DoDI 8510.01 is the Department of Defense instruction that establishes the Risk Management Framework, or RMF, for every DoD information system. Reissued on July 19, 2022, it replaced the older DIACAP certification-and-accreditation model with a continuous risk management process aligned to NIST and Committee on National Security Systems standards, and it governs a system from initial planning through decommissioning.1Department of Defense. DoD Instruction 8510.01 – Risk Management Framework for DoD Systems If you own, secure, or connect a system to the DoD, this instruction defines what you have to do to get it authorized and keep it authorized.
The Seven Steps You Have to Move Through
The framework follows seven sequential steps drawn from NIST Special Publication 800-37, Revision 2.2National Institute of Standards and Technology. SP 800-37 Rev 2 – Risk Management Framework for Information Systems and Organizations Every document, role, and deadline in the instruction maps back to one of them.
- Prepare. Set the organizational context before touching a specific system. This step, added in Revision 2, covers identifying common controls available for inheritance and assigning roles.
- Categorize. Rate the system and its data by potential impact to confidentiality, integrity, and availability.
- Select. Pull an initial baseline of controls from NIST SP 800-53 and tailor them to the environment.
- Implement. Put the controls in place and document how each one works.
- Assess. Test the controls to verify they operate as claimed.
- Authorize. A senior official reviews the residual risk and formally decides whether the system can operate.
- Monitor. Track the security posture continuously, reassess controls on a rotating schedule, and report changes in risk.
These are not a one-time checklist. The Monitor step feeds back into the earlier ones whenever the system changes or new threats appear, which is why the current instruction treats authorization as an ongoing state rather than a single approval.
Who Is Accountable at Each Stage
DoDI 8510.01 assigns specific accountability for every system. These are not ceremonial titles. Each carries administrative and legal responsibility.
Authorizing Official
The Authorizing Official, or AO, is the senior official who formally accepts the risk of running the system. The AO reviews the complete package and issues the decision to authorize, deny, or authorize with conditions, and can downgrade or revoke that decision at any time if the risk picture changes.1Department of Defense. DoD Instruction 8510.01 – Risk Management Framework for DoD Systems One firm rule in the current process: the AO cannot grant a full authorization if any control carries a residual risk level of High or Very High.3Defense Counterintelligence and Security Agency. NISP eMASS Industry Operation Guide
System Owner
The System Owner is the primary advocate for the technology, responsible for funding, mission fit, the security plan, and the Plan of Action and Milestones tracking known vulnerabilities.1Department of Defense. DoD Instruction 8510.01 – Risk Management Framework for DoD Systems
Information System Security Manager
The Security Manager handles day-to-day security operations, serves as the point of contact for incidents and compliance issues, and maintains the documentation that reflects the current state of the system’s defenses.
Security Control Assessor
The Assessor provides an independent evaluation of whether the controls actually work. The Assessor tests controls, identifies gaps, and produces a formal assessment report that feeds into the AO’s decision.4National Institute of Standards and Technology. Computer Security Resource Center Glossary – Authorizing Official
Common Control Provider
The Common Control Provider develops, implements, and monitors controls that other systems inherit.5Computer Security Resource Center. Common Control Provider A data center that already runs physical access and environmental protections, for example, lets the systems hosted there inherit those controls instead of building their own. The Prepare step specifically requires organizations to identify and publish which common controls are available for inheritance.1Department of Defense. DoD Instruction 8510.01 – Risk Management Framework for DoD Systems
What Systems Fall Under the Rule
The instruction applies to all DoD information technology that receives, processes, stores, displays, or transmits DoD information. That covers traditional information systems, IT services, Platform IT embedded in weapons systems and vehicles, and systems operated by contractors on behalf of the department.1Department of Defense. DoD Instruction 8510.01 – Risk Management Framework for DoD Systems Every DoD component is bound: the military departments, combatant commands, defense agencies, field activities, and the Office of the Secretary of Defense.
