Compliance Trestle
OSCAL CompassCompliance Trestle creates, validates and governs compliance documentation in NIST's OSCAL format, the machine-readable standard for control catalogs, profiles, component definitions and assessment results. It is built to run as a CI/CD pipeline over compliance artifacts kept in git, splitting large OSCAL documents into reviewable pieces. It is part of the OSCAL Compass project.
Tagged self-attested: OSCAL documents validate against a public schema, but their content is the operator's claim. A detached signing command exists as a beta feature.
Openness
5 high confidence- license
- Apache-2.0(OSI)
- source
- public
- core features withheld
- no
Trestle is published under Apache-2.0 by the OSCAL Compass community project, with no company selling a fuller edition of it.
- https://cdn.jsdelivr.net/gh/oscal-compass/compliance-trestle@develop/LICENSE recorded 2026-09-26
Apache License, Version 2.0, full text
- https://cdn.jsdelivr.net/gh/oscal-compass/compliance-trestle@develop/README.md recorded 2026-09-27
README points to the OSCAL Compass community meetings and a CNCF OSCAL Compass end-to-end demo; external contributions welcome
- https://ungh.cc/repos/oscal-compass/compliance-trestle/files/develop recorded 2026-09-26
Full file listing of oscal-compass/compliance-trestle develop, 1,546 paths; no ee/, enterprise/, commercial/ or proprietary/ directory
Adoption
2 high confidencePyPI downloads of compliance-trestle, the product's own package, measure its use.
- https://pypistats.org/api/packages/compliance-trestle/recent recorded 2026-09-26
last_month downloads = 63,201 for compliance-trestle
Capability
3 high confidenceIts output is OSCAL, a published standard that auditors and their tools can validate independently, which puts it above tools that emit their own report formats. The content is still the operator's assertion, and signing is a beta feature, so it sits two steps below NVIDIA's hardware attestation.
- https://cdn.jsdelivr.net/gh/oscal-compass/compliance-trestle@develop/docs/predicates/oscal-signing/v1.md recorded 2026-09-26
"Trestle uses this predicate type in the in-toto Statement created by trestle sign"
- https://cdn.jsdelivr.net/gh/oscal-compass/compliance-trestle@develop/README.md recorded 2026-09-27
"Trestle is an ensemble of tools that enable the creation, validation, and governance of documentation artifacts for compliance needs. It leverages NIST's OSCAL as a standard data format"
- https://cdn.jsdelivr.net/gh/oscal-compass/compliance-trestle@develop/trestle/core/commands/sign.py recorded 2026-09-26
"Sign a JSON file as a detached DSSE provenance envelope"; the command is gated as a beta feature
Verified 2026-09-26