Interim Authority to Test
An Interim Authority to Test (IATT) is a temporary permission granted by an authorizing official that lets an organization test an information system in a real operational setting, sometimes with live data, before the system receives a full authorization to operate. It is a short-term, testing-focused authorization and should not be treated as approval for ongoing operational use. Once testing concludes or its conditions expire, the system generally still needs a separate authorization decision before it can operate in production.
An IATT is a temporary authorization issued by an authorizing official (AO), or a principal accrediting authority (PAA) in older DoD terminology, permitting an information system to be tested within a specified operational information environment for a defined timeframe and under stated conditions and constraints. Per available evidence, an IATT is intended to enable testing and evaluation of a system in an operational environment, which may include the use of live data, rather than to authorize routine operational use; applicable security controls are generally expected to be tested during this period. An IATT is distinct from an Authority to Operate (ATO): the IATT authorizes a bounded testing activity, whereas an ATO is the authorization decision permitting operational use of the system. Practitioners should not conflate an IATT with an ATO or with an Interim Approval/Authority to Operate (IATO), and should confirm the specific timeframe, conditions, data-handling constraints, and documentation or test-plan requirements against the governing authorization process and current authoritative sources, as these vary by agency, component (for example, specific DoD Service processes), and the applicable revision of governing guidance. Evidence for scope-specific procedural details in this entry is limited, and implementation, contractual, and legal specifics are out of scope and must be verified against official process documentation.
Why it matters
An Interim Authority to Test matters because it addresses a practical gap in the authorization lifecycle: some systems cannot be fully evaluated in a laboratory or isolated environment and must be tested in a realistic operational setting, sometimes with live data, before an authorizing official can make a confident authorization decision. The IATT provides a bounded, condition-based mechanism for that testing while keeping the activity distinct from routine operational use. Treating it as anything more than a temporary, testing-focused permission is a common and consequential mistake.
The most frequent expert-flagged error is conflating an IATT with an Authority to Operate (ATO). An IATT authorizes a specific testing activity for a defined timeframe and under stated conditions; it is not an authorization to place a system into ongoing production use. When testing concludes or the IATT's conditions expire, the system generally still requires a separate authorization decision before it can operate. Practitioners should also avoid confusing the IATT with an Interim Approval/Authority to Operate (IATO), which is a different concept. Because live data may be involved during IATT testing, the data-handling constraints and conditions attached to the authorization carry real risk-management weight and should be observed precisely.
Equally important, an IATT is not a shortcut around continuous monitoring or a substitute for demonstrating that security controls actually function. Available evidence indicates that applicable security controls are generally expected to be tested during the IATT period, which reinforces that the goal is evaluation and evidence-gathering rather than operational blessing. The specific timeframe, conditions, documentation, and test-plan requirements vary by agency and component and by the applicable revision of governing guidance, so readers should verify the details against their own authorization process rather than assuming a uniform standard.
Who it's relevant to
Inside IATT
Common questions
Answers to the questions practitioners most commonly ask about IATT.