Skip to main content
Category: Authorization & Accreditation

Certification and Accreditation (C&A)

Also known as: C&A, Certification & Accreditation
Simply put

Certification and Accreditation (C&A) is an older term for the formal process by which a government information system was evaluated against security requirements and then approved for operation by a responsible official. Certification generally referred to the technical evaluation of a system's security controls, while accreditation referred to the management decision to accept the associated risk and permit the system to operate. In most current federal and defense practice this terminology has been superseded by the Assessment and Authorization (A&A) process under the Risk Management Framework, and readers should verify the specific terminology and requirements applicable to their environment.

Formal definition

Certification and Accreditation (C&A) denotes the legacy two-part process distinguishing certification, the technical assessment of the extent to which a system's security controls are implemented correctly and operating as intended, from accreditation, the formal declaration by an authorizing official (historically a Designated Approving Authority or equivalent) accepting residual risk and granting authorization for the system to operate. The term is associated with predecessor processes such as DoD's DIACAP and civilian C&A guidance that generally preceded the transition to the NIST Risk Management Framework (RMF), under which the corresponding activities are now typically described as Assessment and Authorization (A&A). Practitioners should note that any resulting authorization is time-bound and subject to continuous monitoring rather than permanent, that certification (assessment) is distinct from accreditation (authorization), and that the precise process, roles, and control baselines depend on the governing publication and revision in force for the applicable system category, which must be confirmed against current authoritative sources.

Why it matters

Certification and Accreditation (C&A) matters because it represents the historical foundation of how government information systems were formally vetted and approved for operation, and its concepts continue to shape current practice even after the terminology changed. Understanding C&A helps practitioners interpret legacy documentation, older system authorization packages, and references in policies or contracts that predate the transition to the Risk Management Framework. Because many systems and organizations carry forward artifacts and language from the C&A era, being able to map those terms to their modern equivalents is essential for accurate compliance work.

Who it's relevant to

Authorizing Officials
Authorizing officials, and their historical counterparts such as Designated Approving Authorities, are the individuals who made or now make the formal risk-acceptance decision that permits a system to operate. Understanding the C&A lineage clarifies why accreditation (authorization) is a management decision distinct from the technical certification (assessment), and reinforces that any resulting authorization is time-bound and subject to continuous monitoring rather than permanent.
Information System Security Managers and Assessors
Those responsible for evaluating security controls should recognize that the certification component of C&A corresponds conceptually to the assessment activity in today's A&A process. This helps when reviewing legacy authorization packages or mapping older DIACAP-era artifacts to current Risk Management Framework requirements, while confirming the applicable control baselines and revisions in force.
Government Contractors
Contractors who encounter C&A terminology in older policies, contract language, or inherited system documentation need to interpret those references accurately and map them to current A&A and RMF requirements. Any obligations should be verified against the current authoritative process applicable to the specific system category and environment.
Compliance Officers and Auditors
Compliance professionals and auditors benefit from understanding C&A when reviewing historical records or reconciling legacy documentation with present-day frameworks. Recognizing that C&A has largely been superseded by Assessment and Authorization under the RMF helps avoid conflating outdated terminology with current binding requirements, which must be confirmed against current official sources.

Inside C&A

Certification
The comprehensive technical evaluation of a system's security controls, performed to determine the extent to which those controls are correctly implemented, operating as intended, and producing the desired outcome relative to the system's security requirements. Certification is an assessment activity and does not by itself grant permission to operate.
Accreditation
The formal management decision by a senior official to authorize operation of an information system and to explicitly accept the residual risk to organizational operations, assets, and individuals. Accreditation is the authorization step and is distinct from the technical certification that precedes it.
Accrediting or Authorizing Official
The senior official accountable for reviewing the certification results and rendering the accreditation decision. This role bears responsibility for accepting the residual risk associated with operating the system.
Security Controls Assessment
The examination and testing of the system's implemented safeguards that supports the certification determination, feeding evidence into the accreditation decision.
Residual Risk Acceptance
The documented acknowledgment of risks that remain after controls are implemented, which the authorizing official must weigh and formally accept as part of granting authorization.
Relationship to Successor Processes
C&A is a legacy term and process framework that has generally been superseded in federal and defense contexts by the Risk Management Framework (RMF) and its Assessment and Authorization (A&A) terminology. Readers should verify which process governs a given system against current authoritative guidance, as legacy processes such as DIACAP are no longer the applicable authority in most environments.

Common questions

Answers to the questions practitioners most commonly ask about C&A.

