// Capability Statement — Download PDF
Insights / RMF, agency by agency
Accreditation

Same RMF, different everywhere: how agencies actually run authorization

On paper, the Risk Management Framework is one federal process. In practice, which RMF you run depends entirely on whose system it is — the tools, the workflow, the roles, and who signs are different at every agency.

Ausper Technology · July 27, 2026 · Insight · Accreditation · RMF & ATO

Everyone points to the same rulebook. NIST’s Special Publication 800-37 defines the Risk Management Framework and its seven steps — Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor — and 800-53 supplies the controls. If RMF were really one process, an authorization would travel from agency to agency and a team fluent in one program could walk into the next. Neither happens cleanly, and the reason is that the framework is a skeleton every agency dresses differently.

The variation is not cosmetic. It changes the tool your package lives in, the sequence of reviews it moves through, the titles and authority of the people who touch it, and what “authorized” even grants. Understanding that variation is most of the job.

One standard, many overlays

Above 800-37 sits a layer of agency-specific policy that quietly rewrites the rules. DoD runs RMF through DoDI 8510.01 with its own control overlays and the DoD-specific approval chain. The Intelligence Community works to ICD 503. Civilian agencies each publish their own handbooks and tailoring — CMS has its Acceptable Risk Safeguards, others their own. And cloud has an entirely separate lane in FedRAMP, which is RMF-derived but run by a central program with its own package and marketplace. Same DNA, different organisms.

The tools rarely match

Where your package actually lives is the most visible split. The system of record is different agency to agency, and each tool imposes its own fields, formats, and rhythms:

eMASSThe DoD workhorse (DISA). Control-by-control workflow, package submission, and the DoD approval chain baked in.
XactaCommon in the IC and parts of DoD and civilian. Heavy automation and continuous-monitoring orientation.
CFACTSCMS’s own system of record, wired to its ARS control set and its authorization process.
ServiceNow / RegScale / ArcherWhere modernizing civilian agencies are heading — continuous, API-driven, control-as-code.

A team that lives in eMASS is not automatically productive in Xacta or CFACTS. The controls may be the same 800-53 family, but the evidence structure, the artifact templates, and the submission mechanics are not. We compared the two most common head-to-head in eMASS vs Xacta and graded the broader field in our A&A tools guide.

The package moves differently

The authorization workflow — who prepares, who assesses, who recommends, who decides — is a shared shape with very different plumbing. The generic flow looks like this:

Prepareowner + ISSOAssessindependent SCARecommendISSM / AODRAuthorizeAO decidesMonitorconmon
The shared shape of an authorization. What varies by agency: who counts as an independent assessor, whether a central review board sits in the middle, how many gates the package clears, and how long each takes.

Some agencies route every package through a centralized control assessor or a review board; others delegate to the system owner’s chain. Some require an independent assessment from a named organization; others accept a self-assessment with spot checks. The step names match 800-37. The gates, sequencing, and evidence bar do not.

Same roles, different names and power

RMF names a cast — Authorizing Official (AO), AO Designated Representative (AODR), Information System Security Manager (ISSM), Information System Security Officer (ISSO), Security Control Assessor (SCA). The titles travel; the authority does not. In one agency the AO is a senior general officer with a formal risk-executive function behind them; in another, authority is delegated deep into a program office. Who can grant an exception, who signs a POA&M, who can accept residual risk, and who actually holds the pen on the decision all shift with the org chart. Bring the wrong assumption about who decides and a package stalls waiting on a signature from someone who cannot give it.

Why reciprocity is harder than the policy promises

RMF is designed to be reciprocal: authorize once, reuse elsewhere. In practice, reciprocity is the exception. Different overlays and tailoring mean the control baselines are not identical; different tools mean the evidence has to be repackaged; and receiving AOs own the risk on their systems, so they tend to re-examine rather than rubber-stamp another agency’s decision. A clean ATO at one agency is a strong head start at the next — not a transfer.

What actually gets you through

The through-line is that speed comes from agency-specific fluency, not from a generic RMF checklist. Knowing which tool the package lives in, which reviews it must clear, what a given AO’s office emphasizes, and what evidence format clears the bar there is the difference between a 12-month slog and a fast, clean authorization. It is exactly why our AccelSecure™ approach is built around a playbook for your target agency — the tool, the workflow, the roles, and the evidence that agency’s assessors actually expect — rather than one generic path we run everywhere.

Sources

  1. NIST, SP 800-37 Rev. 2, Risk Management Framework for Information Systems.
  2. NIST, SP 800-53 Rev. 5, Security and Privacy Controls.
  3. DoD Instruction 8510.01 (DoD RMF); ODNI ICD 503 (IC IT systems); FedRAMP (cloud). Agency policy overlays are public where published.

Related reading

Put this to work

Authorizing at a specific agency?

Tell us the agency and the system of record and we’ll tell you exactly what its path looks like — the tool, the gates, and who signs.

Talk to Ausper