What you can export
MergeGuide generates the following OSCAL document types:| Document | What it contains |
|---|---|
| Component Definition | The controls a component implements and how. |
| Assessment Results | The outcome of assessing your code against the controls. |
| Plan of Action & Milestones (POA&M) | Open items and the plan to remediate them. |
| Catalog | The control catalog for a selected framework. |
This page lists only the OSCAL document types that currently ship. Additional
document types may be added over time.
Export from the dashboard
- Open Compliance in the dashboard.
- Choose the framework and the OSCAL document type you need.
- Generate and download the OSCAL file.
Verify exported evidence
MergeGuide evidence artifacts are signed. You can verify an artifact with the CLI:verify-evidence reference.
Next steps
Compliance overview
How compliance frameworks work in MergeGuide.
SBOM export
Generate a Software Bill of Materials.