OASIS (Organisation for the Advancement of Structured Information Standards) is an international, not-for-profit standards development body that produces open standards for information technology, with particular strengths in web services, security, content formats, electronic business, and emergency management. Founded in 1993, OASIS operates through technical committees that develop specifications via an open, consensus-based process, producing both OASIS Standards and publicly available specifications that are frequently adopted as ISO/IEC standards. Prominent OASIS standards include MQTT for IoT messaging, SAML for federated identity, XACML for access control, OData for REST-based data access, and the OpenDocument Format. OASIS also co-publishes standards with other bodies including the W3C and ISO.

Content

  • OASIS was founded in 1993 as SGML Open, a consortium focused on the adoption of the Standard Generalised Markup Language. As the internet and web services era unfolded, the organisation broadened its scope to encompass the full range of structured information standards needed for B2B integration, enterprise messaging, and eventually IoT and cybersecurity. Its renaming to OASIS in 1998 reflected this expanded mandate. Today the organisation hosts over 70 active technical committees covering domains from legal XML to digital publishing to quantum computing.
  • The OASIS process is distinguished by its accessibility and its explicit route from industry specification to formal international standard. Technical committees are open to any individual or organisation willing to participate, reducing the capture risk associated with closed standards bodies. Approved OASIS Standards can be submitted for adoption as ISO/IEC International Standards through PAS (Publicly Available Specification) transposition, giving them global legal and regulatory recognition. This pathway has been used successfully for the OpenDocument Format (ISO/IEC 26300) and MQTT (ISO/IEC 20922).
  • MQTT, originally developed for satellite pipeline telemetry, became the dominant IoT messaging protocol following its standardisation as an OASIS Standard. Its lightweight publish-subscribe model, designed for constrained devices and unreliable networks, is now embedded in billions of IoT endpoints across industrial automation, smart buildings, and connected vehicles. The OASIS MQTT technical committee maintains the specification and its extensions for enhanced authentication and message expiry.
  • OASIS security standards form a substantial portion of enterprise identity infrastructure. SAML (Security Assertion Markup Language) enables browser-based single sign-on across organisational boundaries and remains the dominant protocol for enterprise federation despite the emergence of OAuth 2.0 and OpenID Connect. XACML (eXtensible Access Control Markup Language) provides a policy-based authorisation framework that separates access control policy from application code. These standards, though mature, continue to be actively deployed and extended in cloud and hybrid enterprise environments.