AI Potluck
Back to Gap Map Product / UX / Assurance & compliance evidence

Compliance Trestle

OSCAL Compass
open source / Overall score: 2.6

Compliance Trestle creates, validates and governs compliance documentation in NIST's OSCAL format, the machine-readable standard for control catalogs, profiles, component definitions and assessment results. It is built to run as a CI/CD pipeline over compliance artifacts kept in git, splitting large OSCAL documents into reviewable pieces. It is part of the OSCAL Compass project.

Tagged self-attested: OSCAL documents validate against a public schema, but their content is the operator's claim. A detached signing command exists as a beta feature.

Openness

5 high confidence
5.0
license
Apache-2.0(OSI)
source
public
core features withheld
no

Trestle is published under Apache-2.0 by the OSCAL Compass community project, with no company selling a fuller edition of it.

Adoption

2 high confidence
2.0

PyPI downloads of compliance-trestle, the product's own package, measure its use.

Capability

3 high confidence
3.0

Its output is OSCAL, a published standard that auditors and their tools can validate independently, which puts it above tools that emit their own report formats. The content is still the operator's assertion, and signing is a beta feature, so it sits two steps below NVIDIA's hardware attestation.

Verified 2026-09-26