Ongoing Authorization
Ongoing Authorization is an approach in which a system's security is continuously evaluated rather than reassessed only at fixed intervals, so that authorization decisions rest on current information about vulnerabilities and threats. Instead of relying on a one-time review, the organization maintains ongoing awareness of the system's security posture to support timely, risk-based decisions. It should not be understood as a permanent approval; authorization remains contingent on continued monitoring.
Ongoing Authorization refers to an authorization state maintained through continuous monitoring and ongoing assessment activities, in which security controls are evaluated on an ongoing basis to preserve awareness of information security, vulnerabilities, and threats in support of organizational risk management decisions. In the NIST RMF context, it is associated with maintaining an authorization decision over time rather than reauthorizing solely on a periodic cycle, and it underpins concepts such as continuous ATO (cATO), which per the evidence generally requires continuous control monitoring, active cyber defense, and DevSecOps adoption. In the FedRAMP context, ongoing authorization is supported by continuous monitoring processes: authorizing agencies remain responsible for monitoring the systems they authorize, and FedRAMP Authorized cloud service providers supply ongoing reporting (for example, an Ongoing Authorization Report) to agency customers. This entry describes the general concept and does not cover agency-specific tailoring, contractual specifics, or the precise reporting cadence, control sets, or version requirements, which vary by program and revision and should be verified against current authoritative sources.
Why it matters
Ongoing Authorization addresses a longstanding weakness in point-in-time authorization models: a system assessed and authorized at a fixed moment can drift out of compliance and accumulate unaddressed vulnerabilities before the next scheduled reassessment. By maintaining ongoing awareness of information security, vulnerabilities, and threats, an organization grounds its authorization decisions in current data rather than a snapshot that may be months or years old. This shift matters most for authorizing officials, who bear the risk-acceptance responsibility for a system and benefit from continuous visibility into whether the security posture that justified the original decision still holds.
Who it's relevant to
Inside OA
Common questions
Answers to the questions practitioners most commonly ask about OA.