Skip to main content
Category: Continuous Monitoring

Ongoing Authorization

Also known as: OA, Ongoing Assessment and Authorization, Ongoing Agency Authorization
Simply put

Ongoing Authorization is an approach in which a system's security is continuously evaluated rather than reassessed only at fixed intervals, so that authorization decisions rest on current information about vulnerabilities and threats. Instead of relying on a one-time review, the organization maintains ongoing awareness of the system's security posture to support timely, risk-based decisions. It should not be understood as a permanent approval; authorization remains contingent on continued monitoring.

Formal definition

Ongoing Authorization refers to an authorization state maintained through continuous monitoring and ongoing assessment activities, in which security controls are evaluated on an ongoing basis to preserve awareness of information security, vulnerabilities, and threats in support of organizational risk management decisions. In the NIST RMF context, it is associated with maintaining an authorization decision over time rather than reauthorizing solely on a periodic cycle, and it underpins concepts such as continuous ATO (cATO), which per the evidence generally requires continuous control monitoring, active cyber defense, and DevSecOps adoption. In the FedRAMP context, ongoing authorization is supported by continuous monitoring processes: authorizing agencies remain responsible for monitoring the systems they authorize, and FedRAMP Authorized cloud service providers supply ongoing reporting (for example, an Ongoing Authorization Report) to agency customers. This entry describes the general concept and does not cover agency-specific tailoring, contractual specifics, or the precise reporting cadence, control sets, or version requirements, which vary by program and revision and should be verified against current authoritative sources.

Why it matters

Ongoing Authorization addresses a longstanding weakness in point-in-time authorization models: a system assessed and authorized at a fixed moment can drift out of compliance and accumulate unaddressed vulnerabilities before the next scheduled reassessment. By maintaining ongoing awareness of information security, vulnerabilities, and threats, an organization grounds its authorization decisions in current data rather than a snapshot that may be months or years old. This shift matters most for authorizing officials, who bear the risk-acceptance responsibility for a system and benefit from continuous visibility into whether the security posture that justified the original decision still holds.

Who it's relevant to

Authorizing Officials
Authorizing officials rely on continuous monitoring data to make timely, risk-based decisions and to maintain an authorization over time rather than treating it as a permanent approval. Ongoing Authorization supports keeping awareness of vulnerabilities and threats current, but the authorization remains contingent on that continued monitoring, it is not a one-time sign-off, and the responsibility for accepting residual risk does not lapse between assessments.
Federal Agencies Consuming Cloud Services
In the FedRAMP context, agencies remain responsible for monitoring the federal information systems they authorize, including FedRAMP Authorized cloud services. Agency personnel should understand that FedRAMP authorization does not remove the agency's own continuous monitoring obligations, and that these obligations are distinct from any DoD-specific requirements a system may also be subject to.
Cloud Service Providers
FedRAMP Authorized cloud service providers supply ongoing reporting to agency customers, for example, an Ongoing Authorization Report, aligned to program requirements. Providers should confirm the applicable reporting cadence and content against current FedRAMP guidance, since these specifics vary by program and revision and are not fixed by this general description.
DoD Programs Pursuing Continuous ATO (cATO)
For DoD programs, Ongoing Authorization under the RMF is the foundation for a continuous ATO, which per the evidence generally requires continuous control monitoring, active cyber defense, and DevSecOps adoption. Teams pursuing cATO should treat these as capability prerequisites rather than paperwork milestones, and should verify current DoD-specific criteria, as agency tailoring and evolving guidance affect what qualifies.
Continuous Monitoring and ISSM Staff
Information system security managers and continuous monitoring teams operate the ongoing assessment activities that keep an authorization valid, constantly evaluating and testing controls to spot vulnerabilities so risk-based decisions can be made quickly. These staff should recognize that assessment activity informs, but is distinct from, the authorization decision itself, and that compliance monitoring is not the same as security assurance.

Inside OA

Continuous Monitoring Foundation
Ongoing authorization generally rests on a continuous monitoring program that tracks the security posture of an information system over time, including automated and manual assessment of control effectiveness, vulnerability status, and configuration changes rather than relying on a single point-in-time snapshot.
Risk-Based Decision Cadence
In most implementations, the authorizing official (AO) makes recurring, risk-informed decisions about whether a system may continue to operate, based on the current state of risk reflected in continuous monitoring data rather than a fixed reauthorization interval.
Relationship to the RMF
Ongoing authorization is generally treated as a mature outcome of the Risk Management Framework's continuous monitoring step, as described in NIST guidance such as the SP 800-37 RMF process; readers should verify the applicable revision, since RMF steps and terminology are periodically updated.
Time-Bound and Revocable Nature
Even under ongoing authorization, an Authority to Operate (ATO) remains subject to conditions and can be adjusted, suspended, or revoked by the AO if monitoring reveals unacceptable risk; it is not a permanent grant.
Governance and Reporting Structure
Ongoing authorization typically depends on defined roles, reporting frequencies, metrics, and escalation paths so that changes in risk are surfaced to the AO in a form that supports timely decisions; specific requirements vary by agency tailoring and program.