Platform IT is easy to overlook. It covers the hardware and software integrated into a weapons platform, vehicle, or piece of equipment, such as avionics in a fighter or fire-control on a destroyer. Facility-related control systems on installations, like building automation and utility monitoring, are also treated as Platform IT and must go through RMF and obtain authorization before connecting to the DoD network.6SERDP-ESTCP. Cybersecurity
Organizations outside the DoD that connect to the Defense Information Network are subject to the same security standards. The Defense Information Systems Agency tracks connection authorizations and can issue a disconnect order for systems that fall out of compliance, ultimately severing the connection permanently if corrective actions are not taken.7Defense Information Systems Agency. DISN Connection Process Guide
One boundary worth knowing: if you are a defense contractor storing Controlled Unclassified Information on your own systems, your compliance track is the Cybersecurity Maturity Model Certification, not RMF. The two frameworks share controls from NIST SP 800-53, but they apply to different populations, and CMMC is far more rigid about residual risk. RMF documentation does not automatically satisfy CMMC without a gap analysis.8DoD CIO. About CMMC
Categorizing the System and Selecting Controls
Before any controls are picked, the system is categorized under FIPS 199, the federal standard for rating sensitivity. The process assigns low, moderate, or high impact ratings across three objectives: confidentiality, integrity, and availability. Low means limited harm from a breach, moderate means serious harm, and high means severe or catastrophic consequences.9National Institute of Standards and Technology. FIPS PUB 199 – Standards for Security Categorization of Federal Information and Information Systems The overall categorization takes the highest single rating, so a system rated low for confidentiality and integrity but high for availability is treated as high-impact throughout.
The System Owner then selects controls from NIST SP 800-53, Revision 5, organized into families like access control, audit and accountability, incident response, and system protection.10National Institute of Standards and Technology. NIST Special Publication 800-53 Revision 5 – Security and Privacy Controls for Information Systems and Organizations The impact level sets the baseline; tailoring adds controls for specific threats and removes ones that do not apply. Each control is allocated as system-specific (implemented by the owner), common (inherited from a provider), or hybrid.1Department of Defense. DoD Instruction 8510.01 – Risk Management Framework for DoD Systems Claiming inheritance for a control nobody is actually providing creates a gap that surfaces at assessment.
This all feeds into the System Security Plan, the blueprint that documents every control, how it is implemented, and who owns it. The Security Assessment Plan alongside it lays out exactly how each control will be tested. Templates for both live on the RMF Knowledge Service, a DoD resource that requires a Common Access Card to reach.11Center for Development of Security Excellence. Course Resources for Introduction to the Risk Management Framework CS124.16 Both plans depend on a detailed inventory of every server, workstation, network device, and software version inside the system boundary.
Supply chain risk feeds into control selection as well. NIST SP 800-161, Revision 1, provides the methodology for identifying supply chain threats (compromised components, malicious code, counterfeit parts) and integrating mitigations into the framework rather than prescribing a fixed checklist.12National Institute of Standards and Technology. NIST SP 800-161 Rev 1 – Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
How the Authorization Decision Gets Made
With the package assembled, most DoD organizations submit it through the Enterprise Mission Assurance Support Service (eMASS), a government-owned web application managed by DISA. eMASS moves the package through an approval chain, records every reviewer action, and enforces business rules that keep an incomplete package from reaching the AO.3Defense Counterintelligence and Security Agency. NISP eMASS Industry Operation Guide
The Security Control Assessor examines the evidence and tests controls against the plan. When a control is not compliant, the System Owner has two options: fix it before the decision, or document it in a Plan of Action and Milestones, or POA&M. The POA&M spells out the vulnerability, the planned remediation, and the timeline.1Department of Defense. DoD Instruction 8510.01 – Risk Management Framework for DoD Systems Every non-compliant control must have a POA&M item before the package advances. The assessor’s findings are compiled into a Security Assessment Report that goes to the AO.
