Policy says move faster. So why are ATO timelines still stalling mission software?政策要求加快进度。那么,为什么任务软件的ATO时间表仍然停滞不前?
As software becomes central to modern warfare, defense organizations are under pressure to modernize the authorization processes that determine how quickly capabilities reach the field.
sponsor content What's this?
As software becomes central to modern warfare, defense organizations are under pressure to modernize the authorization processes that determine how quickly capabilities reach the field.
Presented by Second Front Systems
Second Front Systems
Modern defense missions run on software. From weapons systems to logistics platforms to command and control, operational advantage is increasingly defined by the code systems run and the data they consume. As Secretary of War Pete Hegseth emphasized in a 2025 memorandum , “software is at the core of every weapon and supporting system we field to remain the strongest, most lethal fighting force in the world.”
That reality has elevated software delivery to a strategic priority. In the Department of War’s 2026 AI strategy , leadership explicitly called for “rapid ATO (Authorization to Operate) reciprocity,” signaling that the ability to quickly approve and reuse security authorizations is now considered mission-critical.
And yet, despite clear policy direction, the DOW continues to struggle to deliver software at speed.
At the center of that challenge is reciprocity.
In theory, reciprocity allows one organization to reuse another’s ATO, eliminating redundant security reviews and accelerating deployment. In practice, that promise remains largely unrealized.
Matt Conner, chief information security officer for Second Front Systems has seen this challenge first-hand. He spent more than 20 years in the DOW and intelligence community, including serving as CISO and Authorizing Official at the National Geospatial-Intelligence Agency and later as the Intelligence Community’s CISO under Avril Haines.
“There is a disconnect between what people expect about shortening these timelines and reciprocity and what’s actually happening,” said Conner.
In fact, Second Front commissioned GovExec Intelligence to conduct a blind survey of 200 DOW decision makers who are actively involved in the ATO process, which revealed 97% of respondents say increased use of reciprocity would improve ATO approval time. However, 44% think of presumptive reciprocity as largely “aspirational” and 9% think it’s impossible.
That disconnect persists even as policy has grown more explicit. The DOW has published guidance, including a reciprocity playbook , and Congress has reinforced the mandate through the National Defense Authorization Act , which enshrines presumptive reciprocity.
The authorization bottleneck we can’t afford
The GovExec Intelligence report revealed that traditional ATO timelines still range from 12 to 18 months or longer. Notably, none of the surveyed federal IT decision-makers reported authorization timelines under six months — even among organizations that say they are using reciprocity.
That’s a warning sign.
Every month spent reauthorizing systems that have already been vetted elsewhere delays fielding. It slows joint operations, fragments data environments and limits the Department’s ability to respond to rapidly evolving threats.
As Hegseth has noted, when the Department continues to apply hardware-era processes to modern software, “the warfighter pays the price.”
When it works, reciprocity enables software authorized in one environment to be rapidly deployed across the Army, Navy, Air Force, Marine Corps, Space Force and defense agencies — supporting interoperability and shared situational awareness. When it fails, each organization acts as an island, forcing teams to start from scratch.
Many decisions rely on personal relationships and ad hoc validation rather than standardized, repeatable workflows. And fragmented authorization environments across cloud, on-premises and SaaS systems make reuse even more difficult. In many cases, “reciprocity” still involves re-running large portions of the Risk Management Framework process, undermining its intended value.
“If we didn’t do it, I don’t trust it,” Conner said, describing a common mindset across agencies.
Modernizing reciprocity for the speed of mission
Overcoming these challenges requires more than policy mandates. It requires a shift in how the Department approaches risk, trust and speed.
“Successful reciprocity begins with leadership prerogative and commander’s intent to say ‘I want to go faster. I want to be more efficient. I want to reuse as a default, not as a fallback,’” Conner explained.
It also requires modernization.
“Reciprocity at the speed of relevance is automated,” he said. “It’s machines talking to machines… analyzing telemetry and actual indicators of security posture and presenting a provisional risk recommendation to a decision maker. It’s not sending spreadsheets and PDFs in email.”
Second Front is working to help drive that shift across the DOW. Through research, collaboration with policymakers and direct engagement with authorizing officials and program teams, the company is working to close the gap between reciprocity policy and operational reality. Plus, through their Game Warden platform , they are automating the security, compliance and deployment workflows that enable reciprocity in practice — helping software move across authorized environments without restarting the approval process from scratch.
For Conner, the goal is to equip warfighters with better visibility, automated tooling and standardized processes that allow them to make informed risk decisions faster. The broader mission is to help reduce deployment timelines from years to weeks so critical software can reach operators at the speed modern missions demand.
Because ultimately, the stakes are clear.
In an era of accelerating technological change and intensifying global competition, speed is a strategic advantage. Getting the best technology into the hands of warfighters faster, more securely and at scale depends on rethinking how software is authorized and deployed.
Reciprocity is a critical part of that transformation.
See how Second Front Systems is helping deploy and field capability to our warfighters.
This content is made possible by our sponsor Second Front Systems; it is not written by and does not necessarily reflect the views of Defense One ’s editorial staff.
NEXT STORY: The platform federal agencies trust: How Adobe Connect expands security for mission readiness and workforce transformation
赞助商内容 这是什么?
