Skip to main content

Adoption Strategies

The best way to adopt OSCAL for your system depends on your circumstances. The OSCAL Foundation defines two adoption strategies:

  • Retrofit Adoption: Converting Legacy Documentation
  • New Adoption: Creating New Documentation

Retrofit Adoption

If you need to convert legacy documentation to OSCAL, follow the Retrofit Adoption strategy.

Organizations with existing Word and Excel based authorization packages need to first migrate their content to OSCAL with only the minimum necessary refactoring.

OSCAL is designed to meet you where you are. It allows conversion of content as-is. Once converted, it allows you to migrate over time from that initial convestion to OSCAL's more data-normalized approach.


New Adoption

If you are approaching OSCAL to intially create your system security plan and do not have legacy documentaiton to convert, follow the New Adoption strategy.