Skip to main content
Category: Authorization & Accreditation

Reciprocity

Simply put

Reciprocity is an arrangement in which organizations agree to accept one another's security assessment results instead of each performing their own separate assessment of the same information system. This allows the reuse of information system resources without duplicating assessment work. Practitioners should verify how a specific agency or program implements reciprocity, since acceptance is generally based on mutual agreement rather than an automatic entitlement.

Formal definition

In the security assessment and authorization context, reciprocity refers to a mutual agreement among participating organizations to accept each other's security assessments in order to reuse information system resources. It supports leveraging existing assessment evidence and artifacts across organizational boundaries rather than re-performing assessment activities. Reciprocity is not automatic and generally depends on the participating organizations' agreement and the comparability of assessment scope, rigor, and applicable controls; readers should confirm the specific conditions and any agency- or program-specific limitations against current authoritative guidance. Note that reciprocity concerns acceptance of assessment results and does not by itself constitute an authorization decision, which remains the responsibility of the accepting organization's authorizing official.

Why it matters

Reciprocity addresses one of the most persistent inefficiencies in security assessment and authorization: the tendency for multiple organizations to independently reassess the same information system against overlapping controls. By agreeing to accept one another's assessment results, participating organizations can reuse existing evidence and artifacts rather than duplicating assessment effort, which conserves scarce assessor resources and can accelerate the deployment of shared systems and services. This matters especially where a single system supports multiple missions, agencies, or programs that would otherwise each impose their own separate assessment cycle.

The practical value of reciprocity depends heavily on how it is implemented, and this is where practitioners must exercise care. Reciprocity is a mutual agreement, not an automatic entitlement, and its usefulness rests on the comparability of the underlying assessments, their scope, rigor, and the specific controls evaluated. A frequent and consequential mistake is treating accepted assessment results as equivalent to an authorization to operate. Reciprocity concerns the acceptance of assessment evidence; it does not, by itself, constitute an authorization decision. The accepting organization's authorizing official retains responsibility for the risk-based decision to operate, and that official may still require additional information, conditions, or controls before accepting the risk.

Because acceptance depends on mutual agreement and on assessment comparability, practitioners should never assume that an assessment accepted by one agency or program will be honored elsewhere. Agency- and program-specific limitations are common, and conditions can differ across implementations. Readers should confirm how a particular organization implements reciprocity, and what evidence it will and will not accept, against current authoritative guidance rather than relying on a general expectation of reuse.

Who it's relevant to

Authorizing Officials
Authorizing officials rely on reciprocity to reuse existing assessment evidence rather than commissioning duplicate assessments, but they retain responsibility for the authorization decision itself. Even when accepting another organization's assessment results, the authorizing official must make the risk-based determination to operate and may require additional information or conditions before doing so.
Information System Security Managers and Assessment Teams
Those responsible for conducting or supporting assessments need to understand what assessment evidence and artifacts may be reused across organizational boundaries and where comparability of scope, rigor, and applicable controls must be demonstrated. They should confirm the specific conditions a participating organization requires before assuming prior results will be accepted.
Compliance Officers and Program Managers
Compliance officers and program managers evaluating shared or cross-organizational systems should treat reciprocity as a mutual agreement rather than an automatic entitlement. They should verify agency- or program-specific limitations and avoid assuming that an assessment accepted by one organization will be honored by another.
Government Contractors
Contractors supporting systems that serve multiple agencies or programs benefit from understanding when assessment results may be reused, but should not assume that acceptance in one context carries over to another. They should confirm the accepting organization's specific reciprocity conditions and remember that accepted assessment results do not by themselves constitute an authorization.

Inside Reciprocity

Acceptance of Existing Authorization Artifacts
Reciprocity generally involves one organization accepting another organization's existing security assessment and authorization documentation, such as the System Security Plan (SSP), Security Assessment Report (SAR), and Plan of Action and Milestones (POA&M), to avoid duplicative testing of the same system or controls.
Common Control and Risk Baseline
Reciprocity typically depends on the systems in question sharing a common frame of reference, such as the NIST SP 800-53 control catalog and the RMF process, so that a receiving organization can meaningfully evaluate whether the originating authorization aligns with its own risk tolerance.
Risk Acceptance by the Receiving Authorizing Official
Reciprocity does not eliminate the receiving Authorizing Official's (AO) responsibility. The receiving AO generally reviews the existing artifacts and makes an independent risk determination, and may accept the authorization in whole, in part, or subject to additional conditions.
Scope and Boundary Considerations
Reciprocity applies to the system, environment, and boundary described in the original authorization. Differences in operating environment, connected systems, data types (for example CUI versus other information), or tailoring may limit how much of an authorization can be reused.
Governing Guidance and Policy
Reciprocity concepts are addressed in NIST RMF guidance (such as NIST SP 800-37) and, for DoD systems, in DoD RMF policy issuances; FedRAMP similarly supports reuse of authorizations across federal civilian agencies. Readers should verify the applicable revision and agency-specific policy, as terminology and procedures differ across communities.

