National Institute of Standards and Technology (NIST) - Information technology Laboratory (ITL)

SCAP Specifications

The following specifications are proposed for SCAP version 1.2.


SCAP: Security Content Automation Protocol
Version: 1.2
Status: Final
Specification: NIST Special Publication (SP) 800-126 rev 2
XML Schema: Source Data Stream, Constructs
Example: Source Data Stream Example
Schematron: Instructions and Download
Errata: NIST Special Publication (SP) 800-126 Rev 2 Errata
Change Proposals: Summer 2011 Developer Days (May 31, 2011)


SCAP Content Validation Tool
Released: 06/04/2014
Download: SCAP Content Validation Tool (Download 20 MB)
sha-1: 80D45818F32C6D906406845720DDF9535ACC3B7C
sha-256: CEB372647898C59875128B6CA4590A06DAAD5924CFF9BFEC92AABD2248E5E60E
Description: The SCAP Content Validation Tool is designed to validate the correctness of a SCAP data stream for a particular use case according to what is defined in SP 800-126. This version of the tool is designed to validate SCAP content adhering to SCAP version 1.0, 1.1, and 1.2. The scapval.html within the tool zip file contains additional information about how to run the tool.
SCAP 1.0 Zip Bundle to SCAP 1.2 Data Stream Converter
Sourceforge Site


XCCDF: The Extensible Configuration Checklist Description Format
Version: 1.2
Web site:
Email Discussion List: (View archive) (Subscribe) (Unsubscribe)
OVAL®: Open Vulnerability and Assessment Language
Version: 5.10
Web site:
Developer's Forum: (View archive) (Register)
OCIL: Open Checklist Interactive Language
Version: 2.0
Web site:
Email Discussion List: (Subscribe) (Unsubscribe)
Asset Identification
Version: 1.1
Web site:
Email Discussion List: (Subscribe) (Unsubscribe)
ARF: Asset Reporting Format
Version: 1.1
Web site:
Email Discussion List: (Subscribe) (Unsubscribe)


CCE™: Common Configuration Enumeration
Version: 5
Contact Email:
Official CCE List:
Community Forum: (Subscribe) (Unsubscribe)
CPE™: Common Platform Enumeration
Version: 2.3
Web site:
Contact Email:
Official Dictionary:
Community Forum: (Subscribe) (Unsubscribe)
CVE®: Common Vulnerabilities and Exposures
Version: No version
Web site:
Contact Email:
Official CVE List:
NVD CVE-based Vulnerabilities:


CVSS: Common Vulnerability Scoring System
Version: 2
Specification: NIST IR 7435
Web site:
CCSS: Common Configuration Scoring System
Version: 1.0
Specification: NIST IR 7502


TMSAD: Trust Model for Security Automation Data
Version: 1.0
Web site:

Related Publications and Resources

Guide to Using Vulnerability Naming Schemes
Specification: SP 800-51 Rev. 1