Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Specification for the Extensible Configuration Checklist Description Format (XCCDF), Version 1.1



Neal Ziring, Timothy Grance


This document specifies the data model and XML representation for the Extensible Configuration Checklist Description Format (XCCDF). An XCCDF document is a structured collection of security configuration rules for some set of target systems. The XCCDF specification is designed to support information interchange, document generation, organizational and situational tailoring, automated compliance testing, and compliance scoring. The specification also defines a data model and format for storing results of benchmark compliance testing. The intent of XCCDF is to provide a uniform foundation for expression of security checklists, benchmarks, and other configuration guidance, and thereby foster more widespread application of good security practices.
NIST Interagency/Internal Report (NISTIR) - 7275
Report Number


automated tool, benchmark, compliance, computer security, hardening, lockdown, metadata security requirement, operating system, OVAL, rule checking, security checklist, Security configuration, security controls, security policy, XHTML, XML


Ziring, N. and Grance, T. (2006), Specification for the Extensible Configuration Checklist Description Format (XCCDF), Version 1.1, NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online],, (Accessed June 20, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created October 31, 2006, Updated October 12, 2021