Reciprocity
Reciprocity is an arrangement in which organizations agree to accept one another's security assessment results instead of each performing their own separate assessment of the same information system. This allows the reuse of information system resources without duplicating assessment work. Practitioners should verify how a specific agency or program implements reciprocity, since acceptance is generally based on mutual agreement rather than an automatic entitlement.
In the security assessment and authorization context, reciprocity refers to a mutual agreement among participating organizations to accept each other's security assessments in order to reuse information system resources. It supports leveraging existing assessment evidence and artifacts across organizational boundaries rather than re-performing assessment activities. Reciprocity is not automatic and generally depends on the participating organizations' agreement and the comparability of assessment scope, rigor, and applicable controls; readers should confirm the specific conditions and any agency- or program-specific limitations against current authoritative guidance. Note that reciprocity concerns acceptance of assessment results and does not by itself constitute an authorization decision, which remains the responsibility of the accepting organization's authorizing official.
Why it matters
Reciprocity addresses one of the most persistent inefficiencies in security assessment and authorization: the tendency for multiple organizations to independently reassess the same information system against overlapping controls. By agreeing to accept one another's assessment results, participating organizations can reuse existing evidence and artifacts rather than duplicating assessment effort, which conserves scarce assessor resources and can accelerate the deployment of shared systems and services. This matters especially where a single system supports multiple missions, agencies, or programs that would otherwise each impose their own separate assessment cycle.
The practical value of reciprocity depends heavily on how it is implemented, and this is where practitioners must exercise care. Reciprocity is a mutual agreement, not an automatic entitlement, and its usefulness rests on the comparability of the underlying assessments, their scope, rigor, and the specific controls evaluated. A frequent and consequential mistake is treating accepted assessment results as equivalent to an authorization to operate. Reciprocity concerns the acceptance of assessment evidence; it does not, by itself, constitute an authorization decision. The accepting organization's authorizing official retains responsibility for the risk-based decision to operate, and that official may still require additional information, conditions, or controls before accepting the risk.
Because acceptance depends on mutual agreement and on assessment comparability, practitioners should never assume that an assessment accepted by one agency or program will be honored elsewhere. Agency- and program-specific limitations are common, and conditions can differ across implementations. Readers should confirm how a particular organization implements reciprocity, and what evidence it will and will not accept, against current authoritative guidance rather than relying on a general expectation of reuse.
Who it's relevant to
Inside Reciprocity
Common questions
Answers to the questions practitioners most commonly ask about Reciprocity.