The Gap Between ConMon and cATO
Last reviewed
AdvancedWhat you'll learn
~18 min- Distinguish operating continuous-monitoring machinery from holding a continuous authorization
- Assess a real program against the platform/process/people criteria without flattery
- Write the honest gap statement that a continuous-authorization pursuit actually starts from
The spine, measured
Lesson 1.1 planted this training’s spine as a promise: at the end, we’d measure the distance between the machinery you’ve built and the authorization model the field is heading toward. Time to pay it, with the reference shop as the honest ruler — because its situation is the field’s situation, and pretending otherwise is how programs waste two years.
The reference shop runs, today, most of what this training taught: the schema-gated catalog (2.1), human statements with evolution matrices (2.2), deterministic exports (2.3), operating collectors with strict verdicts (3.1), a defensible store (3.2), generated documents (3.3). Weekly full collection runs, daily drift checks, freshness tracked as a first-class property. By any reasonable reading, that’s continuous monitoring, genuinely operating. And its authorization? Point-in-time. A conditional ATO maturing toward a full ATO on a deadline, with quarterly manual reassessment. The conmon machinery feeds the quarterly ritual; it does not replace it.
Hold that picture, because it kills the two comforting errors at once:
ERROR 1 (the vendor slide): "run the machinery and you have cATO" - false: the machinery is NECESSARY, nowhere near SUFFICIENT; authorization is granted to the triad (4.2), and the shop has one leg of three
ERROR 2 (the cynic's shrug): "cATO is marketing; quarterly is reality" - also false: environments hold real cATOs today (4.2); the model works where all three legs got built - the shop's gap is a DISTANCE, not a mythMeasuring the distance with the criteria
The May-2024 evaluation criteria (4.2’s triad) turn “how far are we?” from a mood into an audit. Run each leg against what the reference shop can demonstrate:
Platform — closest leg. Continuous visibility exists (collectors, drift, freshness). But look at 3.1’s honest accounting through a cATO lens: 35 of 84 controls fully graded, operator evidence stored-not-evaluated, and the assessment-report path partly manual. Continuous authorization means the authorization-relevant signal is continuous — coverage gaps that a quarterly ritual papers over become load-bearing at continuous cadence.
Process — the delivery pipeline is real (Module 5 ships through it), but the authorization workflow itself is quarterly-shaped: evidence flows in continuously, then waits for humans to assemble, review, and re-accept on a calendar. The package updates when people push it, not when evidence arrives. (Closing exactly this is Lesson 6.2.)
People — the least-built leg, and the one programs skip in slides: cATO’s criteria assess whether the team — training, staffing, operational ownership — can sustain the model. A quarterly ritual tolerates a compliance team that surges four times a year; continuous authorization is an operations model, staffed like one, with the AO’s relationship changing from signing events to supervising a stream. (Authorization-as-stream is the pattern name this field uses; 6.4 sequences the org change it implies.)
The honest gap statement
The deliverable this lesson adds to your package — one page, versioned, updated as the distance closes:
Draft our continuous-authorization gap statement from: the coverageaccounting (coverage.md), the catalog, our assessment-cycle records,and the team roster/on-call data. Structure:1) WHAT WE OPERATE: the conmon machinery, by module - with coverage numbers, not adjectives;2) WHAT WE HOLD: our actual authorization model, cadence, and the manual steps between evidence and re-acceptance - drawn as a pipeline with the human gates marked;3) THE DISTANCE, per criteria leg: platform / process / people - each with its two or three blocking gaps, named and owned;4) WHAT WE ARE NOT CLAIMING: the sentence leadership will be tempted to delete - we operate continuous monitoring; we do not hold a continuous authorization - kept in.No aspiration verbs in sections 1-2. Section 3 may use 'requires'.Section 4 is the document’s spine. Every reviewer of this training’s reference material lands on the same observation: the shop’s credibility comes precisely from stating its point-in-time reality while operating better machinery than shops that claim more. That’s Lesson 3.1’s warts-out-loud principle at program scale — and it’s what an AO, whose entire function is calibrated trust (1.1), actually rewards.
Programs that claim continuous prematurely get audited back to reality at the worst moment - mid-assessment, credibility spent, timeline blown. Programs that state the quarterly truth and show the machinery closing the gap get something better than belief: they get their CLAIMS pre-verified, because every claim was calibrated to evidence. In a domain where the currency is an AO’s trust, the honest gap statement is not modesty - it is the highest-yield document in the package.
Meridian leadership, reading the gap statement draft, pushes back on section 4: 'We run collectors daily - saying we do not hold continuous authorization undersells us to the receiving program.' What is the correct response?
Key takeaway
Operating continuous monitoring and holding continuous authorization are different facts, and the reference shop proves a program can excel at the first while honestly holding the second at quarterly cadence. Measure your distance with the triad — platform (coverage, honestly counted), process (where humans gate the evidence-to-acceptance path), people (staffed as operations, not surge) — and publish the gap statement with the sentence leadership wants deleted kept in. The machinery earns trust only when its claims are calibrated. Next: shrinking the process leg — wiring the pipeline to the package itself.