Export OSCAL Assessment Results

  • Release version: Australia
  • Updated May 26, 2026
  • 1 minute to read
  • Export the OSCAL Assessment Results (AR) file for an authorization package from the CAM Workspace.

    Before you begin

    • The authorization package must be in the Assess, Authorize, or Monitor step.
    • At least one control test in the engagement must have a closed state. Accepted closed states are:
      • Closed Complete
      • Closed Incomplete
      • Closed Skipped

    Roles required: sn_irm_cont_auth.info_system_sec_manager, sn_irm_cont_auth.info_system_sec_officer, or sn_irm_cont_auth.admin.

    Procedure

    1. Navigate to Workspaces > CAM Workspace.
    2. In the CAM Workspace, select the List icon.
    3. Select Authorization packages from the RMF list.
    4. Select the authorization package record for which you want to generate an AR file.
    5. Navigate to the Engagements tab.
    6. Select Generate OSCAL.

      A banner appears with the message: "The files are being generated. Please refresh the page after some time, then click 'Download OSCAL Files' to download the OSCAL files."

      The system starts generating OSCAL files asynchronously. This process takes a few minutes depending on package complexity. The Download OSCAL Files button appears when the process is complete.

      Each time you run a generate operation, any previously generated OSCAL files for the package are deleted and replaced.

    7. After the process is complete, select Download OSCAL Files.
      Note:
      Verify that the pop-up blocker is turned off for the URL so that the ZIP file is automatically downloaded to your local machine.

      A ZIP file is downloaded containing the following OSCAL files:

      • Catalog JSON file
      • Profile JSON file
      • SSP JSON file
      • Assessment Plan (AP) JSON file (one per engagement)
      • Assessment Results (AR) JSON file (one per engagement)
      • Overlay Catalog JSON file (if overlays are configured. Also includes overlays from associated control tailoring requests)
      • POA&M JSON file (included if POA&M items exist)

      You can validate these files using the OSCAL CLI validator and import them into other systems or share them with external auditors for assessment planning.

    What to do next

    For information about the OSCAL fields exported in the AR file and their corresponding ServiceNow CAM fields, see OSCAL Assessment Results field mapping.