Skip to main content
Category: Authorization & Accreditation

Authority to Operate

Also known as: ATO, Authorization to Operate, Security Authorization (to Operate)
Simply put

An Authority to Operate (ATO) is a formal decision by a senior official that approves an information system to operate because its security risks have been judged acceptable. It is not a permanent stamp of approval; it reflects a risk-based judgment at a point in time and is generally subject to ongoing monitoring. An ATO indicates that a system was authorized to run, which is distinct from simply passing a security assessment.

Formal definition

An Authority to Operate (ATO), also rendered as Authorization to Operate, is a management decision issued by a designated authorizing official that formally accepts the risk to organizational operations and assets, and grants approval for an information system to operate at a level of risk deemed acceptable. In NIST terminology, it is the outcome of the security authorization process and, per the CSRC glossary, represents one of the possible authorization decisions an authorizing official may render after assessment activities are completed. Practitioners should distinguish the ATO (an authorization decision made by the authorizing official) from the security assessment that informs it (typically performed by an assessor). An ATO is generally time-bound and, in most current implementations, conditioned on continuous monitoring rather than treated as a one-time or permanent approval; specific durations, conditions, and reauthorization triggers depend on the governing framework and agency tailoring. Implementations differ across federal civilian systems, DoD systems, and other environments, for example, a DoD ATO grants approval for a system to operate within a DoD environment, so readers should confirm the applicable authorizing authority, process, and current requirements against official sources.

Why it matters

An Authority to Operate represents the formal moment when a senior official accepts responsibility for the security risks of an information system and permits it to run. This distinction matters because an ATO is a management decision that accepts risk, not merely a technical checkmark confirming that controls were tested. A system can complete a thorough security assessment and still not be authorized to operate; the assessment informs the decision, but the authorizing official, not the assessor, renders the ATO. Treating these two activities as interchangeable is a common and consequential error, because it obscures where accountability for accepted risk actually resides.

Who it's relevant to

Authorizing Officials
As the senior officials who render the ATO decision, authorizing officials formally accept the risk to organizational operations and assets on behalf of the organization. They rely on the results of the security assessment to make an informed, risk-based judgment, and they retain accountability for that decision over the life of the authorization, including through continuous monitoring.
Information System Security Managers and Security Officers
These practitioners prepare and maintain the documentation and control implementations that support an authorization decision. They must distinguish between the assessment that informs the ATO and the authorization decision itself, and they are typically responsible for sustaining the continuous monitoring on which an ATO is generally conditioned.
Security Assessors
Assessors evaluate whether a system's controls are implemented and operating as intended and provide the results that inform the authorizing official's decision. It is important that assessors and their stakeholders recognize that performing an assessment is distinct from granting an ATO; the assessor informs the decision but does not render it.
Government Contractors and System Owners
Contractors and system owners seeking to operate systems within federal or DoD environments must understand that authorization is required before operation, that an authorization is generally time-bound, and that an ATO obtained in one environment does not automatically satisfy the requirements of another. For example, a DoD ATO grants approval to operate specifically within a DoD environment, and readers should confirm the applicable process for their context.
Auditors and Compliance Officers
Auditors and compliance officers should verify not only that a system holds a current authorization but that the conditions attached to it, including any continuous monitoring obligations and reauthorization triggers, are being met. They should also guard against conflating compliance with risk acceptance and against treating an ATO as permanent rather than as a point-in-time decision.

Inside ATO

Authorization Decision
A formal, risk-based decision issued by an Authorizing Official (AO) that permits an information system to operate. Under the NIST Risk Management Framework (RMF), this decision follows the Authorize step and is based on the AO's acceptance of residual risk to organizational operations, assets, and individuals.
Authorizing Official (AO)
The senior official or executive with the authority to formally assume responsibility for operating a system at an acceptable level of risk. The AO signs the authorization decision and accepts accountability for the associated residual risk.
Authorization Package
The body of evidence supporting the authorization decision. In most RMF implementations this generally includes the System Security Plan (SSP), the Security Assessment Report (SAR), and the Plan of Action and Milestones (POA&M); readers should verify current package content requirements against applicable official guidance and agency tailoring.
Defined Authorization Period / Time Bound
An ATO is time-bound rather than permanent. It is typically granted for a specified period or subject to reauthorization conditions, and its continued validity depends on maintaining the security posture on which the decision was based. Specific durations vary by agency policy and revision, so confirm against current authoritative text.
Continuous Monitoring Obligation
An ATO carries an ongoing responsibility to monitor the security state of the system, report changes, and maintain the conditions of the authorization. Ongoing authorization approaches may rely on continuous monitoring in place of periodic full reauthorization, depending on agency implementation.
Residual Risk Acceptance
The ATO reflects the AO's explicit acceptance of the risk remaining after security controls are implemented and assessed. It documents that known weaknesses (often tracked in the POA&M) have been considered and accepted or scheduled for remediation.

