Authorization to Operate (ATO): Why it is falling behind federal programs in 2026

An Authorization to Operate (ATO) — the federal government’s standard cybersecurity authorization — is a point-in-time decision. A system is assessed, an Authorizing Official (AO) formally accepts the risk and the program is cleared to operate for a period the AO defines. Three years is customary, but it has not been required since OMB Memorandum M-14-04 and the 2016 revision of OMB Circular A-130 replaced the fixed reauthorization cycle with ongoing authorization driven by continuous monitoring. The three-year habit outlived the three-year rule. The AO sets both the duration of the authorization and the conditions under which it remains valid. 

An authorized system is not left unwatched in the meantime. Continuous monitoring begins the moment an ATO is issued, and annual assessments, change requests and routine patching continue throughout. The strain is more specific: the formal risk-acceptance decision is revisited periodically, while the system it covers — its code, its configurations and the threats against it — changes daily. 

What is an Authorization to Operate? 

An ATO is the formal, risk-based decision that permits a federal information system to operate on government networks. Grounded in the Federal Information Security Modernization Act (FISMA) and executed through the RMF published by the National Institute of Standards and Technology (NIST), the ATO places accountability with a single senior leader: the Authorizing Official. NIST Special Publication 800-37 defines the authorization as “the official management decision given by a senior federal official to authorize operation of an information system and to explicitly accept the risk to agency operations.” In other words, an ATO is not a paperwork exercise — it is an executive accepting risk on behalf of the agency, based on the evidence in front of them. That same executive decides how long the acceptance stands and what conditions keep it in force. 

Two properties of the RMF matter here, because both are routinely misread: 

  • It is iterative. When a change affects a system’s risk posture, the process loops back until the AO accepts that change and the system returns to Monitor. Authorization was never meant to be a one-time event. 
  • The Monitor step was built to carry an authorization, not merely to bridge the gap between two of them. Regular monitoring keeps the system in compliance with the security requirements the AO holds it to, allows the ATO to be updated based on approved changes and enables intervention if the system exceeds the AO’s risk tolerance. There is an implied “maintain” built into Monitor — the framework expects the system to be kept current between authorization decisions. 

In fact, the RMF was designed from the start to support an open-ended authorization — what we now call cATO.  

Policy is already moving. On September 24, 2025, the Defense Department introduced the Cybersecurity Risk Management Construct (CSRMC), citing static checklists and snapshot-in-time assessments; continuous monitoring and ATO is one of its ten strategic tenets, and cATO the intended end state. We’ll unpack what that means for programs in Part 2. 

What is Continuous Authorization to Operate (cATO)? 

Continuous Authorization to Operate — the continuous ATO, or cATO — is an ongoing risk management model that replaces periodic reauthorization with real-time security visibility. Instead of relitigating a system’s risk posture on a fixed schedule, the AO maintains continuous oversight, using live monitoring data to authorize changes as they occur. Authorization stops being a static event and becomes a continuous state of operational readiness. Critically, cATO is not a departure from the RMF — it is the RMF’s Monitor step operating at full fidelity, giving the AO the evidence to leave the authorization open-ended. 

Coming in Part 2 

In Part 2 of this series, we’ll break down what a continuous ATO actually requires — the Department of War’s three mandatory competencies, how cATO differs from a traditional ATO across every dimension that matters, which programs it’s designed for and the question that ultimately decides everything: How do you give your AO the confidence to grant one? 

More from IPKeys

Want IPKeys insights and news delivered directly to your email?

We'll notify you when new content is published at the email below (and you can opt-out any time)

Thank you! Your submission has been received!

We will never share your information with any third-parties without your permission, nor will we ever spam you. We take privacy very seriously and you can read our full privacy policy here.