The Cybersecurity Risk Management Construct trades snapshot authorizations for continuous, automated defense across five lifecycle phases. What changes, what doesn't, and who's positioned for it.
In late September 2025 the Department of Defense announced the Cybersecurity Risk Management Construct (CSRMC) — its plan to retire the Risk Management Framework as the way DoD systems get and keep authorization. The pitch, in the Department's own framing: move from static, checklist-driven, point-in-time assessments to dynamic, automated, continuous risk management — "cyber defense at the speed of relevance." Rollout guidance has been developing through 2026.
The RMF's six steps produced authorizations that were snapshots: controls verified once, documented in sprawling packages, then left to decay until reauthorization. Timelines of 12–18 months were normal. The paperwork measured compliance at a moment; adversaries operate continuously. Every practitioner has lived the gap between a beautiful SSP and an actually-defended system.
| Phase | What security looks like there |
|---|---|
| Design | Requirements and architecture carry security from day one |
| Build | Hardened pipelines; evidence generated by tooling, not typed into documents |
| Test | Continuous validation and adversarial testing, not a one-time assessment event |
| Onboard | Authorization decisions fed by live telemetry |
| Operations | Continuous monitoring as the default posture — the cATO mindset made standard |
Underneath the phases sit tenets the Department has emphasized: automation everywhere evidence is produced, continuous monitoring and authorization, DevSecOps as the delivery model, cyber survivability of fielded systems, and reciprocity — authorize once, use across the enterprise instead of re-adjudicating the same system in every enclave.
Changes: the center of gravity moves from documents to pipelines. Evidence that regenerates itself — scans, control checks, telemetry — becomes the currency of authorization, and continuous ATO stops being an exotic achievement and becomes the expected end state. Doesn't change: NIST 800-53 controls still sit underneath; existing ATOs don't evaporate; and CSRMC governs DoD systems — it is separate from CMMC, which remains the compliance regime for contractors handling FCI and CUI.
CSRMC rewards exactly the posture the accelerated-ATO playbook builds: inherited controls, automated evidence collection, and monitoring wired in from the first sprint. Programs that treated the RMF as a paperwork exercise will feel this shift hardest; programs that engineered their compliance will barely feel it at all.
This is the work we do every day. Tell us where your program stands and we'll give you a straight answer.
Talk to AusperThis site uses essential browser storage only. With your OK, we’d also use analytics cookies to understand which content is useful. No choice is required — “Essential only” changes nothing. Cookie policy