Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

SCAP Composer User Guide



Joshua Lubell


SCAP Composer is a software application from the National Institute of Standards and Technology (NIST) for creating Security Content Automation Protocol (SCAP – pronounced "ess-cap") source data stream collections. A source data stream collection is a bundle of Extensible Markup Language (XML) documents, each of which must be valid with respect to a schema defined in an SCAP component specification. SCAP Composer's limited scope and small footprint make it easy to install, use, and integrate with other SCAP content development tools. SCAP Composer uses the DITA Open Toolkit, an open source publishing engine for content authored in the Darwin Information Typing Architecture (DITA). SCAP Composer may be used with the NIST SCAP Content Validation Tool to check the conformance of SCAP source data stream components to content requirements and recommendations.
NIST Interagency/Internal Report (NISTIR) - 8290-upd1
Report Number


SCAP, Security Content Automation Protocol, source data stream, Darwin Information Typing Architecture, software, DITA Open Toolkit, SCAP content validation


Lubell, J. (2022), SCAP Composer User Guide, NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online],, (Accessed April 22, 2024)
Created May 16, 2022, Updated November 29, 2022