Is Certification and Accreditation (C&A) the same thing as the Risk Management Framework (RMF)?
No. Certification and Accreditation refers to the earlier process model associated with predecessor frameworks such as DIACAP for DoD systems and the NIST guidance that preceded the current RMF for federal systems. The Risk Management Framework, issued and maintained by NIST, superseded the traditional C&A model in most federal and defense contexts, replacing the two-step 'certification' and 'accreditation' construct with a broader lifecycle that includes categorize, select, implement, assess, authorize, and monitor steps. Treating C&A and RMF as interchangeable overlooks the fact that RMF emphasizes continuous monitoring and an ongoing risk-based authorization rather than a point-in-time certification. Readers should confirm which framework applies to their system against current official sources, as terminology and applicable authorities differ by community.
Does an accreditation decision or Authority to Operate (ATO) last indefinitely once granted?
No. An accreditation decision, or Authority to Operate, is time-bound and subject to conditions, including continuous monitoring of the system's security posture. It is generally granted for a defined period or under an ongoing authorization model and can be revised, suspended, or revoked if the risk picture changes materially. Assuming an ATO is permanent is a common and consequential mistake; the authorizing official's decision reflects the acceptable level of risk at a specific point in time and rests on the assumption that controls remain effective. Specific durations, renewal expectations, and continuous monitoring requirements vary by agency and framework revision and should be verified against the governing policy.
Who holds the authority to make the accreditation or authorization decision?
The authorization decision is generally reserved to a senior official designated as the authorizing official (historically the designated accrediting or approving authority in older C&A models). This official accepts risk on behalf of the organization and formally issues the authorization decision. The individuals or teams performing the assessment of controls are typically distinct from the official who authorizes, which reflects a separation between assessing security controls and accepting residual risk. The specific role titles, delegation rules, and appointment procedures vary by agency and framework, so confirm the applicable designations against current official guidance.
How does certification differ from accreditation in the traditional C&A model?
In the traditional model, certification generally refers to the technical evaluation and verification that a system's security controls are implemented correctly and operating as intended, producing evidence about the system's security posture. Accreditation refers to the management decision to accept the residual risk and formally authorize the system to operate based on that certification evidence. Confusing assessment with authorization is a frequent error: completing a certification or assessment does not by itself permit operation. The distinction persists conceptually in current frameworks, where assessment of controls is separate from the authorization decision. Verify the exact procedural steps against the framework applicable to your system.
What documentation typically supports a C&A or authorization decision?
Supporting documentation generally includes a system security plan describing the system and its implemented controls, results from the assessment of those controls, a plan of action and milestones addressing identified weaknesses, and a risk assessment informing the authorizing official's decision. The specific package contents, naming conventions, and required artifacts vary across frameworks, agency tailoring, and applicable revisions. This entry does not specify the exact document set for any particular system; readers should confirm required artifacts against the current authoritative guidance governing their environment.
Does completing C&A or obtaining an ATO mean a system is secure?
No. Authorization reflects a risk-based decision that residual risk is acceptable at a point in time under stated conditions, not a guarantee that the system is secure or free of vulnerabilities. Equating compliance or authorization with security is a common misconception; controls may degrade, threats evolve, and configurations drift after the decision is made. This is one reason continuous monitoring is emphasized in current frameworks. The scope, rigor, and residual risk accepted depend on the applicable framework, impact level, and agency tailoring, which should be verified against governing policy.

Common misconceptions

Certification and accreditation mean the same thing and can be used interchangeably.
They are distinct. Certification is the technical assessment of whether controls are implemented and operating correctly, while accreditation is the separate management decision to authorize operation and accept residual risk. Confusing the assessment with the authorization is a common expert-flagged error.
An accreditation decision is permanent once granted.
An authorization to operate is time-bound and subject to ongoing conditions such as continuous monitoring. It reflects an accepted risk posture at a point in time and can be reevaluated or withdrawn as conditions change.
C&A is still the current governing process for federal and DoD systems.
C&A is a legacy framework that has generally been replaced by the Risk Management Framework and Assessment and Authorization terminology in most federal and defense contexts. Practitioners should confirm the applicable process against current official sources rather than assume C&A remains in force.

Best practices

Confirm whether the applicable system is governed by legacy C&A or by the current Risk Management Framework and Assessment and Authorization process, and align documentation and terminology accordingly.
Keep the certification (technical assessment) and accreditation (management authorization) activities clearly separated in process and documentation, so that assessment evidence is distinguished from the risk-acceptance decision.
Ensure the authorizing or accrediting official is provided with complete certification results and a clear statement of residual risk before rendering an authorization decision.
Treat any authorization as time-bound and pair it with continuous monitoring so that changes in risk posture are detected and the authorization is reassessed as needed.
Document residual risk acceptance explicitly, including the rationale, so accountability for accepted risk is traceable to the responsible official.
Verify all controls, requirements, and process terminology against the current authoritative publications rather than relying on legacy references, since guidance and terminology evolve across revisions.