Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Transitioning to the Security Content Automation Protocol (SCAP) Version 2



David A. Waltermire, Jessica Fitzgerald-McKay


The Security Content Automation Protocol (SCAP) version 2 (v2) automates endpoint posture information collection and the incorporation of that information into network defense capabilities using standardized protocols. SCAP v2 expands the endpoint types supported by SCAP v1 through the explicit inclusion of network equipment, Internet of Things (IoT), and mobile devices in its scope. To automate self-reporting of posture information from endpoint machines, SCAP v2 will integrate with existing network management protocols that include the Internet Engineering Task Force (IETF) Network Endpoint Assessment (NEA) protocols. SCAP v2 will streamline SCAP content acquisition and reuse through its use of the IETF Resource Oriented Lightweight Information Exchange (ROLIE) protocol. Improvements to software version identification and the incorporation of patch information will be made by transitioning from the Common Platform Enumeration (CPE) to Software Identification (SWID) Tags. SCAP v2 provides component-level interoperability via a modular and extensible architecture. This white paper provides a gap analysis of SCAP v1 and an overview of how SCAP v2 will address these gaps; describes the SCAP 2.0 architecture; and provides a plan for completing the work necessary to finalize SCAP v2.


architecture, configuration, endpoint, endpoint security, SCAP, security automation, security content automation, Security Content Automation Protocol, software identification, SWID, vulnerability


Waltermire, D. and Fitzgerald-McKay, J. (2018), Transitioning to the Security Content Automation Protocol (SCAP) Version 2, Other, National Institute of Standards and Technology, Gaithersburg, MD, [online], (Accessed May 25, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created September 10, 2018, Updated May 4, 2021