Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.

Aug 17 2026
Cloud

Continuous ATO and the Future of Federal IT Cloud Security

FedRAMP 20x is replacing static annual audits with continuous, automated security validation. Here’s how federal agencies can build a cATO program that keeps pace with modern threats.

FedRAMP 20x is now live, and agencies are under pressure to acquire technology at commercial speed. In this environment, the traditional Authorization to Operate process — which can take 12 to 18 months — is increasingly seen as a bottleneck.

Continuous Authorization to Operate flips that model. It uses automated monitoring, real-time risk assessment and ongoing compliance checks instead of point-in-time security reviews.

What Is Continuous ATO (cATO)?

“You can’t move at the pace of relevance with traditional ATO, because you’re stuck with a three- to five-year development cycle,” said Nicolas Chaillan, who from 2019 to 2021 served as the Air Force and Space Force’s first chief software officer. With cATO, on the other hand, that development is fluid and never-ending, “so now, you can release software multiple times a day, with features that you build with real-time feedback from your end users,” Chaillan told FedTech.

Agencies can leverage this to go beyond the traditional point-in-time ATO, potentially driving faster detection and response to emerging threats while also supporting zero-trust architectures.

The security check is no longer an annual exercise; it’s continuously reported and validated.

Click the banner below to view CDW’s new Cybersecurity Research Report.

 

How Continuous ATO Improves Upon Traditional ATO

With automated monitoring, real-time risk assessment and ongoing compliance, cATO offers several advantages compared with traditional ATO.

“Legacy ATO compliance frameworks produce a static, point-in-time security snapshot that often misses new and evolving threats,” says Daniel Kroese, vice president of public policy and government affairs at Palo Alto Networks. They can fail to catch “new vulnerabilities that develop between annual, spreadsheet-heavy audits.”

Continuous ATO transforms compliance into an active operational pipeline, “giving agencies and cloud service providers a common view of security posture and utilizing automated monitoring and real-time telemetry to continuously highlight risks as they happen,” Kroese says.

FedRAMP 20x and the Push for Continuous Monitoring

A modernized, automation-focused framework for cloud security assessments, FedRAMP 20x is helping drive the push for cATO in federal agencies.

FedRAMP 20x is about faster authorization, but it’s also about forcing companies to adopt modern security engineering practices.

Given the labor-intensive nature of traditional ATO, “FedRAMP 20x is a breath of fresh air for cloud service security compliance,” Kroese says. “It completely overhauls the legacy authorization paradigm by replacing massive Word documents and manual audits with machine-readable validation utilizing OSCAL and Key Security Indicators.”

This framework mandates that a cloud service’s security posture “become a live, continuous data stream directly tied to the running production environment,” he says. “It moves the federal market away from bureaucratic box-checking and toward engineering inherently secure, continuously verifiable cloud infrastructure.”

How NSA’s 2026 Implementation Guidelines Apply

The National Security Agency’s 2026 Zero Trust Implementation Guidelines are helping to accelerate this automated shift “by more effectively communicating how enforceable security requires continuous verification,” Kroese says. That, in turn, is “helping government agencies and CSPs visualize implementation across the enterprise.”

READ MORE: CDW supports agencies’ journeys toward optimal zero-trust maturity.

The guidelines, for example, call for “making access control decisions and enforcement as granular as possible,” which maps directly to cATO’s call for ongoing, automated security checks. Its Automation and Orchestration pillar focuses on “replacing manual security tasks with policy-driven, automated actions,” in line with cATO’s requirement for automated, continuous enforcement of controls.

NSA’s implementation guidelines “provide clear direction on the mechanics of implementing real-time inspection; context-aware policy enforcement; and granular access controls rather than implicit, perimeter-based trust,” Kroese says. “They validate that the path to true federal resilience lies in AI-driven, continuous threat detection and automated telemetry.”

Building and Implementing a Continuous ATO Program 

Agencies can take practical steps to implement a cATO program, such as integrating existing security tools with their compliance platform through application programming interfaces rather than treating them as separate systems.

After that, agencies should “Consolidate siloed legacy tools into a unified platform architecture capable of aggregating real-time telemetry across your identity, cloud and network environments,” Kroese says.

Agencies can also look to automate drift remediation. “Deploy AI-powered security automation to instantly detect, triage and remediate configuration drifts the moment they occur,” he says. This helps ensure “your operational posture remains continuously authorized, without manual intervention.”

In support of all this, agencies may need to take a fresh look at how their security teams operate, and the skills they bring to the table.

“Treat compliance as code,” Kroese says. “Shift your mentality from treating compliance as a static document submission to an active engineering pipeline, embedding machine-readable OSCAL evidence generation directly into your deployment workflows.”

da-kuk/Getty Images