随着软件在现代战争中扮演越来越重要的角色,国防组织面临着对授权流程进行现代化改造的压力,这些流程决定了能力到达战场的速度。
由 Second Front Systems 呈现
第二战线系统
现代国防任务依赖于软件运行。从武器系统到后勤平台,再到指挥控制系统,作战优势越来越取决于系统运行的代码及其消耗的数据。正如美国陆军部长皮特·赫格塞斯在2025年的一份备忘录中强调的那样,“软件是我们部署的每一种武器和支持系统的核心,也是我们保持世界上最强大、最具杀伤力作战力量的关键所在。”
这一现实已将软件交付提升至战略优先事项的高度。在战争部2026年人工智能战略中,领导层明确呼吁“快速实现运行授权(ATO)互惠”,这表明快速批准和重复使用安全授权的能力如今被视为至关重要的任务。
然而,尽管政策方向明确,陶氏化学在快速交付软件方面仍然面临挑战。
这一挑战的核心在于互惠。
理论上,互惠机制允许一个组织重复使用另一个组织的授权运行许可 (ATO),从而避免重复的安全审查并加快部署速度。但实际上,这一愿景远未实现。
Second Front Systems 的首席信息安全官 Matt Conner 对此挑战有着切身体会。他曾在陶氏化学公司和情报界工作超过 20 年,包括担任国家地理空间情报局的首席信息安全官和授权官员,后来在 Avril Haines 的领导下担任情报界的首席信息安全官。
康纳说:“人们对缩短这些时间线和互惠的期望与实际发生的事情之间存在脱节。”
事实上,Second Front委托GovExec Intelligence对200位积极参与澳大利亚税务局(ATO)流程的道琼斯工业平均银行(DOW)决策者进行了一项匿名调查。调查结果显示,97%的受访者认为,更多地采用互惠原则将有助于缩短ATO的审批时间。然而,44%的受访者认为推定互惠原则在很大程度上只是“愿景”,另有9%的受访者认为这根本不可能实现。
即使政策日趋明确,这种脱节现象依然存在。美国国防部已发布指导意见,包括互惠政策手册,国会也通过《国防授权法案》强化了这一授权,该法案确立了推定互惠原则。
我们无法承受授权瓶颈带来的后果。
GovExec Intelligence 的报告显示,传统的授权运行 (ATO) 时间仍然长达 12 至 18 个月甚至更久。值得注意的是,所有受访的联邦 IT 决策者均表示,授权时间最长也达不到六个月——即使是那些声称采用互惠原则的机构也不例外。
这是一个警示信号。
每花一个月时间重新授权那些已经在其他地方经过验证的系统,都会延误部署。这会减缓联合行动,造成数据环境碎片化,并限制国防部应对快速演变的威胁的能力。
正如赫格塞斯所指出的那样,当国防部继续将硬件时代的流程应用于现代软件时,“最终付出代价的将是作战人员”。
互惠机制运作良好时,在一个环境中获得授权的软件可以快速部署到陆军、海军、空军、海军陆战队、太空军和国防机构,从而支持互操作性和共享态势感知。而一旦失效,每个组织都将孤立运行,迫使团队从头开始。
许多决策依赖于人际关系和临时验证,而非标准化的、可重复的工作流程。此外,云端、本地和SaaS系统之间分散的授权环境也使得重用更加困难。在许多情况下,“互惠”仍然需要重新运行风险管理框架流程的大部分内容,从而削弱了其预期价值。
“如果我们没做过,我就不会相信,”康纳说道,这反映了各机构普遍存在的这种心态。
为加快任务速度而实现互惠现代化
克服这些挑战需要的不仅仅是政策指令,还需要该部门转变其处理风险、信任和速度的方式。
康纳解释说:“成功的互惠始于领导层的特权和指挥官的意图,即‘我想加快速度。我想提高效率。我想把重复利用作为默认选项,而不是备选方案。’”
它还需要现代化改造。
他说:“这种以高度相关性为导向的互惠机制已经实现自动化。它是机器与机器之间的对话……分析遥测数据和安全态势的实际指标,并向决策者提交初步的风险建议。这不再是通过电子邮件发送电子表格和PDF文件。”
Second Front 致力于推动 DOW 的这一转变。该公司通过研究、与政策制定者合作以及与授权官员和项目团队的直接沟通,努力弥合互惠政策与实际操作之间的差距。此外,他们还通过其 Game Warden 平台,实现了安全、合规和部署工作流程的自动化,从而在实践中实现了互惠——帮助软件在授权环境中迁移,而无需从头开始重新审批流程。
对康纳而言,目标是为作战人员提供更清晰的视野、自动化工具和标准化流程,使他们能够更快地做出明智的风险决策。更广泛的使命是帮助将部署时间从数年缩短到数周,从而使关键软件能够以现代任务所需的速度交付给操作人员。
因为归根结底,利害关系很明确。
在技术变革加速、全球竞争日益激烈的时代,速度是一项战略优势。要更快、更安全、更大规模地将最先进的技术交付给作战人员,关键在于重新思考软件的授权和部署方式。
互惠是这种转变的关键组成部分。
了解一下第二战线系统如何帮助我们的作战人员部署和部署作战能力。
此内容由我们的赞助商 Second Front Systems 提供;它并非由 Defense One 编辑人员撰写,也不一定反映其观点。
下一篇报道:联邦机构信赖的平台:Adobe Connect 如何扩展安全性以提升任务准备和劳动力转型