Ross ROSS = Recommend OSS · open-source software intelligence for agents

usnistgov/macos_security

macOS Security Compliance Project observed · 2026-08-28

github.com/usnistgov/macos_security · homepage · YAML · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

96/100

  • Activity 99
  • Release rhythm 89
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 0.0
  • age_days: 2280
  • days_rel: 72
  • days_push: 7
  • n_releases_24m: 31

Full methodology

Adoption not part of the score

2449 stars · 301 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

The macOS Security Compliance Project (mSCP) is an open-source tool from NIST that generates security baselines, configuration profiles, compliance scripts, and guidance documents for Apple platforms (macOS, iOS/iPadOS, visionOS). It implements NIST SP 800-219 automated secure configuration guidance derived from NIST SP 800-53 controls.

Use cases

  • generate macOS security hardening baselines
  • create MDM configuration profiles for Apple devices
  • audit and enforce macOS security settings with compliance scripts
  • produce CIS-style benchmark documentation for macOS
  • secure federal or enterprise Mac fleets against NIST 800-53 controls
  • customize a security baseline for my organization's Macs
  • check macOS compliance automatically

When to choose

  • you manage macOS/iOS devices and need NIST 800-53 or CIS-aligned hardening
  • you need generated configuration profiles plus enforcement scripts for settings profiles can't enforce
  • you want authoritative, Apple-recognized security guidance updated quickly for new OS releases
  • you're a vendor building compliance manifests for Apple platforms

When to avoid

  • you need security compliance for non-Apple platforms
  • you want a GUI-based policy management tool rather than CLI-generated artifacts
  • you have no MDM or device management capability and need only profile-based settings
  • you need a turnkey monitoring/endpoint-detection product rather than configuration guidance

Facets

cli-tool · maturity active

security configuration-management cli developer-tools security apple-ecosystem developer-tools self-hosted cli python mdm nist-800-53 compliance hardening configuration-profiles cis-benchmarks macos-security device-management macos docker

4 sources

Member repositories

RepositoryRoleHealth v2
usnistgov/macos_securitymain96

For agents

markdown · JSON · MCP: product_card(name="usnistgov/macos_security")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem