Skip to main content

Fall 2025 Service Contractor Magazine

Page 22

Cutting Red Tape, Securing the Mission: Why Faster ATOs Matter and How to Get There

by Gaurav Pal, CEO and Founder, stackArmor, (a Tyto Athene company) Modernizing the federal Risk Management Framework can strengthen security, return precious time to mission work, and save more than a billion dollars a year — without lowering the bar for compliance.

B

efore any federal technology can serve the public or support the warfighter, it needs a formal green light to operate. That approval is called an Authority to Operate (ATO). An ATO is a formal authorization by a government entity that certifies a system has met specific security requirements and is safe to operate within a designated environment. The ATO process is designed to help ensure operational safety while protecting against the growing threat of cyberattacks. This is obtained by following the Risk Management Framework (RMF) — the government’s step‑by‑step process for assessing and managing security risk, developed by the National Institute of Standards and Technology (NIST). These rules exist for a reason: they keep IT systems and sensitive data secure. But in practice, the path to an ATO can be slow, fragmented, and expensive. When manual paperwork crowds out real security work, everyone pays the price — taxpayers, program teams, contractors, and ultimately the people who rely on federal services. This article clearly explains why RMF and ATOs matter, what obstacles exist today, and how pragmatic modernization can preserve rigor while dramatically reducing manual work, potentially saving the government over a billion dollars annually. Based on the analysis of public data and program experience, federal agencies and contractors collectively spend roughly 26 million hours and about $3.6 billion each year on RMF/ATO activities across approximately 13,000 systems. A practical shift toward digital evidence, reusable security patterns, and consistent acceptance criteria could cut

22 / Service Contractor / Fall 2025

that effort by around 40%, saving more than $1.4 billion annually and freeing scarce cyber talent to focus on the threats that matter.

What Slows ATOs Today and Why It Isn’t Making Us Safer

Across agencies, the pattern is familiar. Evidence lives as static Word files, spreadsheets, and screenshots that age the moment they’re created. Control implementations are separated from the systems they are meant to protect, so experts spend time proving that something is secure rather than making it more secure. The result is a talent drain: highly skilled cybersecurity professionals are pulled towards responding to evidence calls, formatting Excel spreadsheets and uploading static documents into legacy GRC platforms. None of this strengthens assurance; it slows mission delivery. For example, let’s say a benefits portal team prepares a small release to fix a confusing form that drives call‑center volume. The code is ready in days or weeks. However, the lack of an ATO causes delays: writing voluminous control narratives, collecting & collating the body of evidence and formatting outputs to conform to an assessor’s requirements are just some of the steps that must be executed. Nothing about the system’s security posture changes, but the go‑live slips a quarter. The public sees no improvement, the team loses momentum, and cyber staff spend weeks formatting documents instead of hardening systems. How many times have you faced this situation?

Professional Services Council


Turn static files into dynamic content formats.

Create a flipbook
Fall 2025 Service Contractor Magazine by Professional Services Council - Issuu