The Foundation focuses on six core objectives—Adoption, Education, Community, Development, Extension, and Internationalization—all aimed at strengthening security practices worldwide.
Since its launch in early 2025, the Foundation has expanded steadily by driving consensus on recommended technical changes to the standard, engaging global partners to accelerate adoption, and cultivating a community committed to OSCAL’s future. The accomplishments highlighted below represent just the beginning with exciting plans for an even more impactful 2026.
OSCAL Foundation Plugfest
The Foundation closed out 2025 the first OSCAL Foundation Plugfest — an event that brought together OSCAL practitioners, industry leaders, government officials, and the broader community to collaborate on advancing the OSCAL standard. The Plugfest opened with an in-person hackathon where more than 30 attendees from across public and private sectors worked collectively to strengthen the technical foundations of OSCAL. Engineers and representatives showcased emerging projects, including OSCAL validators, tooling enhancements, and improvements to the newly announced mapping model.
After a productive morning of hands-on development, the event transitioned into an afternoon program of panels and presentations highlighting OSCAL’s accelerating adoption across sectors. The first panel featured Jesus Luna Garcia, Cybersecurity Standardization Lead – Europe at AWS; Dr. Antonio Skarmeta, Professor at the University of Murcia in Spain; Tom Nash, Director at PwC; and Cristian Tracci, Strategy Officer at the European Cyber Security Organisation (ECSO). These global stakeholders discussed OSCAL’s expanding international use cases. In the EU, for example, strategists are positioning OSCAL as a leading standard for security compliance and interoperability.
The second panel explored OSCAL’s growing impact in the financial services sector. The panel featured John Goodman, Senior Vice President at Cyber Risk Institute (CRI); Theo Bruckbauer, Executive Director, Technology Risk & Compliance at CME Group; Pirooz Javan, CTO at Easy Dynamics Corporation; and Tara Houlden, Director, Product Security Compliance & Risk at Red Hat.
The speakers emphasized how OSCAL enables organizations to move beyond traditional compliance toward continuous monitoring, modernized security architectures, and reduced reliance on legacy systems. They shared tangible examples of how OSCAL is already saving time, energy, and resources while strengthening risk management across the industry.
The final panel examined the rapidly evolving intersection of AI and OSCAL. The panel featured Travis Howerton, Co-Founder and CEO at RegScale; Fritz Kunstler, Principal Security Engineer at AWS; Brian Hennigan, Founder and CEO at 3WM LLC; and Ross Nodurft, Executive Director of the Alliance for Digital Innovation (ADI).
The panel discussed how AI models rely on structured, machine-readable data, and how OSCAL can provide the standardization needed to support interoperability and automation. They highlighted opportunities for OSCAL to enable AI-driven control assessments, improved evidence handling, consistent compliance terminology, and more effective training data for large language models. The discussion made clear that this is only the start of deeper collaboration between the AI and OSCAL communities.
The program also included presentations from two OSCAL Foundation members, RegScale and Easy Dynamics, showcasing the innovative work underway across the OSCAL ecosystem. Both emphasized the importance of bringing new tools, projects, and questions to the Foundation to foster even greater collaboration.
The Plugfest concluded with a keynote address from Jon Boyens, Acting Division Chief of the National Institute of Standards and Technology’s (NIST) Computer Security Division. Boyens praised the strong, collaborative relationship between NIST and the OSCAL Foundation, celebrating the progress made in just the first year and expressing enthusiasm for the continued momentum heading into 2026 and beyond.
MoU between the OSCAL Foundation and NIST
To further strengthen ongoing collaboration, the OSCAL Foundation is proud to announce the recent signing of a Memorandum of Understanding (MoU) with NIST. This agreement formalizes the already strong relationship between NIST, the OSCAL community, and Foundation members.
A key benefit of this partnership is NIST’s improved ability to receive consensus-driven input from the broader OSCAL ecosystem. When members of the Foundation’s Technical Working Group align on recommended enhancements to the standard, the Foundation can deliver these proposals to NIST in a unified, community-validated proposal, significantly reducing the workload required of NIST and accelerating progress.
By formalizing this collaborative model, the MoU reinforces the trust-based relationship between the two organizations and sets the stage for continued co-development of the OSCAL standard in the years ahead.
NIST Accepted Foundation Recommendations into OSCAL
The impact of the OSCAL Foundation’s collaborative model was demonstrated through NIST’s recent release of version 1.2.0 of OSCAL. This version includes a new cross-framework mapping capability spearheaded by Foundation members and developed collaboratively at Foundation meetings over the last several months. Introducing the ability to create and share machine-readable mappings between frameworks, the additions in this release will open up new use cases for OSCAL and further advance the state-of-the-art in compliance automation. Through coordinated technical work, the community refined these enhancements and built consensus before formally submitting them to NIST.
NIST’s adoption of these updates underscores the value of a community-validated approach. Practitioners surface real-world needs, Foundation members collaborate on solutions, and NIST integrates the most effective and broadly supported improvements into the official standard. This cycle of contribution and refinement not only accelerates OSCAL’s evolution but also ensures that the standard continues to reflect the needs of the organizations relying on it every day.
OSCAL Hub
At the recent Plugfest, RegScale, one of the Foundation’s founding members, announced that it will donate its new OSCAL Hub to the OSCAL Foundation. The OSCAL Hub is an open-source platform designed to “help accelerate the approval of security authorizations for government regulators, federal agencies, cloud service providers, and other organizations using the OSCAL standardized framework for information systems.”
The Foundation will assume stewardship of the Hub and work to expand its adoption, strengthen its capabilities, and support its use across the broader OSCAL community.
Looking Towards 2026
After an exceptionally productive first year, the OSCAL Foundation is poised to carry its momentum into 2026. The Technical Working Group will continue advancing the standard, tackling both longstanding challenges and emerging needs, while collaborating closely with NIST to drive meaningful improvements.
At the same time, the Engagement Working Group will expand its outreach efforts with federal and international partners to further increase awareness and adoption of OSCAL. As the community grows, so too will the collective impact of OSCAL, strengthening security and compliance practices across industries worldwide.