Secure Controls Framework
Download The SCF

How to Use the SCF in NIST OSCAL: From Catalog to Baseline

GRC,SCF,Secure Controls Framework
SCF Council
•
October 1, 2026

To use the SCF in OSCAL, download the SCF, take the JSON version, and load it into a tool that reads NIST OSCAL. From there you select and tailor the SCF controls you need into a baseline, then reference those controls in your system security plans and assessment records instead of retyping them in documents.

What is OSCAL?

OSCAL, the Open Security Controls Assessment Language, is a NIST standard for expressing security controls and compliance information as structured, machine-readable data in XML, JSON or YAML. Instead of passing Word documents and spreadsheets between teams and tools, OSCAL lets the same control data move between systems without being rekeyed. NIST maintains the models, schemas and tooling on its OSCAL project site.

    What does the SCF provide for OSCAL users?

    The SCF download contains both an Excel workbook and JSON versions, and the JSON versions are designed to support OSCAL. The SCF describes this as a way to import the full 1,500+ control catalog, with its mappings, into GRC platforms through CSV or NIST OSCAL formatted JSON. See the SCF download page and the short answer in the SCF FAQ, What is OSCAL and which frameworks support it?

    For an OSCAL user, that means you start from a catalog that is already cross-mapped. The mappings use NIST IR 8477 Set Theory Relationship Mapping, described on the STRM page, so each link from an SCF control to an external requirement carries a documented relationship type.

    SCF OSCAL Frequently Asked Questions (FAQ)

    Does the SCF support OSCAL?

    Yes. The SCF download includes JSON versions designed to support OSCAL, alongside the Excel workbook.

    Is OSCAL a cybersecurity framework?

    No. OSCAL is a data format and set of models for control information. Frameworks such as the SCF, NIST SP 800-53 and ISO 27001 can be represented in it, but OSCAL itself does not define security requirements.

    Do I need OSCAL to use the SCF?

    No. Most organizations start with the Excel version. OSCAL becomes useful when you want to move control data between tools, automate SSPs, or keep assessment results tied to controls without manual copying.

    Which OSCAL model should I start with?

    Start with the catalog and a profile. Once your baseline is stable, move to system security plans and then assessment results.