Skip to main content
Category: Continuous Monitoring

Continuous Authorization

Also known as: cATO, Continuous Authorization to Operate, Continuous Authority to Operate, Ongoing Authorization
Simply put

Continuous authorization is an approach to approving an information system to operate that relies on constant monitoring rather than a single point-in-time review. Instead of re-authorizing a system on a fixed schedule, the organization maintains ongoing awareness of security posture, vulnerabilities, and threats so that risk decisions can be made on a near-real-time basis. In some implementations, notably the U.S. Department of Defense's continuous Authorization to Operate (cATO), the traditional expiration date on the authorization may be removed, though the authorization generally remains revocable if conditions warrant.

Formal definition

Continuous authorization, often referred to as continuous Authorization to Operate (cATO), is an implementation of the NIST Risk Management Framework's ongoing authorization model in which authorization decisions are supported by continuous monitoring, ongoing assessment, and maintained awareness of information security, vulnerabilities, and threats. It is intended to support continuous delivery pipelines by shifting from periodic, static reauthorization toward a state of near-real-time risk determination. In the NIST RMF and in the DoD cATO model, robust continuous monitoring can support removal of the authorization's fixed expiration date; practitioners should note that the absence of an expiration date does not make an authorization permanent, as the authorizing official generally retains the ability to revoke authorization when the risk posture is no longer acceptable. The specific criteria, evidence requirements, and governance for achieving and sustaining a continuous authorization state vary by implementation and agency tailoring, and readers should verify requirements against the current authoritative NIST and DoD guidance applicable to their environment.

Why it matters

Traditional authorization treats the approval to operate a system as a milestone tied to a fixed point in time, with reauthorization occurring on a recurring schedule. That model can leave long gaps between assessments during which vulnerabilities, threats, and configuration changes accumulate unmonitored. Continuous authorization addresses this by maintaining ongoing awareness of information security, vulnerabilities, and threats so that risk management decisions rest on a near-real-time picture of the system's posture rather than a snapshot that ages between reviews.

This matters especially for organizations pursuing continuous delivery, where software changes frequently and a static, periodic reauthorization cycle becomes a bottleneck. The U.S. Department of Defense's continuous Authorization to Operate (cATO) is a specific implementation of the NIST Risk Management Framework's ongoing authorization model, designed to support faster and more secure delivery pipelines. Under the DoD cATO approach, a continuous authorization does not carry a fixed expiration date when robust continuous monitoring is in place.

A critical point that experts insist on: the removal of an expiration date does not make an authorization permanent. A continuous authorization generally remains revocable, and the authorizing official retains the ability to withdraw approval when the risk posture is no longer acceptable. Practitioners should also avoid conflating the specific criteria and governance for cATO across implementations, since evidence requirements and agency tailoring vary; readers should verify against the current authoritative NIST and DoD guidance applicable to their environment.

Who it's relevant to

Authorizing Officials (AOs)
AOs make the risk-based decisions that underpin any authorization. Under continuous authorization, they rely on continuous monitoring data to make near-real-time risk determinations rather than periodic reviews. They should understand that removing a fixed expiration date does not remove their responsibility or authority, the authorization generally remains revocable when the risk posture becomes unacceptable.
Information System Security Managers and Security Teams
These teams are responsible for maintaining the ongoing awareness of information security, vulnerabilities, and threats that continuous authorization depends on. Sustaining a robust continuous monitoring capability is what supports the ongoing authorization state, and its adequacy directly affects whether an authorization can be maintained.
DoD Program Offices and DevSecOps Teams
For organizations pursuing continuous delivery within the Department of Defense, cATO is designed to enable faster and more secure delivery by moving away from static, periodic reauthorization. Teams should confirm the specific cATO criteria, evidence requirements, and governance against current DoD guidance, since these vary by implementation and tailoring.
Compliance Officers and Auditors
Those reviewing authorization status should recognize that a continuous authorization without an expiration date is not the same as a permanent authorization, and that continuous monitoring evidence is central to demonstrating a sustained, acceptable risk posture. They should verify requirements against the current authoritative NIST and DoD sources applicable to the environment being assessed.

