compliance-trestle
Tools to manage & autogenerate python objects representing the OSCAL layers/models
Decision gist · record as of 2026-08-14
Yes, if you work with NIST compliance frameworks or need to manage OSCAL documents at scale. The package is actively maintained, has no known vulnerabilities, supports current Python versions, and provides genuine value for teams bringing compliance into DevOps workflows. Install with confidence if your compliance tooling stack requires OSCAL interchange; skip it if you don't work with OSCAL or compliance automation.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later; designed for use in git-based workflows with compliance artifacts.
- Low friction installation via pip; actively maintained with releases every few days.
- Requires Python 3.10 or later and pulls in 19 runtime dependencies including cryptography, pydantic, and YAML/JSON handling libraries—typical for a compliance tooling suite.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 (permissive): you can use, modify, and distribute this package freely in commercial and private projects, provided you include the license notice and state material changes.
last release 2026-08-07 (7 days) · last repo commit 2026-08-14 · 269 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 193,632 downloads/mo, #9,849 on PyPI
Alternatives
Verify before relying
pip install compliance-trestle
from trestle.core.models import OscalBaseModel
# Load and manipulate OSCAL documents via the object model- Whether the package's 19 runtime dependencies introduce supply-chain risk in regulated environments.
- Performance characteristics when working with very large OSCAL catalogs or profiles.
- Extent of support for OSCAL 1.2.1 features beyond what v4 (maintenance mode) provides.
What it is and what it does
Compliance-trestle is a Python toolkit for managing OSCAL (NIST's machine-readable compliance standard) documents in a developer-friendly way. It breaks large OSCAL structures into smaller, editable pieces that fit into normal git workflows—allowing teams to version, review, and collaborate on compliance artifacts via pull requests. The package validates schemas, transforms documents from other formats into OSCAL, and provides governance tooling for markdown and drawio files used in compliance authoring.
The package is built around a CI/CD-friendly pipeline that sits on top of compliance artifacts in git, making compliance state transparent across stakeholders. It supports JSON and YAML formats (not XML), includes detached signing and verification for artifacts, and exposes an underlying object model for developers to interact with OSCAL programmatically. Version 5 is actively developed and supports OSCAL 1.2.1 with pydantic v2; version 4 is in maintenance mode until December 31, 2026.
Use it for
- Manage control descriptions and implementation details in git, linking system changes to affected compliance controls.
- Convert compliance documentation from spreadsheets or markdown into standardized OSCAL format for tool interoperability.
- Enforce consistent formatting and content in compliance markdown documents via template-based governance.
- Build compliance CI/CD pipelines that validate and version OSCAL artifacts alongside infrastructure code.
- Split large OSCAL catalogs into smaller, reviewable pieces for team collaboration and peer review.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you work with NIST compliance frameworks or need to manage OSCAL documents at scale.
The package is actively maintained, has no known vulnerabilities, supports current Python versions, and provides genuine value for teams bringing compliance into DevOps workflows. Install with confidence if your compliance tooling stack requires OSCAL interchange; skip it if you don't work with OSCAL or compliance automation.
Install
compliance-trestle on PyPI
Before you install
Low friction installation via pip; actively maintained with releases every few days. Requires Python 3.10 or later and pulls in 19 runtime dependencies including cryptography, pydantic, and YAML/JSON handling libraries—typical for a compliance tooling suite.
Requires Python 3.10 or later; designed for use in git-based workflows with compliance artifacts.
License in practice
Apache-2.0 (permissive): you can use, modify, and distribute this package freely in commercial and private projects, provided you include the license notice and state material changes.
Quickstart
pip install compliance-trestle
from trestle.core.models import OscalBaseModel
# Load and manipulate OSCAL documents via the object model
Verify before relying
- Whether the package's 19 runtime dependencies introduce supply-chain risk in regulated environments.
- Performance characteristics when working with very large OSCAL catalogs or profiles.
- Extent of support for OSCAL 1.2.1 features beyond what v4 (maintenance mode) provides.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 19 packagesattrscmarkgfmcryptographydefusedxmlfurlilcliimportlib-resourcesjinja2openpyxlorjsonparamikopydanticpython-dotenvpython-frontmatterpywin32requestsrfc8785ruamel-yamlsecuresystemslib |
| Maintenance | Actively maintained 7 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 193,632 / month, #9,849 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersIntended Audience :: Information TechnologyLicense :: OSI Approved :: Apache Software LicenseOperating System :: MicrosoftOperating System :: POSIXProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12 |
Evidence: compliance_trestle-5.0.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “OSCAL document management”
- compliance-trestleCompliance-trestle manages, validates, and transforms OSCAL (NIST's…
- google-cloud-documentai-toolboxProgrammatically manage, manipulate, and extract information from…
- cohere-compass-sdkParse documents via a remote Compass Parser API and manage indexed…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also agent_governance_toolkit · agent-governance-toolkit-core · cdk-nag · prowler · terraform-compliance · stix2-validator · docling-slim · agent-governance-toolkit-cli · doclang · solc-select