Common questions

Answers to the questions practitioners most commonly ask about ATO.

Once we receive an ATO, is our system authorized permanently?
No. An ATO is time-bound and conditional, not permanent. It is issued by an authorizing official (AO) for a defined period and remains contingent on the system maintaining its security posture through continuous monitoring. Changes to the system, its environment, or its risk profile can require reassessment, and the authorization can be revoked or allowed to expire. Some organizations use ongoing authorization approaches tied to continuous monitoring in place of a fixed expiration, but even those depend on sustained adherence to monitoring requirements. Verify the specific duration and conditions against your AO's authorization decision and applicable agency policy.
If our system has an ATO, does that mean it is secure and compliant?
Not necessarily. An ATO reflects an authorizing official's risk-based decision to accept the residual risk of operating a system, based on an assessment at a point in time. It is a formal acceptance of risk, not a guarantee that the system is secure or free of vulnerabilities. Compliance with a control baseline and actual security are related but distinct: an AO may authorize a system with known weaknesses documented in a plan of action and milestones (POA&M). Treating an ATO as proof of security can lead to complacency in ongoing monitoring and remediation.
Who issues an ATO, and what role does the assessment play in that decision?
In systems following the NIST Risk Management Framework (RMF), the authorizing official (AO), a senior official with the authority to accept risk on behalf of the organization, issues the ATO. This is distinct from the assessment itself: an assessor evaluates whether controls are implemented correctly and operating as intended, and documents findings, but does not grant authorization. The AO reviews the assessment results, the security plan, and residual risk before rendering the authorization decision. Confusing assessment with authorization is a common error; the two are separate steps performed by different roles. Confirm the specific roles and delegations under your organization's governing policy.
What generally happens to an ATO when we make a significant change to the system?
Significant changes to a system or its operating environment can affect its risk posture and typically trigger reassessment of the affected controls, and in some cases a new authorization decision by the AO. What constitutes a 'significant change' is determined by the authorizing official and applicable agency policy, and it is generally addressed through configuration management and the continuous monitoring strategy. Minor changes may be handled within existing continuous monitoring processes. Consult your organization's change management and continuous monitoring procedures, as thresholds and required actions vary by agency and system.
Does a FedRAMP authorization satisfy an ATO requirement for a DoD system?
Not automatically. FedRAMP authorization and a DoD authorization decision are distinct, and a FedRAMP authorization does not by itself satisfy DoD requirements. DoD systems generally follow the RMF with additional DoD-specific requirements and impact-level considerations, and a DoD authorizing official must make the risk acceptance decision for the system as deployed in its DoD context. A FedRAMP authorization may support and streamline that process, but reliance on it should be confirmed against current DoD policy and the specific AO's requirements. Verify against the applicable authoritative guidance rather than assuming reciprocity.
What role does continuous monitoring play after an ATO is granted?
Continuous monitoring is central to maintaining an ATO. After authorization, the system is generally subject to an ongoing monitoring strategy covering control effectiveness, security-relevant changes, vulnerability status, and reporting to the authorizing official. This ongoing visibility informs whether the AO's original acceptance of risk remains valid. Failure to sustain continuous monitoring can undermine the basis of the authorization. The specific frequency, metrics, and reporting expectations are defined by organizational and agency policy, so confirm the applicable continuous monitoring requirements for your system.

Common misconceptions

An ATO is a permanent approval that, once granted, allows a system to operate indefinitely.
An ATO is time-bound and conditional. It is subject to continuous monitoring and can be revoked or require reauthorization if the risk posture changes. Continued operation depends on maintaining the conditions on which the authorization was based.
Having an ATO means the system is secure.
Authorization reflects an Authorizing Official's acceptance of residual risk at a point in time, not a guarantee of security. Compliance and authorization are distinct from actual security, and an ATO may be issued while known weaknesses remain documented in a POA&M.
Completing a security assessment is the same as receiving an ATO.
Assessment and authorization are separate activities. The assessment produces evidence (such as a Security Assessment Report) about control effectiveness, but only the Authorizing Official's formal authorization decision constitutes the ATO.

Best practices

Treat the ATO as time-bound: track the authorization period and continuous monitoring obligations, and plan for reauthorization or ongoing authorization well before expiration.
Maintain a current, complete authorization package (such as the SSP, SAR, and POA&M) so that the evidence supporting the AO's risk-based decision stays accurate as the system changes.
Actively manage the POA&M by tracking accepted residual risks and remediation milestones, and report significant changes in the risk posture to the Authorizing Official promptly.
Do not equate the ATO with security; pair the authorization with sustained monitoring, control assessment, and remediation to keep the actual security state aligned with the accepted risk.
Distinguish assessment from authorization in your workflow, and confirm that only the designated Authorizing Official issues the formal authorization decision.
Verify authorization scope and requirements against current, applicable official guidance and agency tailoring, since baselines, authorization periods, and package contents vary across revisions and organizations.