Skip to content
ActaCyber

Continuous ATO: moving from snapshot to ongoing authorization

Continuous ATO, often shortened to cATO, is an operating model in which an authorizing official's risk acceptance stays current through continuous monitoring and fresh evidence, rather than being revisited only at a fixed reauthorization date. A traditional authority to operate is a snapshot: accurate the day the AO signs it, and steadily less accurate as the environment changes underneath it for the next one, two, or three years. A continuous ATO replaces that slow decay with an ongoing stream of evidence, so the authorization reflects what the system actually looks like this week, not what it looked like at the last full reassessment.

What continuous ATO is

Continuous monitoring and continuous ATO are related but not the same thing. Continuous monitoring is the input: ongoing, automated collection of evidence about credential health, endpoint posture, and control effectiveness. A continuous ATO is the output, the authorization decision itself, built to rely on that ongoing evidence stream instead of a periodic manual reassessment. A program can run excellent continuous monitoring and still hold a traditional, fixed-cycle ATO if the authorizing official has not changed how the authorization itself is maintained.

The Department of Defense CIO's 2022 guidance on continuous ATO described three broad criteria a program generally needs to demonstrate: a robust, ongoing continuous monitoring capability; a demonstrated ability to detect and respond rapidly to emerging threats and vulnerabilities, sometimes described as active cyber defense; and adoption of an approved DevSecOps reference design with automated security testing built into the delivery pipeline rather than bolted on afterward. This guidance has continued to evolve since it was issued, so confirm the current criteria against the latest DoD CIO memo rather than treating any fixed list as permanent.

The practical distinction is this: an ATO is the decision, cATO is how that decision stays current afterward. A program does not skip the underlying authorization by pursuing continuous status; it changes how the authorization is maintained once it exists.

Who needs a continuous ATO

The formal cATO designation, as defined by DoD CIO guidance, applies most directly to a specific population, but the underlying operating model is relevant well beyond it.

  • Department of Defense programs, particularly software-intensive systems capable of continuous delivery, pursuing the formal cATO designation under DoD CIO criteria.
  • Civilian agencies leaning heavily on the NIST RMF's Monitor step to approximate ongoing authorization, even where the agency does not use the specific term cATO.
  • Cloud service providers and system owners more broadly who want to keep an existing FedRAMP or agency ATO current between formal reauthorization cycles, reducing the risk that evidence goes stale in the years between full reassessments.

A program does not need the DoD's formal cATO label to benefit from the same discipline: continuous evidence, tight change management, and rapid drift detection improve authorization currency regardless of which agency or which specific memo governs the program.

What a continuous ATO requires

Requirement areaWhat it means in practice
Continuous monitoringAutomated, near-real-time evidence collection rather than periodic manual scans run on a calendar
Automated evidence generationEvidence produced as a byproduct of normal operations, not assembled by hand after the fact
Change management disciplineEvery change to the authorization boundary tracked and assessed, not silently absorbed into the environment
Active cyber defenseDemonstrated ability to detect and respond quickly to emerging vulnerabilities and threats, not just log them
DevSecOps pipeline integrationSecurity testing gated into CI/CD delivery, not applied as a separate step after code ships

None of this replaces the underlying package described on the authority to operate page: the SSP, SAR, and POA&M still have to exist, and an AO still has to make an initial risk-acceptance decision. Continuous ATO changes how that decision stays current afterward; it is not a shortcut around making the decision in the first place.

Moving to a continuous ATO, step by step

  1. Establish a traditional ATO first: A program needs an underlying authorization decision in place before continuous status is meaningful; this follows the standard ATO path described elsewhere on this site.
  2. Build automated, continuous monitoring: Stand up ongoing tracking of credential health, endpoint posture, and control drift across the environment; commonly the longest step, often several months of tooling and process work.
  3. Demonstrate active cyber defense capability: Show a working ability to detect and respond quickly to emerging vulnerabilities, not just collect and store scan results.
  4. Adopt an approved DevSecOps reference design: Integrate automated security testing into the CI/CD pipeline so findings surface before deployment, not after.
  5. Present the case to the authorizing official: Make the argument that ongoing, automated evidence meaningfully replaces periodic manual reassessment for this specific system.
  6. AO grants continuous authorization status: The fixed reauthorization date is replaced with an ongoing review model rather than a single future expiration.
  7. Maintain the discipline indefinitely: Evidence keeps flowing, drift gets caught and remediated quickly, and the AO periodically reviews the program's health rather than re-running a full assessment from a standing start.

Is a continuous ATO cheaper than reauthorizing every three years?

The honest answer is: it depends on the time horizon. Building the automation, continuous monitoring, pipeline-gated testing, and drift detection a cATO requires is real up-front investment, commonly comparable in scale to a single traditional reauthorization effort, roughly $50,000 to $200,000 in tooling and process buildout for a program with limited existing automation, assuming internal engineering time is the largest share of that figure.

Where the economics change is afterward. A traditional program pays a large, concentrated cost every reauthorization cycle, assembling evidence from scratch roughly every three years. A cATO program's marginal annual cost is typically lower, since evidence accumulates continuously rather than being assembled in a single expensive push, though it does not eliminate assessor involvement entirely; an AO still expects periodic independent validation, not a purely self-reported dashboard.

ACTA is licensed per environment, and every engagement starts with a conversation. The buildout described above, continuous evidence, drift tracking, and automated refresh, is exactly what ACTA's continuous monitoring is built to automate rather than require a program to construct from separate tools stitched together.

