Continuous Authorization
Continuous authorization is an approach to approving an information system to operate that relies on constant monitoring rather than a single point-in-time review. Instead of re-authorizing a system on a fixed schedule, the organization maintains ongoing awareness of security posture, vulnerabilities, and threats so that risk decisions can be made on a near-real-time basis. In some implementations, notably the U.S. Department of Defense's continuous Authorization to Operate (cATO), the traditional expiration date on the authorization may be removed, though the authorization generally remains revocable if conditions warrant.
Continuous authorization, often referred to as continuous Authorization to Operate (cATO), is an implementation of the NIST Risk Management Framework's ongoing authorization model in which authorization decisions are supported by continuous monitoring, ongoing assessment, and maintained awareness of information security, vulnerabilities, and threats. It is intended to support continuous delivery pipelines by shifting from periodic, static reauthorization toward a state of near-real-time risk determination. In the NIST RMF and in the DoD cATO model, robust continuous monitoring can support removal of the authorization's fixed expiration date; practitioners should note that the absence of an expiration date does not make an authorization permanent, as the authorizing official generally retains the ability to revoke authorization when the risk posture is no longer acceptable. The specific criteria, evidence requirements, and governance for achieving and sustaining a continuous authorization state vary by implementation and agency tailoring, and readers should verify requirements against the current authoritative NIST and DoD guidance applicable to their environment.
Why it matters
Traditional authorization treats the approval to operate a system as a milestone tied to a fixed point in time, with reauthorization occurring on a recurring schedule. That model can leave long gaps between assessments during which vulnerabilities, threats, and configuration changes accumulate unmonitored. Continuous authorization addresses this by maintaining ongoing awareness of information security, vulnerabilities, and threats so that risk management decisions rest on a near-real-time picture of the system's posture rather than a snapshot that ages between reviews.
This matters especially for organizations pursuing continuous delivery, where software changes frequently and a static, periodic reauthorization cycle becomes a bottleneck. The U.S. Department of Defense's continuous Authorization to Operate (cATO) is a specific implementation of the NIST Risk Management Framework's ongoing authorization model, designed to support faster and more secure delivery pipelines. Under the DoD cATO approach, a continuous authorization does not carry a fixed expiration date when robust continuous monitoring is in place.
A critical point that experts insist on: the removal of an expiration date does not make an authorization permanent. A continuous authorization generally remains revocable, and the authorizing official retains the ability to withdraw approval when the risk posture is no longer acceptable. Practitioners should also avoid conflating the specific criteria and governance for cATO across implementations, since evidence requirements and agency tailoring vary; readers should verify against the current authoritative NIST and DoD guidance applicable to their environment.
Who it's relevant to
Inside cATO
Common questions
Answers to the questions practitioners most commonly ask about cATO.