Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Export in OSCAL format

CAM supports the Open Security Controls Assessment Language (OSCAL) used by the National Institute of Standards and Technology (NIST) that provides control-related information in standardized machine-readable formats. CAM supports Catalog, Profile, SSP, Assessment Plan (AP), Assessment Results (AR), and Control Tailoring Request data.

Source tables to fetch data for the models

Source tableJSON property
Catalog
Control objectivecontrols
Control Objective to Control objective requirementstatements parts
Test template to Assessment procedureassessment objective parts
Control Objectiveguidance
Test TemplateAssessment-method (Examine)
Test TemplateAssessment-method (Interview)
Profile
Baseline ControlInclude-controls
Baseline ControlExclude-controls
SSP
Authorization boundarycomponents
Authorization packageleveraged-authorization
Authorization boundarysecurity-impact-level
Control requirementstatements
Authorization boundaryby-components
Information typeInformation-types
Assessment Plan
Engagementassessment-plan
Engagement metadatametadata (title, state, objectives, progress, dates, budget)
Usersmetadata.parties
Rolesmetadata.roles, responsible-parties
Control testslocal-definitions.activities
Test planlocal-definitions.activities.related-controls.control-objective-selections
Test templatelocal-definitions.activities.props
Assessment procedureslocal-definitions.activities.steps
Controls in scopereviewed-controls
Package referenceimport-ssp.href
Assessment Results
Engagementresults (actual dates, actual cost, state, percent complete)
Engagement metadatametadata (responsible parties, roles, parties, props)
Control testslocal-definitions.activities, results.attestations
Assessment procedureslocal-definitions.activities.steps, results.attestations.parts.parts
Reviewed controlsresults.reviewed-controls
AP referenceimport-ap.href
Control Tailoring Requests
Roles ctr-opened-by, ctr-assigned-tometadata.roles[].id, metadata.roles[].title
Users (Control Tailoring Request Opened by, Control Tailoring Request Assigned to)metadata.responsible-parties[].role-id, metadata.responsible-parties[].party-uuids[]
Traceability propssystem-characteristics.props

Control Tailoring Request data in OSCAL files

When you generate OSCAL files for an authorization package, the export now includes overlays from both the authorization package and any associated control tailoring requests. Previously, only package-level overlays were included.

The number of overlay catalog files generated reflects the total number of distinct overlays across the package and its control tailoring requests. For example, if a package has two overlays and a control tailoring request introduces a third, the export produces three overlay catalog files.

The OSCAL export files also include control tailoring request data. The data includes baseline controls, and overlays with references to their associated control tailoring requests. The metadata section includes:

  • Responsible parties: the CTR Assigned To role and CTR Opened By role, alongside existing package and boundary role assignments
  • Roles: CTR-specific roles exported alongside existing package roles
  • System characteristics props: props representing control tailoring request data for traceability

For more information, see the following topics:

  • Export OSCAL catalog
  • Export OSCAL SSP
  • Export an OSCAL Assessment Plan
  • Export OSCAL Assessment Results

  • Export OSCAL catalog
    From the Control objective list view page, you can export the catalog in OSCAL JSON format for the selected control objectives. This action enables you to export your control objectives from CAM.

  • Export OSCAL SSP
    From the Authorization package overview record page, generate zip files and export the record's mapped content details in OSCAL format. To generate OSCAL SSP, the selected Authorization package must be in implemented state or after that. This action enables you to export your authorization package from CAM.
  • Export OSCAL POA&M
    Generate zip files Plan of Action and Milestones (POA&M) data in Open Security Controls Assessment Language (OSCAL) JSON format from the Authorization package overview record page. The authorization package must be in Implement state or later, and a POA&M file must link to the selected authorization package.
  • Export an OSCAL Assessment Plan
    Export engagement data as OSCAL Assessment Plan files to share testing plans with auditors or import into external systems.
  • Export OSCAL Assessment Results
    Export the OSCAL Assessment Results (AR) file for an authorization package from the CAM Workspace.

Parent Topic:CAM OSCAL