{
  "mapping": {
    "title": "CMMC 20X Evidence Profile v0.1 to NIST OSCAL Assessment Results",
    "status": "discussion-draft-non-normative",
    "reviewed_at": "2026-08-13",
    "oscal_version_reviewed": "1.2.3",
    "source": "https://pages.nist.gov/OSCAL/learn/concepts/layer/assessment/assessment-results/",
    "notice": "This is a conceptual mapping, not an OSCAL Assessment Results document, conformance claim, CMMC standard, or Government-approved extension."
  },
  "entries": [
    {
      "profile_paths": ["profile.package_id", "profile.published_at", "profile.schema_version"],
      "oscal_destinations": ["assessment-results.uuid", "assessment-results.metadata.last-modified", "assessment-results.metadata.version"],
      "disposition": "direct-with-transformation",
      "note": "OSCAL requires a root UUID and metadata. The discussion-draft package uses a readable synthetic identifier and would need UUID transformation in an OSCAL document."
    },
    {
      "profile_paths": ["scope", "claims[*].requirement_id", "claims[*].assessment_objective_ids"],
      "oscal_destinations": ["assessment-results.import-ap", "results[*].reviewed-controls", "results[*].assessment-subjects"],
      "disposition": "contextual",
      "note": "OSCAL Assessment Results imports an Assessment Plan, which links the system and SSP. A production mapping must preserve those document relationships rather than duplicate a free-standing scope."
    },
    {
      "profile_paths": ["source_evidence[*]"],
      "oscal_destinations": ["results[*].observations", "observations[*].relevant-evidence", "back-matter.resources"],
      "disposition": "direct-or-referenced",
      "note": "Evidence may be cited as relevant evidence or represented as a back-matter resource. CMMC-specific coverage, collection, integrity, and limitation semantics still require agreed conventions."
    },
    {
      "profile_paths": ["conflicts[*]", "machine_analysis[*]"],
      "oscal_destinations": ["results[*].observations", "results[*].findings", "results[*].risks"],
      "disposition": "contextual-with-boundary",
      "note": "Tool observations and candidate analysis must not be silently promoted into assessor findings. The profile keeps the producer and decision layer explicit."
    },
    {
      "profile_paths": ["human_dispositions[*]"],
      "oscal_destinations": ["results[*].findings", "results[*].attestations", "results[*].assessment-log"],
      "disposition": "contextual",
      "note": "The target depends on whether the disposition is a finding, assertion, or recorded assessment action. CMMC roles and permissible uses must be defined outside this mapping."
    },
    {
      "profile_paths": ["authorized_decisions[*]"],
      "oscal_destinations": [],
      "disposition": "outside-assessment-results",
      "note": "OSCAL Assessment Results can inform authorization activity; it does not itself grant CMMC certification, affirmation, award, enforcement, or supplier-status effect."
    },
    {
      "profile_paths": ["responsibility_records[*]", "scope.providers[*]"],
      "oscal_destinations": ["system-security-plan.system-implementation.components", "system-security-plan.control-implementation"],
      "disposition": "cross-model-context",
      "note": "Provider inheritance and customer duties originate in implementation context and should be linked through the imported Assessment Plan and SSP where available."
    },
    {
      "profile_paths": ["claims[*].freshness", "material_changes[*]"],
      "oscal_destinations": ["results[*].start", "results[*].end", "results[*].expires", "results[*].observations", "assessment-results.metadata.last-modified"],
      "disposition": "extension-or-profile-rule-needed",
      "note": "OSCAL supports time, observations, result expiration, and document change identity. CMMC-specific freshness and material-change propagation require a defined profile or extension convention."
    }
  ]
}
