// Capability Statement — Download PDF
Insights / CSRMC
DoD Cyber

CSRMC: the Pentagon's plan to retire the RMF.

The Cybersecurity Risk Management Construct trades snapshot authorizations for continuous, automated defense across five lifecycle phases. What changes, what doesn't, and who's positioned for it.

In late September 2025 the Department of Defense announced the Cybersecurity Risk Management Construct (CSRMC) — its plan to retire the Risk Management Framework as the way DoD systems get and keep authorization. The pitch, in the Department's own framing: move from static, checklist-driven, point-in-time assessments to dynamic, automated, continuous risk management — "cyber defense at the speed of relevance." Rollout guidance has been developing through 2026.

Why the RMF lost the room

The RMF's six steps produced authorizations that were snapshots: controls verified once, documented in sprawling packages, then left to decay until reauthorization. Timelines of 12–18 months were normal. The paperwork measured compliance at a moment; adversaries operate continuously. Every practitioner has lived the gap between a beautiful SSP and an actually-defended system.

The construct: five phases, built-in security

PhaseWhat security looks like there
DesignRequirements and architecture carry security from day one
BuildHardened pipelines; evidence generated by tooling, not typed into documents
TestContinuous validation and adversarial testing, not a one-time assessment event
OnboardAuthorization decisions fed by live telemetry
OperationsContinuous monitoring as the default posture — the cATO mindset made standard

Underneath the phases sit tenets the Department has emphasized: automation everywhere evidence is produced, continuous monitoring and authorization, DevSecOps as the delivery model, cyber survivability of fielded systems, and reciprocity — authorize once, use across the enterprise instead of re-adjudicating the same system in every enclave.

What changes for programs — and what doesn't

Changes: the center of gravity moves from documents to pipelines. Evidence that regenerates itself — scans, control checks, telemetry — becomes the currency of authorization, and continuous ATO stops being an exotic achievement and becomes the expected end state. Doesn't change: NIST 800-53 controls still sit underneath; existing ATOs don't evaporate; and CSRMC governs DoD systems — it is separate from CMMC, which remains the compliance regime for contractors handling FCI and CUI.

Our take

CSRMC rewards exactly the posture the accelerated-ATO playbook builds: inherited controls, automated evidence collection, and monitoring wired in from the first sprint. Programs that treated the RMF as a paperwork exercise will feel this shift hardest; programs that engineered their compliance will barely feel it at all.

Quick answers

Does CSRMC cancel my current ATO?
No. Existing authorizations carry forward while the Department transitions. What changes is the expectation for how systems demonstrate risk posture going forward — continuous, automated evidence rather than periodic reauthorization packages.
Is CSRMC just continuous ATO by another name?
Continuous authorization is a core tenet, but CSRMC is broader: it restructures how security is built across the full lifecycle — design, build, test, onboard, operations — with automation and reciprocity as first-class requirements.
Does CSRMC replace CMMC?
No. CSRMC governs how DoD authorizes and defends its own systems. CMMC remains the separate compliance regime for defense contractors handling federal contract information and CUI.
Put this to work

Need it done, not just explained?

This is the work we do every day. Tell us where your program stands and we'll give you a straight answer.

Talk to Ausper