Over the last decade, the Department of Defense (DoD) has relied on a foundational process to ensure its information systems are secure: the Risk Management Framework (RMF). Think of it as the official cybersecurity rulebook (formally, NIST SP 800-37). This six-step process (Categorize, Select, Implement, Assess, Authorize, and Monitor) provided a standardized, repeatable blueprint for building and managing secure systems. Historically, its role was critical. It acted as a gatekeeper, ensuring technology met a rigorous security standard before being deployed on the battlefield or in a mission-critical environment.
A Changing World Demands a New Approach
The RMF was designed for a world of defined network perimeters, a digital fortress with a strong wall. But our world has changed. Today’s challenges include:
- A Dissolved Perimeter: With cloud computing, remote work, and mobile devices, there is no longer a clear “inside” and “outside” of the network.
- Accelerated Timelines: Agile and DevOps practices demand speed, but a lengthy, static Authorization to Operate (ATO) process often becomes a bottleneck. This tendency toward “analysis paralysis” is precisely why the Pentagon is advancing initiatives like the Software Fast Track (SWFT) program, which aims to use automation to accelerate accreditation. As acting DoD CIO Katie Arrington explained, “AI tools on the back end will analyze the data. If everything meets the requirements for a digital ATO, we won’t have to wait on a human to review it.”
- Sophisticated Threats: Adversaries now assume they can breach the perimeter, using tactics like stolen credentials to move laterally within a network.
This new reality is why we also heard Arrington declare during a virtual INSA Coffee & Conversation session on June 5, 2025, “We’re blowing up the RMF.” The statement isn’t about demolition; it’s about a necessary evolution. We must adapt by removing bottlenecks to facilitate speed, automation, and continuous authorization.
The Modern Solution: Integrating Zero Trust Architecture (ZTA)
If the old model of a fortified perimeter is obsolete, what replaces it? The answer lies in a newer security mindset: Zero Trust. The framework for implementing this mindset is the Zero Trust Architecture (ZTA). This security model is built on a simple but powerful principle: “never trust, always verify.” It operates as if a breach is inevitable or has already occurred, eliminating the concept of a trusted internal network.
Key tenets of Zero Trust include:
- Identity-Centric Security: Strong authentication and authorization for every user and device.
- Microsegmentation: Dividing the network into small, isolated segments to contain potential breaches.
- Continuous Monitoring: Constantly verifying the security posture of all assets in real-time.
- Least Privilege Access: Granting only the minimum level of access required for a task.
Zero Trust, which never assumes a static secure posture, demands a modernized RMF with continuous authorization embedded in the accreditation framework. Underscoring this push for evolution, the DoD published a Request for Information (RFI) in June for a “Risk Management Framework (RMF) Revamp,” actively seeking industry input on how to modernize its foundational process for managing cyber risk.
A Powerful Partnership: How RMF and ZTA Work Together
Instead of replacing RMF, ZTA is layered on top of it, creating a powerful synergy. Think of RMF as the how (the structured process for managing risk) and ZTA as the what and why (the guiding security principles). This partnership was formalized through the DoD’s own Zero Trust Strategy and a Zero Trust Reference Architecture (ZTRA), which provided a clear roadmap for this integration. Ultimately, this alone was not enough to yield the desired results.
Reimagining Cyber Defense: Moving at the Speed of Relevance
On Sept 23rd, Arrington made good on her promise of change incorporating ZTRA. The introduction of the Cybersecurity Risk Management Construct (CSRMC) by the DoW marks a pivotal moment in the evolution of U.S. defense cybersecurity policy. It is a deliberate and forceful move away from established, but increasingly inadequate, compliance paradigms. The CSRMC is officially defined as a “transformative framework to deliver real-time cyber defense at operational speed”.
One may assume the RFI feedback received thus far was considered and resulted in the new CSRMC. It represents a direct response to the recognized deficiencies of the previous Risk Management Framework (RMF), which was widely seen as a slow, bureaucratic, and checklist-driven process that failed to meet the operational demands of modern warfare.
CSRMC Phase Description
The new CSRMC builds cybersecurity into DoW systems across the five phases of the systems development life cycle (SDLC) – design, build, test, onboard and operations. These phases map to RMF steps and related cybersecurity activities.
- Design: Security is embedded at the outset, ensuring resilience is built into system architecture. Prepare, Categorize, Select: Define functional, cybersecurity, and cyber survivability requirements, form the mission owner team, and select security controls.
- Build: Secure designs are implemented as systems achieve Initial Operating Capability. Implement security controls in code and configuration, conduct initial risk reviews, and validate critical controls.
- Test: Comprehensive validation and stress testing are performed prior to Full Operating Capability. Assess: Conduct formal cybersecurity assessments, perform penetration testing on high-risk systems, and remediate vulnerabilities.
- Onboard: Automated continuous monitoring is activated at deployment to sustain system visibility. Authorize: Deploy to production environments, fully onboard systems into the continuous monitoring program, and enable cATO (Continuous Authorization to Operate).
- Operations: Real-time dashboards and alerting mechanisms provide immediate threat detection and rapid response. Monitor: Connect to DODIN (Department of Defense Information Network), manage real-time risk via automated dashboards and alerts, and execute incident response playbooks.
