Online Certificate Status Protocol (OCSP) is a protocol used for validation (ie revocation status) of X509 certificates in a PKI system as a real-time alternative to CRLs.
OCSP is a method for checking for revoked certificates in a more scalable manner than CRLs, by querying an OCSP responder for the status of a given individual certificate, rather than having to obtain a large CRL.
OCSP is covered by the following RFCs:
More information on OCSP can be found in its Wikipedia article.