Open Security Controls Assessment Language (OSCAL). The Secure Controls Framework (SCF) supports OSCAL.
OSCAL is an acronym that stands for Open Security Controls Assessment Language. The US National Institute of Standards and Technology (NIST) developed OSCAL to be a standardized, data-centric and machine-readable structure to automate cybersecurity compliance efforts.
The Secure Controls Framework (SCF) supports OSCAL. When you download the SCF, the download folder contains both an Excel version and JSON versions. The JSON versions of the SCF are designed to support OSCAL.
OSCAL is organized into layered models: the catalog model (a set of controls, such as the SCF itself), the profile model (a selected and tailored baseline of controls), the component definition model (how a product or service implements controls), the system security plan (SSP) model, the assessment plan and assessment results models, and the plan of action and milestones (POA&M) model. Using the same machine-readable format across these stages is what allows GRC tools to exchange control, implementation and assessment data without manual re-keying.
NIST OSCAL Page - https://pages.nist.gov/OSCAL/