Authority to Operate
An Authority to Operate (ATO) is a formal decision by a senior official that approves an information system to operate because its security risks have been judged acceptable. It is not a permanent stamp of approval; it reflects a risk-based judgment at a point in time and is generally subject to ongoing monitoring. An ATO indicates that a system was authorized to run, which is distinct from simply passing a security assessment.
An Authority to Operate (ATO), also rendered as Authorization to Operate, is a management decision issued by a designated authorizing official that formally accepts the risk to organizational operations and assets, and grants approval for an information system to operate at a level of risk deemed acceptable. In NIST terminology, it is the outcome of the security authorization process and, per the CSRC glossary, represents one of the possible authorization decisions an authorizing official may render after assessment activities are completed. Practitioners should distinguish the ATO (an authorization decision made by the authorizing official) from the security assessment that informs it (typically performed by an assessor). An ATO is generally time-bound and, in most current implementations, conditioned on continuous monitoring rather than treated as a one-time or permanent approval; specific durations, conditions, and reauthorization triggers depend on the governing framework and agency tailoring. Implementations differ across federal civilian systems, DoD systems, and other environments, for example, a DoD ATO grants approval for a system to operate within a DoD environment, so readers should confirm the applicable authorizing authority, process, and current requirements against official sources.
Why it matters
An Authority to Operate represents the formal moment when a senior official accepts responsibility for the security risks of an information system and permits it to run. This distinction matters because an ATO is a management decision that accepts risk, not merely a technical checkmark confirming that controls were tested. A system can complete a thorough security assessment and still not be authorized to operate; the assessment informs the decision, but the authorizing official, not the assessor, renders the ATO. Treating these two activities as interchangeable is a common and consequential error, because it obscures where accountability for accepted risk actually resides.
Who it's relevant to
Inside ATO
Common questions
Answers to the questions practitioners most commonly ask about ATO.