What is an authority to operate (ATO)?
An authority to operate (ATO) is a formal decision by a senior official that a US government computer system may run. By granting it, the official accepts the remaining security risk. NIST calls it an authorization to operate.
Also known as: ATO, authorization to operate, approval to operate
Researched and fact-checked by AI, with no human review. 6 sources listed below. How we verify
Last updated
What does an ATO decide?
A federal computer system needs a formal sign-off before it goes live. The NIST glossary calls this an authorization to operate. It defines the term as an official management decision by a senior federal official. The official authorizes the system to run and explicitly accepts the risk. The decision rests on an agreed set of security and privacy controls. The glossary adds that a system is authorized for a specified period, on terms the official sets. The older name was approval to operate.
The process comes from the Risk Management Framework, which NIST published in its current form in December 2018. An authorizing official reviews a package of security documents and decides if the risk is acceptable. The framework's text lists four possible decisions:
- authorization to operate
- common control authorization, which covers safeguards that several systems inherit
- authorization to use, which accepts another organization's existing package
- denial of authorization
The framework says an official may authorize a system for only a short period. One example is testing a system in real conditions before every control is in place.
Why does it slow down military technology?
A Department of War memo dated September 28, 2026 uses the wording authority to operate. NIST's entry for ATO lists that wording too. The memo lists that approval and a second one, the authority to connect, among the main barriers to fielding counter-drone systems. It says such processes take months. It orders one department-wide process, with a clear lead, within 30 days of publication. For tested and validated systems, the steps must take days or weeks. For systems approved before, reviewers are to reuse earlier data and re-examine only material changes.
The department had already changed its wider approach. On September 24, 2025, it announced a Cybersecurity Risk Management Construct. It said the earlier framework leaned too heavily on static checklists and manual processes. The new construct aims for continuous monitoring and what the department calls a constant ATO posture. Its ten tenets include reciprocity, meaning assessments are reused across systems.
What does an ATO not cover?
An ATO is about the security of an information system. It is not permission to use a weapon. The 2026 memo treats radio spectrum approval, weapons safety reviews and legal reviews as separate steps.
Sources
- authorization to operate - Glossary, NIST Computer Security Resource Center
- ATO - Glossary, NIST Computer Security Resource Center
- SP 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, NIST Computer Security Resource Center
- NIST Special Publication 800-37, Revision 2: Risk Management Framework for Information Systems and Organizations, National Institute of Standards and Technology (NIST)
- Accelerating Employment of Counter-Unmanned Aircraft Systems to Protect American Airspace Sovereignty (memorandum, September 28, 2026), U.S. Department of War
- Department of War Announces New Cybersecurity Risk Management Construct, U.S. Department of War, Chief Information Officer