Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

mSCP Automated Secure Configuration Guidance: Draft SP 800-219r2 Available for Public Comment

NIST requests comments on the initial public draft (ipd) of Special Publication (SP) 800-219r2 (Revision 2), Automated Secure Configuration Guidance From the macOS Security Compliance Project (mSCP).

NIST requests comments on the initial public draft (ipd) of Special Publication (SP) 800-219r2 (Revision 2), Automated Secure Configuration Guidance From the macOS Security Compliance Project (mSCP). This publication provides resources for assessing macOS desktop and laptop, iOS, and visionOS system security in an automated way, including up-to-date and practical recommendations (i.e., secure baselines and associated rules) that are available on the mSCP GitHub site. It also describes use cases for leveraging the mSCP content. Updates from the previous version of this publication highlight the mSCP’s next generation of improvements, including simpler OS version and rule management as well as an expanded audience.

The public comment period is open from June 22 through August 14, 2026. See the publication details for a copy of the draft and instructions for submitting comments.

NOTE: A call for patent claims is included on page ii of this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications.

 

Released June 22, 2026
Was this page helpful?