Compliance-as-code ● New

Meet OscalIQ

Compliance, in OSCAL, without the pain.

OscalIQ turns your compliance documentation into a living system of record. It converts legacy Word and Excel System Security Plans into machine-readable NIST OSCAL and keeps them accurate and audit-ready as the system evolves - with built-in DISA STIG, CMMC / NIST 800-171, POA&M, and FedRAMP 20x support.

OSCAL readiness

What is OSCAL, and why does readiness matter?

OSCAL - the Open Security Controls Assessment Language - is NIST’s standard for machine-readable compliance documentation. Instead of a System Security Plan (SSP) that lives in a Word file and goes stale the moment it’s signed, OSCAL represents your controls, assessments, and POA&Ms as structured data that tools can validate, exchange, and keep current.

As FedRAMP 20x pushes the whole program toward continuous, machine-readable validation and Key Security Indicators (KSIs), OSCAL readiness stops being optional. OscalIQ is the fastest way to get there: convert a legacy SSP to OSCAL, assess against DISA STIGs and CMMC / NIST 800-171 with live SPRS scoring, manage POA&Ms and deviations, and emit the machine-readable packages agencies and 3PAOs ask for - all in one place.

What OscalIQ does

Author, assess, and maintain compliance in one place

Legacy SSPs to OSCAL

Bring Word and Excel System Security Plans in and maintain them as clean, machine-readable NIST OSCAL - a living system of record, not a document that goes stale.

FedRAMP 20x ready

Track Key Security Indicators (KSIs), see live readiness, and emit the machine-readable 20x package.

DISA STIG assessment

Assess systems against DISA STIGs with a browsable STIG library, version migration, and checklist tracking that stays current as new releases ship.

CMMC / NIST 800-171

Level 1 and Level 2 assessment against the 110 NIST 800-171 requirements, with DoD SPRS scoring and POA&M eligibility.

Findings to closure

POA&M management, deviations (false positive, risk adjustment, operational requirement), and FedRAMP inventory import.

Integrations

Bring-your-own-AI to translate cryptic control and STIG language into plain English, Jira to track gaps to closure, and a REST API with personal access tokens.

How it works

From legacy document to living, audit-ready OSCAL

1

Import

Upload a legacy Word or Excel SSP. OscalIQ extracts the control implementations for you to review.

2

Maintain

Keep everything as machine-readable OSCAL and edit it as your system evolves - always export-ready.

3

Assess

Assess against DISA STIGs and CMMC / 800-171, with live scoring and readiness.

4

Close

Turn gaps into POA&M items and Jira issues, and track them to closure.

FAQ

OscalIQ questions, answered

What is OscalIQ?

OscalIQ is a compliance-as-code platform from Inttelio. It converts legacy Word and Excel System Security Plans into machine-readable NIST OSCAL and keeps them accurate and audit-ready, with built-in DISA STIG, CMMC / NIST 800-171, and POA&M management.

What is OSCAL?

OSCAL (the Open Security Controls Assessment Language) is a NIST standard set of machine-readable formats for security documentation - System Security Plans, assessment plans and results, and POA&Ms. Representing an SSP in OSCAL lets tools validate, exchange, and continuously maintain compliance data instead of passing static Word documents around. OscalIQ makes an organization OSCAL-ready without hand-writing XML or JSON.

What is FedRAMP 20x and how do I get ready?

FedRAMP 20x is FedRAMP's modernized path built around continuous, machine-readable validation using Key Security Indicators (KSIs) instead of a static once-a-year package. To get ready for FedRAMP 20x you need your security data in OSCAL, a way to track and evidence each KSI, and continuous monitoring. OscalIQ tracks KSIs, shows live 20x readiness, and emits the machine-readable package.

How do I convert an SSP to OSCAL?

Upload your existing Word or Excel System Security Plan to OscalIQ. It extracts the control implementations for you to review, then maintains them as machine-readable OSCAL you can export any time - so you convert once and keep it living, rather than re-converting a document every cycle.

Which frameworks does it support?

FedRAMP (including the 20x Key Security Indicators), NIST SP 800-53 Rev5, DISA STIGs, and CMMC 2.0 / NIST SP 800-171 Level 1 and Level 2 with DoD SPRS scoring.

Does OscalIQ send my data to AI models?

No. AI is optional, off by default, and bring-your-own-model: it runs on your chosen provider under your own API key. Only the public standard’s requirement text is ever sent - to translate cryptic wording into plain language - never your SSP content, evidence, findings, or answers.

Who is it for?

Cloud service providers pursuing or maintaining an authorization, compliance consultants and 3PAOs, and internal GRC teams who need to keep an SSP living and accurate rather than frozen in a document.

Is it available?

Yes. OscalIQ is a standalone product from the Inttelio team - request a demo for a guided walkthrough.

See OscalIQ in action

A standalone product from the Inttelio team. Request a demo for a guided walkthrough.

Request a demo