Readiness check
Compliance / How authorization works

ATO, FedRAMP, CMMC — which one is actually yours?

Three approvals get conflated constantly. They apply to different parties, come from different authorities, and only one of them is the thing a defense contractor sits an assessment for. Here's the honest map — and where you actually fit on it.

The short version
Your cloud holds a FedRAMP authorization. You earn a CMMC certification. An ATO is the risk-acceptance decision behind the first — rarely something you pursue yourself.
Three approvals, three parties

Who is being approved, and by whom.

ATO
Authorization to Operate

A formal decision by an agency official to accept the risk of running a specific system. The output of the NIST Risk Management Framework. Applies to a federal information system.

WhoA system owner
Issued byAuthorizing Official
BasisNIST 800-37 (RMF)
FEDRAMP
Cloud authorization

A standardized authorization for a cloud service offering — effectively an ATO for a cloud, reusable across agencies. This is what makes AWS GovCloud or Azure Government usable for CUI.

WhoA cloud provider
Issued byAgency ATO / JAB P-ATO
YouInherit it
CMMC
Your certification

A certification that you, the contractor, protect CUI to the 110 controls. Assessed by an independent C3PAO against 320 objectives. This is the thing you sit an assessment for.

WhoYou, the contractor
Issued byC3PAO
Basis32 CFR Part 170
The part people get wrong

You almost certainly don't need your own ATO.

Contractors hear "authorization" and assume they must chase an ATO. In the usual case, you don't. You build your CUI boundary inside a cloud that already holds a FedRAMP authorization — you inherit that — and you pursue a CMMC Level 2 certification for your own handling of CUI.

An ATO becomes yours to obtain only when you operate a system directly on an agency's behalf. If that's you, we'll say so. If it isn't, chasing one wastes months.

Your cloud (AWS / Azure / Google) FedRAMP — inherited
Your CUI boundary CMMC L2 — you earn
Interim self-attestation SPRS score (7019/7020)
Your own ATO usually not required
The path you'll walk

How a CMMC Level 2 certification actually happens.

01

Scope the CUI

Everything starts with the boundary. We identify every asset that stores, processes, or transmits CUI — and, just as important, what genuinely doesn’t. Scope is the biggest lever on cost, so we draw it tight and defensible.

02

Implement 110 controls

We build to NIST 800-171 Rev 2 — all 110 controls, mapped to the 320 assessment objectives — configured in your FedRAMP-authorized cloud as infrastructure-as-code, not slideware.

03

SSP + evidence

Every control is documented in a System Security Plan, with the shared-responsibility split written down and evidence collected against each objective. This is what the assessor actually reads.

04

Post SPRS score

You self-assess against the 110 and post a score to SPRS (via 7019/7020). It has to be honest — the C3PAO will check it, and a gap between your score and reality is the fastest way to fail.

05

C3PAO assessment

An independent C3PAO assesses you against all 320 objectives. We prepare the evidence, run a mock assessment, and coordinate the engagement — up to the independent line we can’t cross for you.

06

Certify + affirm

You receive a CMMC Level 2 certification, valid three years, with an annual affirmation in SPRS. Cadence keeps the evidence current so the next assessment isn’t a fire drill.

CMMC certification valid three years with an annual affirmation in SPRS. Status current Sept 2026. [confirm — current phase at engagement]
For context — the RMF

And how an ATO happens — the process your cloud already went through.

The Risk Management Framework (NIST 800-37 Rev 2) is the seven-step process behind every ATO and every FedRAMP authorization. You inherit most of it from your cloud; it's worth knowing what it is.

0
Prepare
1
Categorize
2
Select
3
Implement
4
Assess
5
Authorize (ATO)
6
Monitor
Source: NIST SP 800-37 Rev 2. The ATO is the decision at step 5.
Where we fit

One owner across the whole path.

STEPS 01–03 · ENCLAVE
Build to the controls

Scope, implement, and document the boundary in your FedRAMP-authorized cloud.

ONGOING · CADENCE
Keep the score real

Operate the boundary and keep the SPRS score honest between assessments.

STEPS 04–06 · ATTEST
Get to the certificate

Evidence, mock assessment, and C3PAO coordination — up to the independent line.

Not sure which approval your contract needs?

A readiness check reads your clause and tells you exactly what you're on the hook for — and what you're not.