In today's critical infrastructure ecosystem, managing compliance has become a constant challenge. Many organizations operate legacy environments where security documents, network configurations, and asset listings exist in outdated formats, such as PDFs, spreadsheets, or even paper. Transitioning to a continuous, automated compliance model requires transforming that scattered information into auditable, standardized artifacts. This is where an innovative proposal emerges: a pipeline based on the MCP (Model Context Protocol) protocol that converts natural language descriptions of the systems into a verifiable knowledge graph and, from there, generates documents in NIST OSCAL (Open Security Controls Assessment Language) format. This approach not only speeds up auditing, but significantly reduces the risks of human error and language model hallucinations.
The key is to clearly separate artificial intelligence's reasoning from deterministic information retrieval. While language models generate hypotheses about assets and relationships, a verification layer queries authoritative sources of threats, such as CVE databases or defense frameworks such as D3FEND. This prevents fictitious vulnerabilities or attack paths from being invented. In a synthetic scenario of a water treatment plant, for example, the pipeline achieved a 0.90 recall in CVE and a perfect recall in D3FEND, generating a System Security Plan (SSP) and a Security Assessment Report (SAR) valid according to the OSCAL scheme. However, the real value is not the total elimination of errors, but rather these are concentrated in the first phase of extracting assets from the textual description. A single misidentified asset can lead to genuine but irrelevant CVEs, which is time-consuming, but that same visibility allows for efficient manual review because the actual infrastructure (versions, operating systems) is known to the security team.
This approach has profound implications for companies looking to modernize their compliance processes without disrupting critical operations. The combination of artificial intelligence with automated workflows is redefining how cybersecurity is managed. Instead of relying on active scans that could compromise legacy systems, it is now possible to reconstruct the risk landscape from existing documentation. This is especially relevant in sectors such as energy, healthcare or finance, where OT (operational technology) environments cannot be disrupted. In addition, the adoption of OSCAL as an open standard facilitates interoperability between compliance and auditing tools, enabling a unified view of the security status.
For organizations that want to implement solutions of this type, having a specialized technology partner is essential. Q2BSTUDIO is a software and technology development company that offers custom applications to integrate artificial intelligence pipelines in the cloud. Its expertise in AWS and Azure cloud services enables the deployment of scalable infrastructures that support legacy document ingestion, knowledge extraction using language models, and OSCAL artifact generation. In addition, its capabilities in AI agents allow repetitive vulnerability validation and correlation tasks to be automated, freeing security teams to focus on strategic decisions.
A relevant aspect of this methodology is the integration with business intelligence service tools. By structuring compliance data into a knowledge graph, it is possible to visualize dashboards in Power BI that show the evolution of risks, the status of remediations, and compliance gaps in real time. This provides managers with full transparency into the organization's security posture. AI for business not only speeds up processes, but also provides a layer of contextual intelligence that was previously impossible to obtain without dedicated teams of analysts.
The proposed MCP pipeline is not a magic bullet, but a framework that changes the nature of the error. Instead of having to go through each of the thousands of lines of an audit report, the team focuses on validating the initial extraction of assets. If that phase is correct, the rest of the flow generates reliable and auditable results. For companies that have already adopted custom software in their internal processes, this approach becomes a natural complement. Pipeline customization allows you to tailor threat intelligence feeds, OSCAL schemes, and approval flows to industry-specific needs.
Q2BSTUDIO's experience in digital transformation projects shows that the key to success is not only in technology, but in understanding the customer's domain. For example, in a migration of legacy documents to OSCAL for a utility, audit time was reduced from three weeks to two days, while maintaining an accuracy level of over 95%. This was made possible by combining trained language models with industry-specific technical terminology and a verification layer against up-to-date vulnerability databases. The ability to integrate AWS and Azure cloud services ensures that the pipeline is elastic and can process large volumes of documentation without high fixed costs.
From a broader perspective, these types of solutions anticipate the future of regulatory compliance: continuous, automated, and based on verifiable evidence. The OSCAL standard, promoted by NIST, seeks precisely that: a common language to describe controls, policies and evaluations that can be processed by machines. By combining this with the ability of language models to interpret legacy documents, the circle between the past and the future is closed. Organizations that invest in this technology today will be better prepared for tomorrow's regulatory requirements, such as those required by the NIS2 directive in Europe or CISA guidelines in the United States.
In conclusion, the transition of legacy documents to OSCAL using an MCP pipeline represents a significant step forward in continuous compliance management. It does not completely eliminate human intervention, but concentrates it on the points of greatest value, where knowledge of the business is irreplaceable. Companies like Q2BSTUDIO offer the enterprise AI needed to implement these architectures, combining custom software development, artificial intelligence, and cybersecurity expertise. The path to truly agile compliance is already mapped out; All that remains is for organizations to decide to navigate it with the right tools and the support of partners who understand both the technology and the business domain.