Common questions

Answers to the questions practitioners most commonly ask about Reciprocity.

Does an existing Authority to Operate (ATO) from one organization automatically transfer to another under reciprocity?
No. Reciprocity is intended to promote reuse of existing assessment evidence and authorization artifacts, not to automatically transfer an ATO. In most implementations, the receiving authorizing official (AO) retains the authority and responsibility to review the prior body of evidence, evaluate residual risk against their own environment and risk tolerance, and issue their own authorization decision. Reciprocity generally reduces duplicative testing rather than eliminating the receiving AO's decision. Confirm the specific expectations against the current governing policy applicable to your system.
Does a FedRAMP authorization satisfy DoD reciprocity requirements on its own?
Not automatically. A FedRAMP authorization is issued under the FedRAMP program for federal civilian cloud use, while DoD systems are authorized under the RMF and, for cloud services, are typically evaluated against additional DoD-specific requirements and impact-level expectations. DoD components generally may leverage a FedRAMP authorization as a starting point, but additional DoD-specific controls, review, and an authorization decision by the applicable DoD AO are commonly required. Reciprocity here is a basis for reuse, not a substitute for the receiving authority's separate determination. Verify current DoD and FedRAMP guidance for the applicable service and impact level.
What artifacts should be prepared to support a reciprocity review by a receiving authorizing official?
Reciprocity reviews generally rely on the existing authorization package, which in most implementations includes the security plan, the assessment report or results, the plan of action and milestones, and the prior authorization decision documentation. Providing complete, current, and traceable artifacts tends to reduce duplicative testing. The receiving AO determines which items are sufficient and whether additional evidence is needed, so confirm required artifacts and formats against the receiving organization's current policy.
How does continuous monitoring status affect a reciprocity decision?
Because an ATO is time-bound and subject to continuous monitoring, the currency and completeness of monitoring data generally influence whether a receiving AO will accept prior evidence. Stale assessments, unresolved items in the plan of action and milestones, or gaps in ongoing monitoring may prompt the receiving AO to require additional review or testing. Reciprocity does not remove continuous monitoring obligations. Confirm monitoring expectations with the receiving organization.
How should differences in control baselines or tailoring be handled during a reciprocity review?
When the receiving environment applies a different baseline, impact level, or agency-specific tailoring than the original authorization, the receiving AO generally identifies control gaps and determines whether additional evidence or testing is needed to address them. Reciprocity supports reuse where the prior evidence maps to the receiving requirements, but differences in scope, impact level, or tailoring may limit how much can be reused. Verify the applicable baseline and tailoring against the current authoritative text for both environments.
Who holds the final decision authority when leveraging reciprocity, and what does that mean for accountability?
In most implementations, the receiving authorizing official holds the final authorization decision and accepts the associated residual risk for their environment, even when reusing another organization's evidence. This means reciprocity reduces effort but does not shift accountability away from the receiving AO. Roles, responsibilities, and any conditions on acceptance should be confirmed against the governing policy applicable to the receiving system.

Common misconceptions

Reciprocity means a system authorized by one organization is automatically authorized for use by another.
Reciprocity generally facilitates reuse of assessment artifacts, but the receiving Authorizing Official normally must still make an independent risk-based decision. Acceptance is not automatic and may be partial or conditional.
A FedRAMP authorization automatically satisfies DoD requirements through reciprocity.
FedRAMP authorization and DoD authorization are governed by different authorities and, for DoD, additional impact-level and security requirements may apply. A FedRAMP authorization does not by itself satisfy DoD-specific requirements; the responsible DoD AO must evaluate and accept the risk under applicable DoD policy.
Once an authorization is accepted under reciprocity, it remains valid indefinitely.
The underlying authorization (ATO) is time-bound and subject to continuous monitoring. Changes to the system, environment, or risk posture can affect the validity of a reciprocal acceptance, so reciprocity does not confer a permanent status.

Best practices

Confirm that the originating authorization is current, still under active continuous monitoring, and not expired or superseded before relying on it.
Obtain and review the complete authorization package, SSP, SAR, and POA&M, rather than accepting a summary statement of authorization.
Verify that the originating system's boundary, environment, data types, and control tailoring align with your own use case and risk tolerance, and document any gaps.
Have the receiving Authorizing Official make and record an explicit, independent risk determination, noting any conditions or supplemental controls required for acceptance.
Do not assume cross-community reciprocity (for example FedRAMP to DoD) is automatic; confirm the applicable impact level and agency-specific requirements against current authoritative policy.
Establish a mechanism to receive ongoing continuous monitoring outputs from the originating organization so that changes in risk posture are reflected in your reciprocal acceptance.