OSCAL Requirements

All OSCAL Core Requirements must be met for all OSCAL artifacts.

This chapter contains information about OSCAL SSP requirements that are not explicit FedRAMP SSP requirements.

System Status

FedRAMP no longer includes System Status in the SSP template; however core OSCAL requires the system status to be identified.

The system statys is represented in system-characteristics.

OSCAL Representation

system-security-plan:
  system-characteristics:
    status:
      state: operational
      remarks: 'Remarks are optional if status/state is "operational".
        Remarks are required otherwise.'


OSCAL Allowed Values

Valid state values:

Although core OSCAL also allows under-development and disposition (retired), these values do not make sense in a FedRAMP authorization package.