Authority to Use
An Authority to Use (ATU) is a formal decision by an agency official to allow that agency to use an information system, service, or application that has already been authorized by another party. Rather than performing a full authorization from scratch, the agency reviews and formally accepts an existing authorization so it can use the offering. This concept is commonly applied to cloud services, such as those handled through FedRAMP.
An Authority to Use (ATU) is an official management decision issued by an authorizing official to authorize the use of an information system, service, or application, as reflected in the NIST CSRC glossary definition of authorization to use. In practice, particularly within the FedRAMP context, an ATU functions as an agency-internal decision to formally accept and reuse an existing authorization for a cloud service offering rather than issuing an independent Authority to Operate (ATO). An ATU is distinct from an ATO: an ATO generally represents an authorizing official's own risk-based determination based on a review of a system's security posture, whereas an ATU generally leverages a prior authorization that the accepting agency reviews and accepts. Both are risk-based management decisions and, as authorizations, should not be treated as permanent; they remain subject to the terms of the underlying authorization and applicable continuous monitoring requirements. This entry does not address FedRAMP program mechanics, DoD-specific requirements, or the specific review obligations an agency must meet, which readers should confirm against current authoritative sources.
Why it matters
The Authority to Use (ATU) matters because it addresses one of the most persistent challenges in federal authorization work: avoiding duplicative, resource-intensive reviews of systems that another party has already authorized. When an agency can review and formally accept an existing authorization rather than issuing its own Authority to Operate (ATO) from scratch, it can adopt cloud services more efficiently. This is especially relevant in the FedRAMP context, where a cloud service offering may already carry an authorization that multiple agencies can leverage. Understanding the ATU concept helps authorizing officials, ISSMs, and compliance staff correctly frame what decision they are actually making and what responsibilities they retain.
A common and consequential mistake is treating an ATU as though it eliminates an agency's own risk responsibility. An ATU is still a risk-based management decision: the accepting agency reviews and formally accepts an existing authorization, and that acceptance carries obligations. FedRAMP guidance indicates that each agency issuing an ATO or ATU for a cloud offering has review responsibilities tied to the cloud service, so an ATU should not be understood as a rubber stamp that transfers all accountability elsewhere. Officials should also avoid conflating an ATU with an ATO, an ATO generally reflects the authorizing official's own determination based on a review of the system's security posture, while an ATU generally leverages a prior authorization that the accepting agency reviews and accepts.
Equally important, an ATU should not be treated as permanent. Like an ATO, it is a time-bound, risk-based decision that remains subject to the terms of the underlying authorization and to applicable continuous monitoring requirements. If the underlying authorization changes or lapses, the basis for the ATU can be affected. Officials who assume an ATU stands indefinitely, independent of the authorization it relies upon, risk operating on an outdated understanding of a system's risk posture.
Who it's relevant to
Inside ATU
Common questions
Answers to the questions practitioners most commonly ask about ATU.