cATO – The New Frontier: Secure Software Supply Chain (SSSC) (Part 2 of 5)
Recap: The Three Pillars of cATO
In Part 1, we traced the origins of Continuous Authorization to Operate (cATO), from the bottlenecks of the traditional ATO process to the OSD memo that established cATO as an evolution of the Risk Management Framework. That memo shifted the Department’s authorization model away from point-in-time approvals and toward continuous, data-driven risk management, anchored by three core pillars: Secure Software Supply Chain (SSSC), Active Cyber Defense (ACD), and Continuous Monitoring (CONMON). In this installment, we turn to the first of these pillars, SSSC, and examine what the Department actually requires organizations to demonstrate.
What SSSC Requires: Three Core Focus Areas
The SSSC requirements revolve around three primary focus areas: 1) Conducting software composition analysis (SCA) and generating SBOMs to catch known vulnerabilities in every release, 2) Continuously monitoring the software factory’s own security controls in addition to the authorized system’s controls, and 3) Integrating supply-chain risk management practices drawn from standards like NIST SP 800-218 Secure Software Development Framework (SSDF), NIST SP 800-161 Cybersecurity Supply Chain Risk Management (C-SCRM), and OWASP guidance.
The DevSecOps Platform (DSOP): The Linchpin of SSSC
The evaluation criteria for SSSC are organized around three core competencies: the DevSecOps Platform (DSOP), the processes for using it, and the people who operate it. The linchpin that drives the SSSC is the implementation of an approved DSOP. This area requires the organization to demonstrate that it is using a DSOP built on an approved DoD Enterprise DevSecOps Reference Design, identifying which specific reference design the platform adheres to.
Process Requirements: Control Gates and Guardrail Analysis
Evaluating the processes for using the DSOP focus on the repeatable processes that govern how software moves through the pipeline. It requires reliance on Infrastructure as Code (IaC) and Configuration as Code (CaC) to eliminate cloud or environment drift between development, test, and production. Central to this is control gate and guardrail analysis where the organization must document each control gate in the pipeline, define what conditions cause it to open or close, specify what triggers an alert and how personnel should respond, and demonstrate the control gates functioning using either live dashboards (preferred) or screenshots as evidence. Most importantly, these guardrail analysis processes must specify for each guardrail the concrete steps that are followed when an application or artifact falls outside the established risk tolerance.
People Requirements: Training, Roles, and Workforce Qualifications
Finally, evaluating the people using the DSOP assesses whether the workforce is properly trained, organized, vetted, and meets cybersecurity personnel qualifications under DoD 8140.03. It requires providing an organization chart showing DevSecOps team roles, verifying that each team member has training appropriate to their role, and demonstrating proper separation of duties and least-privilege access. Teams must periodically run tabletop exercises covering incident response, control-gate triggers, security alerts, and elevated-privilege requests, with after-action reports produced. The organization must also document its DevSecOps education and certification process showing that team members are specifically trained on the adopted DoD Reference Design. This includes training on the security automation tools in use, CI/CD control gates, risk tolerances, root-cause analysis practices for security findings, POA&M documentation approach and dashboard implementation.
Coming Up in This Series
With SSSC establishing the foundation for trustworthy software before it ever reaches production, the Department’s authorization model still needs a way to respond to threats once a system is live. In Part 3 we turn to Active Cyber Defense (ACD), the pillar that shifts the focus from securing what’s built to actively detecting, responding to, and recovering from the threats that emerge after deployment using real-time detection, incident response, and continuous vulnerability management practices.
Here at Andrew Morgan we help organizations obtain the highest value from their human capital, organizational, and technical investments to lower costs and optimize how they work, with capabilities spanning business process improvement, systems engineering and integration, analytics and reporting, infrastructure modernization, regulatory risk/compliance, and security and information assurance. If you are looking for a partner to help navigate your organization or program through this new way of working, we would love to hear from and engage with you directly.


