// Capability Statement — Download PDF
Insights / RMF, agency by agency
Accreditation

Same RMF, different everywhere: how agencies actually run authorization

On paper, the Risk Management Framework is one federal process. In practice, which RMF you run depends entirely on whose system it is — the tools, the workflow, the roles, and who signs are different at every agency.

Ausper Technology · July 27, 2026 · Insight · Accreditation · RMF & ATO

Everyone points to the same rulebook. NIST’s Special Publication 800-37 defines the Risk Management Framework and its seven steps — Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor — and 800-53 supplies the controls. If RMF were really one process, an authorization would travel from agency to agency and a team fluent in one program could walk into the next. Neither happens cleanly, and the reason is that the framework is a skeleton every agency dresses differently.

The variation is not cosmetic. It changes the tool your package lives in, the sequence of reviews it moves through, the titles and authority of the people who touch it, and what “authorized” even grants. Understanding that variation is most of the job.

One standard, many overlays

Above 800-37 sits a layer of agency-specific policy that quietly rewrites the rules. DoD runs RMF through DoDI 8510.01 with its own control overlays and the DoD-specific approval chain. The Intelligence Community works to ICD 503. Civilian agencies each publish their own handbooks and tailoring — CMS has its Acceptable Risk Safeguards, others their own. And cloud has an entirely separate lane in FedRAMP, which is RMF-derived but run by a central program with its own package and marketplace. Same DNA, different organisms.

The tools rarely match

Where your package actually lives is the most visible split. The system of record is different agency to agency, and each tool imposes its own fields, formats, and rhythms:

eMASSThe DoD workhorse (DISA). Control-by-control workflow, package submission, and the DoD approval chain baked in.
XactaCommon in the IC and parts of DoD and civilian. Heavy automation and continuous-monitoring orientation.
CFACTSCMS’s own system of record, wired to its ARS control set and its authorization process.
ServiceNow / RegScale / ArcherWhere modernizing civilian agencies are heading — continuous, API-driven, control-as-code.

A team that lives in eMASS is not automatically productive in Xacta or CFACTS. The controls may be the same 800-53 family, but the evidence structure, the artifact templates, and the submission mechanics are not. We compared the two most common head-to-head in eMASS vs Xacta and graded the broader field in our A&A tools guide.

The package moves differently

The authorization workflow — who prepares, who assesses, who recommends, who decides — is a shared shape with very different plumbing. The generic flow looks like this:

Prepareowner + ISSOAssessindependent SCARecommendISSM / AODRAuthorizeAO decidesMonitorconmon
The shared shape of an authorization. What varies by agency: who counts as an independent assessor, whether a central review board sits in the middle, how many gates the package clears, and how long each takes.

Some agencies route every package through a centralized control assessor or a review board; others delegate to the system owner’s chain. Some require an independent assessment from a named organization; others accept a self-assessment with spot checks. The step names match 800-37. The gates, sequencing, and evidence bar do not.

Same roles, different names and power

RMF names a cast — Authorizing Official (AO), AO Designated Representative (AODR), Information System Security Manager (ISSM), Information System Security Officer (ISSO), Security Control Assessor (SCA). The titles travel; the authority does not. In one agency the AO is a senior general officer with a formal risk-executive function behind them; in another, authority is delegated deep into a program office. Who can grant an exception, who signs a POA&M, who can accept residual risk, and who actually holds the pen on the decision all shift with the org chart. Bring the wrong assumption about who decides and a package stalls waiting on a signature from someone who cannot give it.

Why reciprocity is harder than the policy promises

RMF is designed to be reciprocal: authorize once, reuse elsewhere. In practice, reciprocity is the exception. Different overlays and tailoring mean the control baselines are not identical; different tools mean the evidence has to be repackaged; and receiving AOs own the risk on their systems, so they tend to re-examine rather than rubber-stamp another agency’s decision. A clean ATO at one agency is a strong head start at the next — not a transfer.

What actually gets you through

The through-line is that speed comes from agency-specific fluency, not from a generic RMF checklist. Knowing which tool the package lives in, which reviews it must clear, what a given AO’s office emphasizes, and what evidence format clears the bar there is the difference between a 12-month slog and a fast, clean authorization. It is exactly why our AccelSecure™ approach is built around a playbook for your target agency — the tool, the workflow, the roles, and the evidence that agency’s assessors actually expect — rather than one generic path we run everywhere.

Common questions

Is the RMF the same at every federal agency?
The six steps and the NIST SP 800-53 control catalogue are the same everywhere. Almost nothing else is. Overlays change which controls apply and how they are tailored, the assessment tooling differs, the package moves through a different workflow, the roles carry different names and very different authority, and the person who signs sits somewhere else in the organization. The standard is federal; the process is local.
Does an ATO from one agency transfer to another?
Reciprocity is policy, not a guarantee. A receiving authorizing official can accept the package as-is, accept it with conditions, or re-assess the parts they care about. What actually transfers well is evidence: current scan results, a boundary that matches the architecture, and implementation statements specific enough to be verified. What transfers badly is a package written to satisfy one agency’s template.
What makes an authorization move faster?
Knowing the receiving organization before you write. Which overlay they apply, which tool they expect the package in, which roles review in what order, and what their assessors consistently push back on. That knowledge does not shorten the control work, but it removes the rework cycles — and rework, not assessment, is where most authorization schedules are actually lost.

Sources

  1. NIST, SP 800-37 Rev. 2, Risk Management Framework for Information Systems.
  2. NIST, SP 800-53 Rev. 5, Security and Privacy Controls.
  3. DoD Instruction 8510.01 (DoD RMF); ODNI ICD 503 (IC IT systems); FedRAMP (cloud). Agency policy overlays are public where published.

Related reading

Put this to work

Authorizing at a specific agency?

Tell us the agency and the system of record and we’ll tell you exactly what its path looks like — the tool, the gates, and who signs.

Talk to Ausper