HomeGlossaryAuthority to Operate (ATO)
Technology & IT ProcurementATO

Authority to Operate (ATO)

An Authority to Operate (ATO) is the formal written authorization by an agency Authorizing Official for a federal IT system to operate, based on an accepted level of risk documented in a security assessment.

Quick answer

An Authority to Operate (ATO) is the formal written authorization by an agency Authorizing Official for a federal IT system to operate, based on an accepted level of risk documented in a security assessment.


An Authority to Operate (ATO) is the formal written decision by a senior agency official, the Authorizing Official (AO), that an information system is authorized to operate based on a thorough assessment of its security controls and an acceptance of residual risk, as required by FISMA and NIST SP 800-37.

What is an Authority to Operate?

The Federal Information Security Management Act (FISMA) requires every federal information system to have a current ATO before it can be used to process, store, or transmit federal government data. The ATO represents the Authorizing Official's explicit acceptance of risk and formal permission for the system to operate in the federal environment.

The ATO process (formally called "Risk Management Framework" or RMF under NIST SP 800-37) involves several key steps: categorize the system (Low, Moderate, or High based on data sensitivity), select and implement applicable NIST 800-53 security controls, assess those controls (typically by an independent assessor), compile a Plan of Action and Milestones (POA&M) for any gaps, and present the full security package for the Authorizing Official's authorization decision.

The ATO document specifies: which system is authorized, who granted the authorization, the date of authorization, the authorization termination date (typically 3 years, though continuous monitoring can extend this), and any conditions or limitations on operation. Systems operating without a valid ATO are in violation of FISMA.

For contractors building or operating systems on behalf of federal agencies, obtaining ATO is not optional, it is a contractual requirement. Contractors who develop new federal systems must plan ATO acquisition as a project milestone, and those who operate government systems must maintain ATO currency through continuous monitoring, annual security reviews, and timely remediation of identified vulnerabilities.

FedRAMP authorization is a specialized ATO pathway for cloud service providers that agencies can leverage rather than conducting independent assessments.

Why ATOs matter for government contractors

Contractors providing IT systems or operating government infrastructure must understand ATO requirements. A system that cannot achieve ATO cannot be deployed, contract value is at risk. Projects that fail to budget time and resources for the ATO process routinely experience costly delays and require emergency remediation to achieve authorization.

Example

A contractor wins a $20M contract to develop a new HHS patient data management system. The contract requires ATO before the system enters production. The contractor implements 325 NIST 800-53 Moderate controls, commissions an independent security assessment, submits a security package to HHS's Authorizing Official, and responds to 18 months of assessment findings. The AO grants a three-year ATO with a POA&M for 12 remaining findings that must be remediated within 90 days. The system enters production, and the contractor monitors and reports security status quarterly.

Frequently Asked Questions

How long is an ATO valid?


Standard ATOs are typically valid for three years, after which a reassessment is required. Under continuous monitoring programs, agencies can maintain ATO currency beyond three years without a full reassessment, provided the system's risk posture remains acceptable. The Continuous ATO (cATO) model formalizes this approach.

What is a Plan of Action and Milestones (POA&M)?


A POA&M is the document listing security deficiencies identified during the security assessment that have not yet been remediated, along with the planned remediation actions and target completion dates. The AO reviews the POA&M as part of the authorization decision and may impose conditions requiring remediation of high-risk items before or shortly after granting the ATO.

Can a system operate without an ATO?


Technically, agencies can grant an Interim ATO (IATO) or Provisional ATO for limited operation while the full authorization is completed. Operating without any authorization is a FISMA violation and exposes both the agency and the contractor to significant risk.

Who is the Authorizing Official?


The Authorizing Official is a senior agency executive with budget and mission authority for the system, typically a C-suite official or senior program manager. The AO is personally accountable for the authorization decision and cannot delegate the risk acceptance decision itself, though they typically rely on security teams to prepare the authorization package.

How Bidovate helps

Bidovate puts Authority to Operate (ATO) to work inside your capture and proposal workflow.

Federal contracting

See Bidovate in action

Book a demo and we will show you the platform using your actual contract data.