Certification and Accreditation (C&A)
Certification and Accreditation (C&A) is an older term for the formal process by which a government information system was evaluated against security requirements and then approved for operation by a responsible official. Certification generally referred to the technical evaluation of a system's security controls, while accreditation referred to the management decision to accept the associated risk and permit the system to operate. In most current federal and defense practice this terminology has been superseded by the Assessment and Authorization (A&A) process under the Risk Management Framework, and readers should verify the specific terminology and requirements applicable to their environment.
Certification and Accreditation (C&A) denotes the legacy two-part process distinguishing certification, the technical assessment of the extent to which a system's security controls are implemented correctly and operating as intended, from accreditation, the formal declaration by an authorizing official (historically a Designated Approving Authority or equivalent) accepting residual risk and granting authorization for the system to operate. The term is associated with predecessor processes such as DoD's DIACAP and civilian C&A guidance that generally preceded the transition to the NIST Risk Management Framework (RMF), under which the corresponding activities are now typically described as Assessment and Authorization (A&A). Practitioners should note that any resulting authorization is time-bound and subject to continuous monitoring rather than permanent, that certification (assessment) is distinct from accreditation (authorization), and that the precise process, roles, and control baselines depend on the governing publication and revision in force for the applicable system category, which must be confirmed against current authoritative sources.
Why it matters
Certification and Accreditation (C&A) matters because it represents the historical foundation of how government information systems were formally vetted and approved for operation, and its concepts continue to shape current practice even after the terminology changed. Understanding C&A helps practitioners interpret legacy documentation, older system authorization packages, and references in policies or contracts that predate the transition to the Risk Management Framework. Because many systems and organizations carry forward artifacts and language from the C&A era, being able to map those terms to their modern equivalents is essential for accurate compliance work.
Who it's relevant to
Inside C&A
Common questions
Answers to the questions practitioners most commonly ask about C&A.