Common failure points

Programs moving toward continuous ATO tend to fail in a specific, recurring set of ways.

  • Treating cATO as meaning no more assessments at all, when an AO still expects periodic independent validation behind the continuous evidence, not a purely self-reported dashboard.
  • Automating evidence collection for some controls while leaving others manual, so gaps hide behind the parts of the picture that look continuously current.
  • Confusing continuous monitoring, the input, with continuous ATO, the authorization outcome built on top of it, and assuming one implies the other automatically.
  • Standing up drift detection without a real remediation process behind it, so alerts accumulate unread instead of triggering action.
  • Assuming DoD cATO criteria transfer unchanged into a civilian agency context without confirming what that agency's own authorizing official actually expects.
  • Underinvesting in change management discipline, so the authorization boundary quietly drifts from what the continuous monitoring tooling is actually watching.

How ACTA automates continuous ATO

This is the framework ACTA's continuous monitoring capability was built around directly. ACTA tracks credential health, evidence freshness, endpoint posture, and drift from previously passing controls on an ongoing basis, the specific areas where an authorization quietly goes stale between formal reviews. A stale posture refreshes to current in two clicks rather than requiring a separate project every time evidence needs to be brought current.

That refresh is deterministic, not a fresh judgment call each time: ACTA runs on goRapide, BMD's deterministic causal engine, with no LLMs, no agents, and nothing probabilistic in the compliance path, so refreshing the same drifted control twice produces the identical evidence and the identical determination both times, with an inspectable causal chain an AO can trace behind each one, exactly the kind of consistency continuous authorization depends on.

The artifacts an AO reviews stay current automatically: the SSP and evidence binder reflect the live environment rather than a point-in-time snapshot, which is precisely the case a program needs to make when arguing that ongoing evidence should replace a fixed reauthorization date. ACTA's federal pack library, including FedRAMP, the NIST RMF, NIST 800-53, and FISMA, ships every pack with every license, so a program building toward continuous status is not paying separately for the monitoring capability on top of the underlying frameworks it authorizes against.

For programs doing this work in isolated or highly restricted environments, ACTA is a single hardened Docker image under 20 MB running on roughly 100 MB of RAM, fully air-gappable: the standard build phones home only for a license heartbeat, and the air-gapped build makes no network callback at all, so continuous evidence generation does not itself become a new channel evidence has to leave the boundary through.

Continuous ATO and adjacent frameworks

Continuous ATO is an evolution of, not a replacement for, an authority to operate: a program needs the underlying risk-acceptance decision before continuous status is meaningful. The NIST RMF's Monitor step already asks for exactly this kind of ongoing evidence in principle; a cATO formalizes that expectation and holds it to a higher, largely automated standard.

FedRAMP already includes continuous monitoring obligations after authorization, monthly scanning and annual assessments among them; a cATO-style approach is a natural extension of that existing ConMon discipline rather than a separate program layered on top of it.

See the full compliance framework library for how ongoing authorization connects to the rest of the federal and defense frameworks this corpus covers.

Frequently asked questions

How is a continuous ATO different from a traditional ATO?

A traditional ATO is reauthorized on a fixed cycle, commonly every three years, and its accuracy decays between reviews. A continuous ATO relies on ongoing, automated evidence to keep the authorization current continuously, replacing the fixed reassessment date with an ongoing review model.

What are the DoD's criteria for a continuous ATO?

DoD CIO guidance issued in 2022 described three broad criteria: a robust continuous monitoring capability, demonstrated active cyber defense against emerging threats, and adoption of an approved DevSecOps reference design with automated security testing. This guidance has continued to evolve, so confirm current specifics against the latest memo.

Does continuous ATO eliminate the need for reassessment?

No. An authorizing official still expects periodic independent validation behind the continuous evidence stream, not a purely self-reported dashboard. Continuous ATO changes how often and how manually that validation happens, not whether it happens at all.

What is ongoing authorization?

Ongoing authorization is another term for the same operating model a continuous ATO describes: an authorization maintained through continuous monitoring and fresh evidence rather than revisited only at a fixed reauthorization date.

Can a civilian agency pursue a continuous ATO?

The formal DoD cATO designation is specific to Department of Defense guidance, but civilian agencies can build the same underlying discipline, continuous monitoring, automated evidence, and tight change management, into how their own authorizing officials maintain authorization currency.

What is the two-click posture refresh?

It refers to ACTA's continuous monitoring capability: when tracked evidence, such as credential health or control drift, goes stale, refreshing it back to current state takes two clicks rather than a separate reassessment project.

How does drift get caught under a continuous ATO?

Continuous monitoring tracks credential health, endpoint posture, and control effectiveness against previously passing baselines on an ongoing basis, flagging drift as it occurs rather than waiting for the next scheduled reassessment to surface it.

Is continuous monitoring the same thing as a continuous ATO?

No. Continuous monitoring is the ongoing evidence collection itself. A continuous ATO is the authorization decision built to rely on that evidence stream instead of a periodic manual reassessment; a program can have one without the other.

What happens if evidence goes stale under a continuous ATO?

A stale posture is flagged by continuous monitoring and needs to be refreshed before the authorizing official can rely on it again. Under ACTA, that refresh takes two clicks; under a manual program, it typically means reopening the affected evidence by hand.

Request a quote

Related frameworks