Validate OSCAL documents for structural integrity, schema compliance, and OSCAL-specific requirements...
Validate OSCAL documents against NIST schemas and perform structural integrity checks to ensure compliance data quality.
Use this skill when you need to:
This skill validates documents you provide against structural rules and OSCAL schema requirements. Validation logic is safe — it checks format and syntax, not compliance content.
Note: For baseline completeness validation (e.g., "does this SSP cover all FedRAMP Moderate controls?"), you must also provide the baseline profile/catalog.
| Level | Meaning | Action Required |
|---|---|---|
| ERROR | Document is invalid | Must fix before use |
| WARNING | Potential issues | Should review |
| INFO | Suggestions | Optional improvements |
| Rule | Description |
|---|---|
| STRUCT-001 | Document must not be empty or null |
| STRUCT-002 | Document must have a root element |
| STRUCT-003 | Root element must be a valid OSCAL model type |
| Rule | Description |
|---|---|
| META-001 | Metadata section is required |
| META-002 | Title is required |
| META-003 | Last-modified timestamp is required |
| META-004 | Version is required |
| META-005 | OSCAL version should match current spec |
| Rule | Description |
|---|---|
| UUID-001 | Document UUID must be present |
| UUID-002 | UUIDs must be valid RFC 4122 format |
| UUID-003 | UUIDs must be unique within document |
| Rule | Description |
|---|---|
| REF-001 | Internal references must resolve |
| REF-002 | Control references must exist |
| REF-003 | Party references must resolve |
metadata sectiontitle is present and non-emptylast-modified is valid ISO timestampversion is presentoscal-version matches expected format#uuid-value)For Catalogs:
For SSPs:
For Component Definitions:
Provide validation results as:
VALIDATION REPORT
=================
Document: [filename]
Model Type: [type]
Valid: [YES/NO]
Issues Found:
- [SEVERITY] [RULE-ID]: [Message] at [location]
Summary:
- Errors: X
- Warnings: Y
- Info: Z
| Issue | Cause | Fix |
|---|---|---|
| Missing metadata | Incomplete document | Add required metadata section |
| Invalid UUID | Malformed identifier | Generate new RFC 4122 UUID |
| Unresolved reference | Broken link | Update reference or add target |
| Missing timestamp | Incomplete metadata | Add ISO 8601 timestamp |
When asked "Validate this SSP for compliance":