The AO reviews the security plan, the assessment report, and the POA&M items, then issues one of the following:
- Authorization to Operate (ATO). Full approval to operate, typically valid for three years assuming no major changes to the system’s security posture.13Carnegie Mellon University Software Engineering Institute. Risk Management Framework and Authority to Operate
- Denial of Authorization to Operate (DATO). The risk is unacceptable and the system cannot connect until the problems are resolved and a new assessment is completed.3Defense Counterintelligence and Security Agency. NISP eMASS Industry Operation Guide
- Interim Authority to Test (IATT). Limited, temporary network access for testing and evaluation purposes only.
Life After Authorization
Receiving an ATO is not the finish line. The current instruction emphasizes ongoing authorization, where the AO continuously evaluates risk based on monitoring results rather than waiting for a full reauthorization every three years.1Department of Defense. DoD Instruction 8510.01 – Risk Management Framework for DoD Systems The AO communicates changes in risk determinations and can downgrade or revoke authorization at any point.
Continuous monitoring covers regular vulnerability scans, configuration checks, and assessment of a rotating subset of controls. Certain events trigger a reassessment outside the normal cycle: significant configuration changes, new threat intelligence, spikes in detected vulnerabilities, or shifts in risk assessment findings.14National Institute of Standards and Technology. Ongoing Authorization Automated tools produce the reports, but someone still has to review the output and act on findings. A system whose POA&M items pile up unremediated is heading toward a revoked authorization.
Reciprocity Between Components
A system already authorized by one DoD component should not have to repeat the entire process for another. The DoD Cybersecurity Reciprocity Playbook defines reciprocity as the reuse of capabilities proven secure within the DoD.15DoD CIO. DoD Cybersecurity Reciprocity Playbook Because every component follows the same RMF, they produce standardized artifacts a receiving organization can review and accept.
In practice, this works through reuse of existing RMF artifacts. eMASS includes a reciprocity search function that helps organizations find and leverage existing authorizations. For cloud services, the DoD maintains reciprocity with FedRAMP for systems processing Impact Level 2 data found on the FedRAMP Marketplace. For higher impact levels, the DoD can issue its own Provisional Authorization, and the mission AO determines whether the cloud service meets the requirements for the data involved.15DoD CIO. DoD Cybersecurity Reciprocity Playbook Disputes between components are escalated to the DoD CIO.
A Faster Path for Software: SWIFT
The traditional RMF authorization process has drawn persistent criticism for taking too long to approve commercial software warfighters need. In response, the DoD launched the Software Fast Track (SWIFT) program in May 2025. Vendors submit a software bill of materials from both production and sandbox environments, along with a third-party certified SBOM, and upload the artifacts into eMASS. AI tools evaluate the submissions against 12 risk characteristics spanning financial operations through cybersecurity posture, and provisional authorizations issue far faster than under the conventional route.
SWIFT does not replace RMF. It offers an alternative for software that meets specific criteria, prioritizing secure-by-design principles, zero trust architecture, and continuous monitoring. Legacy platforms, weapons systems, and complex enterprise architectures still run through the full RMF process.
Time and Cost to Expect
Underestimating time and money is the most common mistake. Documentation alone can take months for a moderately complex system, especially if the boundary is poorly defined or the hardware and software inventory is incomplete. Assessment for a straightforward system might run 90 days. For a high-impact system with hundreds of controls, six months or longer is realistic.
Professional training for RMF practitioners typically runs several thousand dollars for a five-day bootcamp. An independent third-party assessment organization costs significantly more, with fees scaling to system complexity, the number of controls in scope, and testing depth. Organizations that skip experienced help often find the rework from a failed assessment costs more than the consulting would have.
The biggest hidden cost is labor. Every step requires someone to write, review, test, and maintain documentation. System Owners who treat this as a part-time responsibility alongside operational duties produce weaker packages and face longer authorization timelines. The smoothest RMF experiences belong to organizations that staff it like a project from day one.