Compliance as code
OSCALControl implementations live in compliance-trestle. SSPs are generated from the same source as the Terraform — no parallel documentation universe.
- OSCAL component definitions per system · diff-able in git
- Inheritance from CSP / shared-service profiles (FedRAMP, CMS, DoD)
- Assessment results land back as OSCAL · SAR auto-built
- POA&Ms generated from failed controls · not authored by hand
