cATO – The New Frontier: The Dilemma (Part 1 of 5)

The ATO Bottleneck: Why Traditional Authorization Can’t Keep Pace

For decades, the Authorization to Operate (ATO) has served as the gatekeeper for federal information systems, requiring agencies to formally assess and accept the risk of operating a system before it is permitted for production use. Although this is a sound risk management practice, the traditional ATO process has become one of the most persistent bottlenecks in federal IT modernization. A single authorization package can take six months to over a year to complete, requiring extensive documentation, security control assessments, and sign-off from an Authorizing Official (AO) before a system is cleared to go live. For organizations trying to adopt DevSecOps practices and ship code continuously, this timeline is fundamentally incompatible with the pace of modern software delivery.

The Real Problem: A Snapshot in a Constantly Changing Environment

The deeper problem isn’t just speed; rather, it’s the point in time nature of the assessment itself. A traditional ATO captures a system’s security posture as a snapshot in time, reflecting the security and risk posture of the system at the moment of the AO’s signature. But modern software environments are not static. Code and dependencies change constantly, new vulnerabilities emerge and are patched or accepted as a Plan of Action & Milestone (POA&M), and the threat landscape shifts daily. Once granted, most ATOs are only reassessed on a periodic cycle, often every three years, meaning the “authorized” risk posture can drift significantly from the actual risk posture long before the next reauthorization. This ultimately results in security teams that are focused on managing the security control artifacts (the paperwork, checklists, and packages) rather than the actual security posture of the system since the entire model rewards passing a one-time gate over sustaining continuous vigilance.

Enter cATO: The OSD Memo That Redefined Authorization

To address these shortcomings, the Office of the Secretary of Defense (OSD) issued a memo introducing the concept of Continuous Authorization to Operate (cATO) as an evolution of the Risk Management Framework (RMF). It notes that the traditional implementation of the RMF has fallen short in continuously monitoring risk after an authorization is granted. The memo further advances the idea that real-time or near real-time security data analytics are now essential to keep pace with modern cyber threats. To operate effectively in contested environments, it directs the adoption of cATO as the mechanism for closing this gap.

The Three Pillars of cATO

The memo recognizes that systems rarely operate in isolation, but as part of a larger “system of systems,” and that cATO is meant to formalize and monitor the security connections across these interdependent systems. It calls for all security controls to feed into a system level dashboard so AO’s can view their full area of responsibility and make real time, risk informed authorization decisions. In effect, the memo shifts the Department’s authorization model from periodic, point in time approvals toward continuous, data driven risk management enabled by DevSecOps automation. To achieve cATO approval, the memo, in addition to further guidance from the Office of the Chief Information Officer (OCIO), establishes three core pillars required for a cATO: Secure Software Supply Chain (SSSC), Active Cyber Defense (ACD), and Continuous Monitoring (CONMON).

Coming Up in This Series

In Part 2, we’ll dig into the first of these pillars, the Secure Software Supply Chain (SSSC), and unpack how the cATO evaluation criteria translate the abstract goal of supply chain security into concrete requirements around SBOMs, DevSecOps platforms, and the people and processes that keep them running.

 

Here at Andrew Morgan we help organizations obtain the highest value from their human capital, organizational, and technical investments to lower costs and optimize how they work, with capabilities spanning business process improvement, systems engineering and integration, analytics and reporting, infrastructure modernization, regulatory risk/compliance, and security and information assurance. If you are looking for a partner to help navigate your organization or program through this new way of working, we would love to hear from and engage with you directly.