// Capability Statement — Download PDF
Insights / A&A Tooling
A&A Tooling

eMASS vs XACTA, from people who live in both.

The two workhorse assessment-and-authorization platforms compared practically — where each fits, where teams struggle, and the habits that keep either one clean.

Ausper Technology · July 20, 2026 · Insight · A&A Tooling · eMASS and Xacta

Every A&A shop lives in one of two systems of record: eMASS (Enterprise Mission Assurance Support Service, the DoD workhorse) or XACTA (Telos's platform, common across the IC and some civilian agencies). Programs rarely choose — the agency chooses for you. What you control is how cleanly you run the one you're handed.

eMASSXACTA
Where you'll meet itDoD components, DISA-aligned programsIC elements, some fed-civ agencies
StrengthsDeep DoD workflow fit, inheritance, STIG/ACAS ingest pathsFlexible workflows, 360 continuous views, IC process fit
Where teams struggleData hygiene at scale; stale artifacts; asset sprawlWorkflow sprawl; configuration debt; report tuning
The constantBoth are only as good as the control statements and evidence you feed them.

Running either one clean

One source of truth. The tracker isn't eMASS *and* a spreadsheet — pick the system of record and kill the shadow copies, or reconciliation eats your ISSO's week, every week.

Inheritance first. Map common control providers before writing a single statement; half your package may already exist upstream. Both platforms support it; most programs underuse it.

Feed them automatically. Scanner results, asset data, and evidence should arrive by integration, not upload button. That's frequently a platform-engineering job — ServiceNow-to-A&A pipelines are a pattern we build repeatedly.

Write for the assessor. No tool rescues a weak implementation statement. Statement libraries, reviewed and reused, are the highest-leverage artifact in either system.

Common questions

What is the difference between eMASS and Xacta?
eMASS is the government-furnished A&A system of record across most of DoD — it is where the package lives and where the authorization decision is recorded. Xacta is a commercial GRC platform used across DoD, the intelligence community and civilian agencies; it is more configurable, and teams tend to do the analytical work there. One is the ledger, the other is the workshop.
Can a program use both?
It is common, and often unavoidable. Control analysis, inheritance modelling and evidence assembly happen in Xacta because it is the better environment for that work, and the finished package is pushed into eMASS because that is what the authorizing official signs from. The cost is a synchronisation problem, so decide early which system is authoritative for each field.
What goes wrong in either tool?
Both are records of decisions, not substitutes for making them. The failure pattern is identical in each: implementation statements that were true two architectures ago, POA&M milestones whose dates have already gone by, and inherited controls that were accepted once and never re-verified against the provider’s current responsibility matrix.

Related reading

Put this to work

Need it done, not just explained?

This is the work we do every day. Tell us where your program stands and we'll give you a straight answer.

Talk to Ausper