Latest / Story
What Happens When an ATO Expires?
Your authorization letter carries a termination date. When that date passes without a new authorization decision, your system is operating without authorization. This article explains what that means in practice and what to do about it. The rules come from NIST, and they are simpler than most teams expect.
What does an expired ATO actually mean?
An ATO (Authorization to Operate) is a risk decision, not a permanent permit. The authorizing official is the person who formally accepts the risk of operating the system. They grant the ATO for a set term. When the term ends, the permission ends with it.
NIST (National Institute of Standards and Technology) defines this rule in SP (Special Publication) 800-37 Rev 2. Without ongoing authorization, the termination date set by the authorizing official marks when authorization expires. Reauthorization is required after that point. Operating past that date means operating without the authorizing official's accepted risk.
Who sets the expiration date, and can it change?
The authorizing official sets the termination date as part of the authorization decision. That decision package also lists terms and conditions, plus any events that could trigger a fresh review. The length of the term is not fixed by NIST. The authorizing official sets the term, guided by federal and organizational policy.
Read your authorization decision letter. It names the exact termination date or frequency. Ask your authorizing official whether your system qualifies for ongoing authorization. If it does, your calendar pressure changes from a hard date to steady reporting.
Does an expired ATO mean you must shut the system down?
Yes, in practical terms. Without a current authorization decision, nobody has formally accepted the risk of operating the system.
You have two clean options. Reauthorize before the date lapses. Or stop processing the covered data until authorization is restored.
What if the date passes while the package is under review?
Keep the authorizing official informed before the date hits. Ask what status the system holds during review. Their answer is the only one that counts.
How does reauthorization work?
Reauthorization repeats the RMF (Risk Management Framework) authorization step with current information. NIST notes it can be as simple as updating the authorization package (SP 800-37 Rev 2, Reauthorization).
The package holds the SSP (System Security Plan) and the SAR (Security Assessment Report). It also holds the POA&M (Plan of Action and Milestones), which tracks every open weakness.
In practice, the steps run in this order:
- Review the current SSP and update it for every system change.
- Run a fresh assessment of the implemented security controls.
- Update the SAR with the new assessment results.
- Review the POA&M, close what is fixed, and add new findings.
- The authorizing official reviews the package and issues a new decision.
How deep the assessment goes is the authorizing official's call. NIST says to lean on monitoring data where it exists (Reauthorization).
Start with a security impact analysis before the assessment. List every change since the last authorization: new servers, new software, new connections. The analysis shows which controls need fresh testing. It also tells the authorizing official what changed and why the risk picture moved.
Bring fresh evidence for every control you claim. Screenshots, config exports, and scan reports beat written assertions. Map each weakness in the SAR to a dated POA&M item. An assessor should trace every finding to a fix.
What are time-driven and event-driven reauthorizations?
Time-driven reauthorization happens when the termination date arrives (SP 800-37 Rev 2, Reauthorization). This is the planned, calendar-based path.
Event-driven reauthorization happens when something changes the risk picture (SP 800-37 Rev 2, Reauthorization). A breach or incident can trigger it. So can a failed or weak continuous monitoring program.
Significant system changes can also force the question. A major upgrade or a new data type may change the risk picture enough to require review.
Either path ends the same way: a fresh authorization decision from the authorizing official. Plan for the time-driven path so the event-driven one never surprises you.
Can continuous monitoring replace a hard expiration date?
Yes, through ongoing authorization. NIST describes this path in SP 800-37 Rev 2 (Ongoing Authorization). Under ongoing authorization, the authorizing official keeps accepting risk based on current monitoring data.
With a strong monitoring program in place, a time-driven reauthorization may not be needed. You replace the big periodic reauthorization with steady reporting of your security posture.
NIST SP 800-137 calls this discipline ISCM (Information Security Continuous Monitoring) (SP 800-137). It defines ISCM as keeping ongoing awareness of security, vulnerabilities, and threats to support risk decisions. It supplements periodic assessments rather than replacing them.
But the trade cuts both ways. NIST warns that failing to keep an effective monitoring program running can be grounds for rescinding the authorization decision. Monitoring is the lifeline, not a formality.
How far ahead should you start preparing?
NIST does not name a fixed lead time (SP 800-37 Rev 2, Reauthorization). It leaves the schedule to federal and organizational policy and the authorizing official's requirements.
A good planning habit is to start the reauthorization package six months before the termination date. That leaves room for a full assessment, POA&M cleanup, and the authorizing official's review cycle.
Set two reminders now. One at six months out to start the package. One at ninety days out to confirm the authorizing official has everything needed to decide.
What should you keep running between authorizations?
This is the work that makes reauthorization painless.
Keep your monitoring cadence running. Test controls at the frequency your monitoring strategy names. Report results to the authorizing official on schedule.
Work the POA&M every month. Close fixed items with evidence attached. Add new findings within days, not quarters.
Log every system change. Each logged change feeds the next security impact analysis. A change log is the cheapest reauthorization insurance you can buy.
Run a gap review at six months out. Compare the live system against the SSP. Close the gaps before the assessment starts.
Who needs to know the expiration date?
The system owner owns the calendar. The ISSO (Information System Security Officer) owns the evidence. The authorizing official owns the decision. Make sure all three track the same date.
Put the date on a shared calendar with the two reminders attached. A date that lives in one inbox gets missed.
Sources
- NIST SP 800-37 Rev 2, Appendix F: Authorization Decision Information
- NIST SP 800-37 Rev 2, Appendix F: Reauthorization
- NIST SP 800-37 Rev 2, Chapter 3: Ongoing Authorization
- NIST SP 800-137, Information Security Continuous Monitoring
Next step
Track every authorization termination date in one place so none of them surprise you. See how PolicyCortex keeps your evidence current for reauthorization day.