Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

SCAP 1.4 Component Specification Version Updates: An Annex to NIST SP 800-126r4

Published

Author(s)

Dragos Prisaca, Stephen Quinn

Abstract

The Security Content Automation Protocol (SCAP) is a multi-purpose framework of component specifications that support automated configuration, vulnerability, patch checking, security measurement, and technical control compliance activities. The SCAP version 1.4 specification is defined by the combination of NIST SP 800-126r4, a set of schemas, and this document. This document allows the use of specific minor version updates to SCAP 1.4 component specifications and particular Open Vulnerability and Assessment Language (OVAL) schema versions to provide additional functionality for SCAP 1.4 without causing any loss of existing functionality.
Citation
Special Publication (NIST SP) - 800-126Ar4
Report Number
800-126Ar4

Keywords

eXtensible Configuration Checklist Description Format (XCCDF), Open Vulnerability and Assessment Language (OVAL), security automation, security configuration, Security Content Automation Protocol (SCAP)

Citation

Prisaca, D. and Quinn, S. (2026), SCAP 1.4 Component Specification Version Updates: An Annex to NIST SP 800-126r4, Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.SP.800-126Ar4, https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=961964 (Accessed June 9, 2026)
Additional citation formats

Issues

If you have any questions about this publication or are having problems accessing it, please contact [email protected].

Created June 8, 2026
Was this page helpful?