For SMBs and federal contractors trying to move faster through authorization
Why this issue exists
Issue 2 ships in Week 10, after a four-week run on Authorization to Operate (ATO) bottlenecks, evidence collection, and the operational shifts that separate teams who finish ATOs in months from teams who stall for years. If your business is pursuing a federal Authority to Operate, holding one and dreading the next reauthorization, or selling into agencies that ask for one, this issue is for you.
The pattern we see in nearly every stalled ATO
The ATO that was scoped for 90 days is in month seven. Your team is buried in spreadsheets. Your assessor keeps asking for evidence you thought you already provided. The goalposts feel like they move every Friday.
This is not unusual. It is the norm for most small and mid-sized federal contractors. We have walked into engagements across defense, healthcare, and financial services where the engineering work was done months ago and the authorization was still stuck. The pattern is almost always the same:
- Scope was never locked. The system boundary kept expanding because nobody pushed back when stakeholders added "just one more" integration.
- Documentation lives in five places. Policies in SharePoint, evidence in a shared drive, control narratives in a spreadsheet, configuration screenshots on someone's laptop, and the System Security Plan (SSP) in a Word doc that has not been opened in three months.
- No single owner is driving. Engineering thinks the security lead owns it. The security lead thinks the program manager owns it. The program manager thinks the assessor will tell them what to do.
- Evidence was an afterthought. Controls were implemented correctly, but the proof was never captured. Now your team is recreating six months of audit trails from memory.
The organizations that move through ATOs quickly are not lucky. They are prepared differently.
The five bottlenecks that stall most authorizations
In our experience, the vast majority of ATO delays we see trace back to five specific failure modes. They are operational, not technical, which means they are fixable without touching your architecture:
1. Scope creep before the kick-off. The system boundary on paper is smaller than the system boundary in production. Before any control work begins, lock the boundary in writing and require a change-control gate to expand it.
2. Evidence collected reactively, not continuously. If you are taking screenshots in the week before assessment, you are already late. Configure your environment so every change produces a logged, timestamped record automatically. The cloud platforms already do most of this; turn it on and tune it.
3. Identity and Access Management (IAM) findings. This is consistently the most-cited issue when packages get returned for rework. Privileged access without documented justification, no just-in-time access for sensitive operations, missing audit trails for break-glass accounts. The fix is operational hygiene.
4. The compliance owner problem. "Everyone owns compliance" means no one owns compliance. Every authorization needs one named person accountable for the program's health, with allocated time, clear responsibilities, and the authority to hold engineering accountable. Not a full-time hire for most SMBs; a designated team member with budgeted hours.
5. Treating the SSP as a document, not a system of record. The SSP should reflect what your environment actually does today. If it diverges, your assessor will find it, and the rework will cost you weeks. Maintain it the way you maintain your code.
The shift that separates fast ATOs from stalled ATOs
Teams who finish ATOs quickly do not work harder. They work in a different operating mode: evidence is captured automatically as part of normal operations, not generated under deadline pressure. Controls are proven continuously, not at assessment time. The SSP is a living document maintained alongside the system, not a deliverable produced by the lowest bidder six weeks before submission.
When you operate that way, the assessment is a confirmation of what you already know. When you do not, the assessment is a forensic exercise.
Most useful resources from this month
- Cost Calculator: The dollar number behind a stalled ATO. Two clicks gives you the side-by-side comparison of staying on the current trajectory, doing-it-yourself, or running a managed Bridge subscription, with the months of warfighter delay called out alongside the dollars. Lead with this when you take the budget conversation to finance.
- ATO Readiness Checklist: The five areas where most SMBs stall before authorization, with the specific artifacts each one needs. Use it to score your own posture before you ever engage an assessor.
- Audit Prep Template (Evidence Collection): A working spreadsheet that maps controls to evidence types, owners, and capture cadence. The version we use internally with our own clients.
- Hidden Costs of Non-Compliance Blog: The dollar figures behind a stalled ATO. Useful for getting leadership budget for the operational work that prevents the stall.
- "Cut Your Audit Prep from Weeks to Days" Whitepaper: The 31-page deep dive on operational changes, build-versus-buy decisions, and a 30-day starter plan. Free; no gate beyond an email.
One thing to do this week
Pull a list of every privileged account in your environment. For each one, document in a single sentence why that account needs that level of access and what audit trail captures its activity. If you cannot do that for every account in under an hour, you have just identified the single most common reason ATO packages get returned for rework.
This exercise takes a regulated SMB an afternoon. It surfaces the issue that most often costs teams six to twelve weeks during assessment.
What's coming next
- Week 11 (Jul 7-9): Blog 7 on running compliance as a program, not a project, paired with the Compliance Program Blueprint.
- Week 13 (Jul 21-23): Blog 8 on continuous monitoring, paired with the Continuous Monitoring Toolkit.
- Week 14 (Jul 28-30): Issue 3 of this newsletter, focused on what continuous compliance actually looks like day to day for a small team.
Closing
ATOs do not stall because the technology is hard. They stall because the operating posture around the technology was never built. The teams who get authorized fast and stay authorized are the teams who treat compliance as an operating condition, not a deliverable.
If you want a second set of eyes on where your ATO is stuck, or where it is likely to stall before you start, we offer free 30-minute consultations. Book one here.
Follow the campaign on LinkedIn: Pandora Cloud
Until next month,
Kim Howell CEO and Co-Founder, Pandora Cloud
Subscribe to get the next issue in your inbox
Built to Comply lands monthly. No jargon walls. No product pitches.