The CSRMC Ten Strategic Tenets
Underpinning the five-phase lifecycle are ten foundational principles that define the “how” of the CSRMC. These strategic tenets are not sequential steps but rather a set of strategic imperatives that must be woven into the fabric of every phase of a system’s life.
- Automation: Automate to enhance risk management by streamlining processes, reducing human error, and improving efficiency.
- Critical Controls: Adhere to identified critical controls, and adaptive recovery strategies strengthen defenses to ensure operational continuity and protect sensitive assets.
- Continuous Monitoring (CONMON) Control, and ATO: Provide real-time visibility into threats, vulnerabilities, and compliance gaps through continuous monitoring.
- DevSecOps: Integrate security and automation through continuous development, testing, and deployment to accelerate delivery safely.
- Cyber Survivability: Safeguard against cyber threats, disruptions, and data breaches through strong encryption, multi-factor authentication, continuous monitoring, and incident response planning.
- Training: Enhance role-based training program for RMF practitioners to ensure consistent performance, cybersecurity knowledge, and standards.
- Enterprise & Inheritance: Share security controls, policies, or risks to increase adoption proven frameworks, reduce compliance burdens, and maintain operational consistency.
- Operationalization: Strengthen our defense against evolving threats through threat detection, incident response, compliance management, and proactive monitoring.
- Reciprocity: Accept each other’s security assessments to reuse system resources and/or to accept each other’s assessed security posture to share information.
- Cybersecurity Assessments: Establish comprehensive cybersecurity assessment programs that integrate threat-informed testing methodologies with mission-aligned risk management processes.
Automation is arguably the most critical tenet, focused on enhancing risk management by “streamlining processes, reducing human error, and improving efficiency”. It is the primary enabler for achieving the speed and scale required by the CSRMC.
Getting Started: Key Considerations for Your Program
As RMF and ZTA converge and the specifics of the new CSRMC are formalized, program managers should adopt best practices by asking critical questions to prepare:
- Identity and Access Management (IAM): Is our current IAM solution robust enough to serve as the foundation of a Zero Trust environment?
- Data Visibility: Do we have the tools for continuous monitoring and validation of data access across our entire network, including cloud and legacy systems?
- Training and Awareness: Have we provided adequate training to ensure all personnel understand the importance of this new security model and their role within it?
- Phased Implementation: What is a practical pilot program we can launch to demonstrate value and build momentum without disrupting the entire mission?
Answering these questions is the first step toward building a realistic and effective implementation roadmap as we anxiously await formal DoW directives. While the rollout of CSRMC may take years, it’s important for defense contractors and organizations within the DIB (Defense Industrial Base) to start preparing now.
Navigating the Road Ahead: Challenges to Implementation
This strategic shift is not without its hurdles. Successfully navigating them requires careful planning and expertise.
- Legacy Systems: Most agencies can’t afford a “rip-and-replace” approach. Integrating CSRMC with legacy systems requires a pragmatic, phased modernization strategy that prioritizes the most critical assets first.
- Cultural Shift: Adopting CSRMC requires a significant change in mindset away from the traditional “trusted network” assumption. This underscores the need for clear communication and robust change management.
- Complexity & Skills: Implementing CSRMC architecture across a vast IT environment is inherently complex. It demands a workforce with modern security skills, including not just technical expertise but also crucial soft skills like communication and collaboration.
- Cost: Implementing CSRMC can be expensive, as it often requires investment in new technologies and processes.
Navigate Your CSRMC Journey with SMS
The evolution from traditional RMF to the CSRMC framework presents significant challenges and opportunities. Having a partner with deep experience in both DoD compliance and cutting-edge cybersecurity is essential for success.
At SMS, we specialize in helping government organizations navigate this complex landscape. Our team of cleared experts provides strategic guidance and hands-on support to build secure, compliant, and mission-ready systems.
Ready to modernize your security posture and streamline your cATO process? Contact us today for a strategic assessment.
2 Responses
Well written. I’m looking forward to anything that streamlines the byzantine collection of controls and processes that current makes RMF the equivalent of trying to run a marathon with concrete shoes. Hopefully we see this framework deployed soon and that makes our collective lives easier.
Excellent emphasis on the purpose and use case of ZTA. Zero trust has been thrown around for a long time as a buzzword, without much clarification as to the how and why it should be implemented.
Looking forward to seeing more cybersecurity articles.
This is well written. However, This is what the RMF process was supposed to be in the first place. It has been for many years. The problem is that people turned it in to a checklist and left everything up to interpretation. I have personally worked with an application team and produced an ATO from start to finish in a week. We worked on it continuously and had the cooperation of everyone involved. It is possible in the current, well Rev4 version, of the system. This was for a legacy system so it did not have a lot of things like ZTA built in but, it can still be done with the existing environment if you just use common sense and have the technical know how. Micro segmentation helped a lot.
I do not see anything in your article that is not already included in RMF, nor do I see anything being removed. It is just putting things to work the way they are intended. RMF has been around and evolving for longer than I can remember (I have been involved in it for over 20 years). What you are talking about is just implementing it as intended and it finally getting enforced. Without the enforcement all of the cybersecurity staff have just been left out hanging in the wind.
ZTA has also been a requirement for many years. It too, has just been something that was unfunded and not enforced.
All of this goes back to the old adage, “Talk is Cheap, Action costs money.”
Thank you for the updated perspective and the information saying it is finally going to get enforced.