Historical analysis: this article examines information published by the source on June 22, 2026. Check the latest vendor guidance before acting.
What was published
NIST has released an initial public draft (ipd) of Special Publication (SP) 800-219r2, titled “Automated Secure Configuration Guidance From the macOS Security Compliance Project (mSCP).”
Status and scope
This document is currently in the initial public draft stage. A public comment period has been established from June 22 through August 14, 2026. The guidance focuses on enterprise applications of security automation for Apple operating systems.
What the guidance covers
The publication provides resources and practical recommendations to assess system security in an automated manner. Specifically, it addresses:
* macOS (desktop and laptop)
* iOS
* visionOS
The draft references secure baselines and associated rules hosted on the mSCP GitHub site and outlines specific use cases for leveraging this content.
How organizations can use it
Vulnerability management teams can utilize these baselines to shift from manual configuration audits to automated assessment. By applying the rules provided via the mSCP project, defenders can identify deviations from the recommended secure state across their Apple fleet. Revision 2 introduces improvements intended to simplify rule management and OS versioning compared to previous iterations.
Decisions and next steps
Security leaders should evaluate whether their current configuration management process for Apple devices relies on static checklists or automated validation.
Our analysis suggests the following decision checkpoints:
1. Baseline Alignment: Compare existing internal hardening standards against the mSCP baselines to identify gaps in exposure management.
2. Automation Integration: Determine if current tooling can ingest the GitHub-hosted rules to provide continuous visibility into configuration drift.
3. Verification Method: To verify that a mitigation is effective, organizations should move beyond version checks and instead use the automated assessment tools described in the guidance to produce evidence of a compliant state.
Limits and open questions
Because this is an initial public draft, it is not yet a final standard. Furthermore, these are configuration baselines intended to reduce exposure; they are not patches for software vulnerabilities and do not eliminate all security risks. The integration of GitHub-hosted rules into official NIST workflows remains an external dependency that organizations must manage.
Source and editorial note
mSCP Automated Secure Configuration Guidance: Draft SP 800-219r2 Available for Public Comment June 22, 2026 · Source date: June 22, 2026 · Retrieved August 31, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Archive date: June 25, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 07, 2026 at 01:35 UTC.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