Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Technical Specification for the Security Content Automation Protocol (SCAP) SCAP Version 1.4

Published

Author(s)

Dragos Prisaca, Stephen Quinn, Jack Vander Pol, Daniel Harris

Abstract

The Security Content Automation Protocol (SCAP) is a suite of specifications that standardize the format and nomenclature by which software flaw and security configuration information is communicated, both to machines and humans. This publication, along with its annex (NIST Special Publication 800-126Ar4) and a set of schemas, collectively define the technical composition of SCAP version 1.4 in terms of its component specifications, their interrelationships and interoperation, and the requirements for SCAP content.
Citation
Special Publication (NIST SP) - 800-126r4
Report Number
800-126r4

Keywords

checklists, patch verification, security automation, security checklists, security configuration, Security Content Automation Protocol (SCAP), software flaws, vulnerabilities.

Citation

Prisaca, D. , Quinn, S. , Vander Pol, J. and Harris, D. (2026), Technical Specification for the Security Content Automation Protocol (SCAP) SCAP Version 1.4, Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.SP.800-126r4, https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=961963 (Accessed June 9, 2026)
Additional citation formats

Issues

If you have any questions about this publication or are having problems accessing it, please contact [email protected].

Created June 8, 2026
Was this page helpful?