---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Export OSCAL POA\&M

# Export OSCAL POA\&M {#ariaid-title1}

* Release version: Zurich
* 
* Updated December 1, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Generate zip files Plan of Action and Milestones (POA\&M) data in Open Security Controls Assessment Language (OSCAL) JSON format from the Authorization package overview record page. The authorization package must be in
Implement state or later, and a POA\&M file must link to the selected authorization package.

## Before you begin

Role required: sn_irm_cont_auth.admin, sn_irm_cont_auth.system_owner, sn_irm_cont_auth.authorization_official, sn_irm_cont_auth.info_system_sec_manager, or sn_irm_cont_auth.info_system_sec_officer

## Procedure

1. Navigate to WorkspacesCAM Workspace.
2. In the CAM Workspace, select the List icon (![List]()).
3. Select Authorization packages from the RMF list.
4. From the list view, select the authorization package record for which you want to generate a POA\&M file.  
   Note:  
   The authorization package must be in the Implement, Assess, Authorize, or Monitor state to generate OSCAL POA\&M.
5. To export OSCAL POA\&M, select Generate OSCAL POAM from the Generate OSCAL drop-down.  
   Note:  
   To generate the OSCAL POA\&M, the POA\&M file must be linked to the selected Authorization package.

   A message appears to indicate that file generation is in progress. Refresh the page before
   downloading the JSON files.
6. To download the POA\&M zip file, select Download OSCAL POAM from the Download OSCAL drop-down list.  
   Note:  
   * If there's POA\&M linked to the authorization package, the POA\&M files are generated.
   * Verify that the pop-up blocker is turned off for the URL so that the POA\&M zip file is automatically downloaded to your local repository.
   {#export-oscal-poa-m__ul_syf_fml_nhc}

   To customize the OSCAL behavior for export, see the [OSCAL Model customization support \[KB1650397\]](https://hi.service-now.com/kb_view.do?sysparm_article=KB1650397) article in the Now Support Knowledge Base.

   For more information on OSCAL import error, see the [OSCAL Import \[KB1794095\]](https://hi.service-now.com/kb_view.do?sysparm_article=KB1794095) article in the Now Support Knowledge Base.
{#export-oscal-poa-m__steps_ebb_yqh_mhc}

*[\>]: and then