Inside cATO

Ongoing Authorization Basis
Under NIST SP 800-37 Rev. 2, continuous (ongoing) authorization shifts the authorization decision from a point-in-time event to an ongoing, risk-based determination supported by a robust continuous monitoring program. When sufficient near-real-time information on security and privacy posture is available, the authorizing official may issue an ongoing authorization and, per the applicable revision of SP 800-37, the traditional fixed authorization expiration date may be removed rather than requiring periodic reauthorization on a fixed cycle. Readers should verify the specific conditions in the current authoritative text.
DoD Continuous Authorization to Operate (cATO)
A DoD-specific construct described in the DoD CIO continuous authorization to operate guidance. As documented in that memorandum, a cATO reflects a state in which real-time or near-real-time monitoring, an active cyber defense capability, and adoption of an approved DevSecOps reference design allow ongoing authorization. Per that guidance, cATOs do not carry an expiration date; however, they remain conditional and revocable by the authorizing official if the required conditions are not maintained. Confirm current DoD criteria and prerequisites against the governing memorandum.
Continuous Monitoring (ConMon) Program
The foundational capability that makes continuous authorization possible. It generally includes ongoing control effectiveness assessment, security-relevant information collection, vulnerability and configuration monitoring, and reporting to the authorizing official. The rigor and automation of ConMon typically determine whether an authorizing official can move from periodic reauthorization to ongoing authorization.
Authorizing Official (AO) Risk Determination
The authorizing official retains accountability for the ongoing risk-acceptance decision. Continuous authorization does not remove the AO from the process; instead, it changes the cadence and evidentiary basis of the decision, with the AO relying on continuous monitoring outputs to sustain, condition, or withdraw the authorization.
Revocability and Conditionality
Even where an authorization no longer carries a fixed expiration date, it is not unconditional or permanent. The authorization is contingent on continued satisfaction of monitoring, defense, and process requirements, and the AO can revoke or suspend it if the security or privacy posture degrades or required conditions lapse.
Scope and Applicability Boundaries
Continuous authorization terminology and criteria differ by community. NIST SP 800-37 Rev. 2 ongoing authorization applies broadly to federal systems under the RMF, while DoD cATO carries additional DoD-specific prerequisites. FedRAMP and civilian agency continuous monitoring expectations may differ again. Practitioners should confirm which authority governs their system rather than assuming cross-program equivalence.

Common questions

Answers to the questions practitioners most commonly ask about cATO.