Common questions

Answers to the questions practitioners most commonly ask about OA.

Does ongoing authorization mean an Authority to Operate (ATO) never expires?
No. Ongoing authorization does not make an ATO permanent. It reframes the authorization decision as a continuous, data-driven process supported by continuous monitoring rather than a one-time event followed by a fixed reauthorization date. The authorizing official's decision remains conditional and can be adjusted, suspended, or revoked based on changes in the system's risk posture. Readers should confirm how their specific agency or program treats authorization duration and triggering events against current official guidance.
Is ongoing authorization the same thing as continuous monitoring?
Not exactly. Continuous monitoring is the ongoing collection and analysis of security-relevant information about a system, while ongoing authorization is the risk-based decision process that consumes those monitoring outputs to maintain or reconsider the authorization state. In most implementations, effective continuous monitoring is a prerequisite that enables ongoing authorization, but the two are distinct: monitoring produces evidence, and the authorizing official makes the authorization determination. Confusing assessment or monitoring activity with the authorization decision is a common mistake.
What does an authorizing official generally need in place before moving a system to ongoing authorization?
Implementations generally depend on a mature continuous monitoring program, defined monitoring frequencies, and reliable, near-current security status information that the authorizing official can review to make risk decisions. Organizations typically also establish criteria for what changes or findings trigger a formal reconsideration of the authorization. The specific entry, exit, and eligibility criteria vary by agency and program, so readers should verify requirements against their applicable authorizing guidance rather than assuming a uniform standard.
How do triggering events fit into an ongoing authorization approach?
Under ongoing authorization, the authorization state can be reassessed in response to defined triggering events rather than solely on a fixed calendar schedule. Such events may include significant system changes, newly identified vulnerabilities or threats, or shifts in the residual risk that the authorizing official has accepted. The precise definitions of what constitutes a triggering event and the associated response are set by organizational and agency policy, so implementers should confirm their program's specific criteria.
How should organizations document ongoing authorization decisions over time?
Because authorization becomes a continuing process, organizations generally need to maintain current records that reflect the system's evolving risk posture and any authorization determinations made in response to monitoring data or triggering events. This typically includes keeping the system's authorization package and supporting artifacts current rather than static between review cycles. Specific documentation requirements and retention expectations depend on agency policy and applicable guidance, which readers should confirm against current authoritative sources.
Can moving to ongoing authorization reduce the compliance burden compared with periodic reauthorization?
It can shift the nature of the effort rather than simply reduce it. Ongoing authorization generally trades the concentrated effort of periodic reauthorization for a sustained investment in continuous monitoring, timely analysis, and responsive risk decision-making. Whether this reduces overall burden depends on the maturity of the monitoring program and available resources. Organizations should also remember that ongoing authorization supports maintaining an authorization decision but does not, by itself, equate to being secure, and program-specific expectations should be verified against current official guidance.

Common misconceptions

Ongoing authorization means the system is authorized once and no longer needs review.
It is the opposite: ongoing authorization depends on a robust, continuous monitoring program, and the AO's authorization remains contingent on the current risk state and can be withdrawn if that state degrades.
Moving to ongoing authorization eliminates the traditional time-bound ATO.
The authorization is still conditional and revocable; ongoing authorization shifts the emphasis from periodic reauthorization events to continuous, risk-based decisions, but it does not make an ATO permanent or unconditional.
A strong continuous monitoring feed automatically equals a secure and compliant system.
Continuous monitoring supports authorization decisions but does not by itself guarantee security or compliance; the data must be assessed against applicable controls and interpreted by the AO, and monitoring is a means to inform risk decisions, not a substitute for them.

Best practices

Establish and document a continuous monitoring strategy before pursuing ongoing authorization, defining which controls are monitored, at what frequency, and by which automated or manual means.
Ensure the authorizing official receives risk information in a decision-ready form, with clear metrics, thresholds, and escalation triggers that support recurring risk-based determinations.
Treat the ATO as conditional and revocable by defining the criteria under which authorization would be reassessed, suspended, or withdrawn based on monitoring findings.
Align the ongoing authorization approach to the applicable revision of the governing RMF guidance and verify current requirements against the official source, since RMF terminology and steps are periodically updated.
Coordinate with agency-specific tailoring and governance requirements, since impact levels, reporting frequencies, and authorization expectations can differ across programs and organizations.
Do not treat continuous monitoring data as proof of security or compliance on its own; pair it with assessment of control effectiveness and documented AO risk decisions.