Register:Mechanism/ATO6 recordsSHA3-256 chainedSealed head sha3:88486cfbf9793fbc4aadf07134b631a312fab8f5c55567154a5c9912137b4ac5Intact

Register / Mechanism / ATO packaging

The package is a projection of the record.

An authorization decision is a claim about a system as of a date. PolicyCortex generates the SSP, SAR and POA&M from one implementation record kept on the hash chain in your tenant, exports the package as OSCAL 1.1.2 with eMASS XML and evidence indexes, and regenerates it to any timestamp inside retention, so the authorizing official can enumerate what changed.

Exhibit A-1continuous ato, as shipped
The PolicyCortex continuous ATO workspace: authorization lifecycle, passing-control posture, open POA&Ms, evidence artifacts, and six live collections

Exhibit A-1 · the authorization workspace: lifecycle, posture, POA&Ms, and six live collections. Illustrative demo data; the interface is real.

REC 0000ONE RECORDsha3-2563d7b658e097aaa8e334df1ae2093453e626749b45f04422210a69493e75ee455prev:339a9a3d41df

One implementation record, several shapes.

The documents assessors ask for are projections of this record, not parallel artifacts maintained by hand. SSP, POA&M, and SAR generate from one implementation record, and the package exports as OSCAL 1.1.2. The same record ships in assessor handoff shape for the eMASS and C3PAO exchange, and in program-office shapes for federal environments. The document is never the source. The chain is.

ssp
The System Security Plan, in NIST SP 800-18 r1 structure, generated from the implementation record rather than authored beside it.
sar
The Security Assessment Report, per NIST SP 800-53A, generated from the same record.
poam
The Plan of Action and Milestones: open gaps by family and severity, each with an owner and a remediation path.
oscal
OSCAL 1.1.2 JSON, native. Machine readable by construction; the format FedRAMP 20x asks for.
emass
eMASS XML, the assessor handoff shape for the eMASS and C3PAO exchange. The OSCAL package is C3PAO-agnostic; it does not lock you to an assessor.
conmon.record
The continuous monitoring record: append-only JSONL, hash chained, seven-year retention, regenerable to any timestamp.
evidence.index
The index of evidence artifacts behind every control, each with its content hash and capture time.
package
One ZIP carrying all of the above: inventory, validations, POA&M, SSP, SAR. Hash chained, AES-256 protected.

See alsoProof of state, where the rows come fromThe export surface in the architecture

REC 0001AS OFsha3-25689f39801be7f5e623f86312819aa59f48d6847e627bc6811a33c8cac122c0c31prev:3d7b658e097a

Regenerable to the date the authorizing official signed.

An authorization decision is a claim about a system as of a date. The record regenerates to any historical timestamp, so the package your authorizing official signed and the package you hold today differ only by rows you can enumerate. Chain verification tells both of you whether anything was edited after the fact.

Continuous authorization records are the same rows in a different envelope. When a collector was down or a scope was unobserved, the package says so: a declared gap with interval and reason, never silently fewer rows.

package regenerationtwo runs of the same export; values illustrative, shapes real
$ pcx export package as-of=2026-05-14
implementation  one record, head sha3:2f8ce1a90b47
projections     ssp  sar  poam  oscal-1.1.2.json  emass.xml  evidence-index
gaps            1 declared (interval and reason on record)
verify          INTACT

$ pcx export package as-of=2026-08-31
delta           rows added since 2026-05-14, enumerated by sequence number
edited.rows     0   (an edit would read BROKEN at the first failing seq)

See alsoProof of change, where edits become visibleDeclared gaps

REC 0002LIFECYCLEsha3-2568497825ad5a0c7106c61d99cd0beac4edcd947ea556eb02dc8ff90de8eda6538prev:89f39801be7f

From scope to 3PAO assessment.

One authorization package, tracked from scope through 3PAO assessment. The rows below are where assessors expect to find what the record produces; the record is the product.

NIST 800-53
CA-7 continuous monitoring from point-in-time records; AU-9 and AU-10 from the chain itself; CM-3, AC-6, SI-4. SSP and SAR generated, not authored.
NIST 800-171 / CMMC Level 2
One evidence base for the 110 requirements, handed to the assessor as generated evidence with the raw payload attached.
FedRAMP 20x
Machine-readable by construction; exports as OSCAL 1.1.2 rather than as documents transcribed from screenshots.
eMASS / C3PAO
The handoff package: what the assessor receives and how they verify it by hash.
Exhibit A-2ato collection, as shipped
A PolicyCortex ATO collection overview: passing controls, six-stage lifecycle from scope to 3PAO assessment, control family coverage, and package readiness

Exhibit A-2 · one authorization package from scope to 3PAO assessment: passing controls, family coverage, next action. Illustrative demo data; the interface is real.

See alsoThe eMASS and C3PAO handoffThe federal record

REC 0003BOUNDARIESsha3-256d1d2cbd055a180a15711c4a785c9515c5ee8e8bbd3d0cdf9eccfca8857f6648aprev:8497825ad5a0

Which boundaries.

AWS and Azure boundaries are supported for ATO packaging, including AWS GovCloud and Azure Government; the software also runs inside GCC High. GCP support covers governance, remediation, and control-linked evidence, not an ATO workflow. On-premises delivery for air-gapped environments is available.

Where each component runs and what it can reach is stated in the architecture.

REC 0004QUESTIONSsha3-2567db58a5548ef2689aa6e93ee6076abeebce48472711af2545e1b858381923ba5prev:d1d2cbd055a1

Four questions program offices ask.

  1. Q-01

    What is in the package?

    The SSP, the SAR, the POA&M, the OSCAL 1.1.2 JSON, the eMASS XML, and the evidence indexes, generated from one implementation record and shipped as one ZIP, hash chained and AES-256 protected.

  2. Q-02

    Which clouds are supported for ATO packaging?

    AWS and Azure boundaries, including AWS GovCloud and Azure Government; the software also runs inside GCC High. GCP is observed for governance, remediation, and control-linked evidence, but an ATO workflow for GCP is not offered.

  3. Q-03

    Can the package be regenerated as of a past date?

    Yes. Retention is seven years and the record regenerates to any historical timestamp inside it, so the package as of the day the authorizing official signed is a parameter you pass, not an archive you search.

  4. Q-04

    Does PolicyCortex authorize or certify the system?

    No. The authorizing official remains the authority on what operates and the assessor remains the authority on what passes. PolicyCortex produces the records those decisions rest on, and no certification is guaranteed.

REC 0005STATED LIMITsha3-25688486cfbf9793fbc4aadf07134b631a312fab8f5c55567154a5c9912137b4ac5prev:7db58a5548ef

What this page is not.

Hand the assessor a package built to be verified.

Request verification
Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000ONE RECORD3d7b658e097a339a9a3d41df
REC 0001AS OF89f39801be7f3d7b658e097a
REC 0002LIFECYCLE8497825ad5a089f39801be7f
REC 0003BOUNDARIESd1d2cbd055a18497825ad5a0
REC 0004QUESTIONS7db58a5548efd1d2cbd055a1
REC 0005STATED LIMIT88486cfbf9797db58a5548ef

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:88486cfbf979. The product does the same thing to your evidence.

Photograph: U.S. Department of Energy, Public domain (U.S. Department of Energy, 17 U.S.C. 105). Source