Does continuous authorization mean the ATO becomes permanent and can never be revoked?
No. Under continuous or ongoing authorization, the traditional fixed authorization expiration date may be removed when robust continuous monitoring is in place, NIST SP 800-37 Rev. 2 permits this, and the DoD continuous ATO (cATO) approach specifies that a cATO does not carry an expiration date. However, removing the expiration date is not the same as making the authorization permanent. The authorization remains an ongoing risk-based decision that the authorizing official can suspend or revoke if the system's risk posture degrades, if continuous monitoring lapses, or if unacceptable risk emerges. Readers should verify the specific conditions in NIST SP 800-37 Rev. 2 and the applicable DoD cATO guidance.
Is continuous authorization the same as continuous compliance, meaning that if my system stays compliant it stays authorized?
No. Authorization and compliance are distinct concepts, and continuous authorization does not reduce to demonstrating continuous compliance. Continuous authorization generally rests on an ongoing, evidence-driven assessment of a system's actual security posture and residual risk through continuous monitoring, not merely on satisfying a checklist of controls at a point in time. A system can be nominally compliant and still carry unacceptable risk, and an authorizing official retains discretion over the risk-based authorization decision regardless of compliance status. Compliance is an input to, not a substitute for, the authorization decision.
What capabilities generally need to be in place before an organization can move from a traditional time-bound ATO to continuous authorization?
Implementations generally expect a mature, ongoing continuous monitoring capability rather than periodic reassessment. In the DoD cATO context, this typically includes the ability to demonstrate ongoing visibility and awareness of the system's security posture, active cyber defense, and adoption of an approved architecture aligned with DevSecOps practices, among other conditions. The specific prerequisites vary by authorizing body and evolve across guidance revisions, so readers should confirm current requirements against the applicable NIST SP 800-37 Rev. 2 guidance and any governing agency or DoD memoranda before assuming their program qualifies.
How does the role of the authorizing official change under continuous authorization?
The authorizing official continues to own the risk-based authorization decision, but the decision becomes an ongoing determination informed by continuous monitoring data rather than a discrete event tied to a reauthorization cycle. Instead of re-authorizing at a fixed interval, the authorizing official is generally expected to maintain ongoing awareness of the system's risk posture and to act, including suspending or revoking authorization, if monitoring reveals that risk has become unacceptable. This shifts emphasis toward sustained governance and near-real-time risk awareness. Specific responsibilities depend on the governing framework and agency implementation.
What kinds of monitoring evidence are typically expected to sustain a continuous authorization?
Continuous authorization generally depends on ongoing evidence of the system's security posture drawn from an active continuous monitoring program, for example, near-real-time or frequently refreshed information on control effectiveness, vulnerabilities, and the residual risk associated with the system. The intent is that authorization decisions are informed by current data rather than by a point-in-time assessment. The precise scope, frequency, and format of monitoring evidence vary by authorizing body and by applicable revision of the governing guidance, so organizations should confirm expectations against current authoritative sources before designing their monitoring approach.
Can continuous authorization be revoked, and what typically triggers that?
Yes. Even where the authorization no longer carries an expiration date, it remains revocable. An authorizing official can generally suspend or withdraw the authorization when the system's risk posture deteriorates to an unacceptable level, for instance, when continuous monitoring breaks down or ceases to provide adequate visibility, or when newly identified risk exceeds what the authorizing official is willing to accept. The removal of a fixed expiration date does not remove the authorizing official's ongoing authority and responsibility to reconsider the authorization. Specific triggers and procedures depend on the applicable framework and agency implementation.

Common misconceptions

Continuous authorization means the authorization is permanent and can never be lost.
Removing a fixed expiration date, as allowed under NIST SP 800-37 Rev. 2 ongoing authorization and required for DoD cATO, does not make an authorization permanent. It remains conditional on sustained continuous monitoring and other prerequisites, and the authorizing official can revoke or suspend it if those conditions are not maintained.
Every authorization under a continuous authorization model retains a time-bound expiration date and must be periodically reauthorized on a fixed schedule.
Under a mature ongoing authorization approach, the traditional fixed expiration date may be removed. NIST SP 800-37 Rev. 2 permits this when a robust continuous monitoring program supports the ongoing decision, and the DoD cATO guidance states that cATOs do not have an expiration date. The specific conditions should be verified against the applicable authoritative text.
Achieving continuous authorization means the system is fully secure and compliance work is finished.
Continuous authorization is a risk-management and monitoring posture, not a guarantee of security. It generally increases the ongoing effort required, since sustaining the authorization depends on continuously demonstrating control effectiveness and an active monitoring or defense capability.

Best practices

Confirm which authority governs your system before pursuing continuous authorization, since NIST SP 800-37 Rev. 2 ongoing authorization, DoD cATO, and civilian or FedRAMP continuous monitoring expectations carry different prerequisites and criteria.
Establish and mature a robust continuous monitoring program with near-real-time visibility into control effectiveness before seeking to remove a fixed authorization expiration date, because the ongoing decision depends on that evidentiary basis.
Treat the authorization as conditional and revocable at all times; maintain the monitoring, active defense, and process capabilities that justified it, and document how degradation would be detected and reported to the authorizing official.
Keep the authorizing official continuously informed through defined reporting so the ongoing risk determination is supported by current information rather than a periodic reassessment alone.
For DoD systems, verify current cATO prerequisites, including continuous monitoring, active cyber defense, and an approved DevSecOps reference design, directly against the governing DoD CIO memorandum, as criteria may evolve.
Verify specific conditions, cadence, and expiration-date handling against the current authoritative text of the applicable publication or memorandum rather than relying on assumptions carried over from legacy point-in-time ATO practices.