sha3:88486cfbf9793fbc4aadf07134b631a312fab8f5c55567154a5c9912137b4ac5IntactRegister / Mechanism / ATO packaging
The package is a projection of the record.
An authorization decision is a claim about a system as of a date. PolicyCortex generates the SSP, SAR and POA&M from one implementation record kept on the hash chain in your tenant, exports the package as OSCAL 1.1.2 with eMASS XML and evidence indexes, and regenerates it to any timestamp inside retention, so the authorizing official can enumerate what changed.

Exhibit A-1 · the authorization workspace: lifecycle, posture, POA&Ms, and six live collections. Illustrative demo data; the interface is real.
3d7b658e097aaa8e334df1ae2093453e626749b45f04422210a69493e75ee455prev:339a9a3d41dfOne implementation record, several shapes.
The documents assessors ask for are projections of this record, not parallel artifacts maintained by hand. SSP, POA&M, and SAR generate from one implementation record, and the package exports as OSCAL 1.1.2. The same record ships in assessor handoff shape for the eMASS and C3PAO exchange, and in program-office shapes for federal environments. The document is never the source. The chain is.
- ssp
- The System Security Plan, in NIST SP 800-18 r1 structure, generated from the implementation record rather than authored beside it.
- sar
- The Security Assessment Report, per NIST SP 800-53A, generated from the same record.
- poam
- The Plan of Action and Milestones: open gaps by family and severity, each with an owner and a remediation path.
- oscal
- OSCAL 1.1.2 JSON, native. Machine readable by construction; the format FedRAMP 20x asks for.
- emass
- eMASS XML, the assessor handoff shape for the eMASS and C3PAO exchange. The OSCAL package is C3PAO-agnostic; it does not lock you to an assessor.
- conmon.record
- The continuous monitoring record: append-only JSONL, hash chained, seven-year retention, regenerable to any timestamp.
- evidence.index
- The index of evidence artifacts behind every control, each with its content hash and capture time.
- package
- One ZIP carrying all of the above: inventory, validations, POA&M, SSP, SAR. Hash chained, AES-256 protected.
See alsoProof of state, where the rows come fromThe export surface in the architecture
89f39801be7f5e623f86312819aa59f48d6847e627bc6811a33c8cac122c0c31prev:3d7b658e097aRegenerable to the date the authorizing official signed.
An authorization decision is a claim about a system as of a date. The record regenerates to any historical timestamp, so the package your authorizing official signed and the package you hold today differ only by rows you can enumerate. Chain verification tells both of you whether anything was edited after the fact.
Continuous authorization records are the same rows in a different envelope. When a collector was down or a scope was unobserved, the package says so: a declared gap with interval and reason, never silently fewer rows.
$ pcx export package as-of=2026-05-14 implementation one record, head sha3:2f8ce1a90b47 projections ssp sar poam oscal-1.1.2.json emass.xml evidence-index gaps 1 declared (interval and reason on record) verify INTACT $ pcx export package as-of=2026-08-31 delta rows added since 2026-05-14, enumerated by sequence number edited.rows 0 (an edit would read BROKEN at the first failing seq)
See alsoProof of change, where edits become visibleDeclared gaps
8497825ad5a0c7106c61d99cd0beac4edcd947ea556eb02dc8ff90de8eda6538prev:89f39801be7fFrom scope to 3PAO assessment.
One authorization package, tracked from scope through 3PAO assessment. The rows below are where assessors expect to find what the record produces; the record is the product.
- NIST 800-53
- CA-7 continuous monitoring from point-in-time records; AU-9 and AU-10 from the chain itself; CM-3, AC-6, SI-4. SSP and SAR generated, not authored.
- NIST 800-171 / CMMC Level 2
- One evidence base for the 110 requirements, handed to the assessor as generated evidence with the raw payload attached.
- FedRAMP 20x
- Machine-readable by construction; exports as OSCAL 1.1.2 rather than as documents transcribed from screenshots.
- eMASS / C3PAO
- The handoff package: what the assessor receives and how they verify it by hash.

Exhibit A-2 · one authorization package from scope to 3PAO assessment: passing controls, family coverage, next action. Illustrative demo data; the interface is real.
d1d2cbd055a180a15711c4a785c9515c5ee8e8bbd3d0cdf9eccfca8857f6648aprev:8497825ad5a0Which boundaries.
AWS and Azure boundaries are supported for ATO packaging, including AWS GovCloud and Azure Government; the software also runs inside GCC High. GCP support covers governance, remediation, and control-linked evidence, not an ATO workflow. On-premises delivery for air-gapped environments is available.
Where each component runs and what it can reach is stated in the architecture.
7db58a5548ef2689aa6e93ee6076abeebce48472711af2545e1b858381923ba5prev:d1d2cbd055a1Four questions program offices ask.
- Q-01
What is in the package?
The SSP, the SAR, the POA&M, the OSCAL 1.1.2 JSON, the eMASS XML, and the evidence indexes, generated from one implementation record and shipped as one ZIP, hash chained and AES-256 protected.
- Q-02
Which clouds are supported for ATO packaging?
AWS and Azure boundaries, including AWS GovCloud and Azure Government; the software also runs inside GCC High. GCP is observed for governance, remediation, and control-linked evidence, but an ATO workflow for GCP is not offered.
- Q-03
Can the package be regenerated as of a past date?
Yes. Retention is seven years and the record regenerates to any historical timestamp inside it, so the package as of the day the authorizing official signed is a parameter you pass, not an archive you search.
- Q-04
Does PolicyCortex authorize or certify the system?
No. The authorizing official remains the authority on what operates and the assessor remains the authority on what passes. PolicyCortex produces the records those decisions rest on, and no certification is guaranteed.
88486cfbf9793fbc4aadf07134b631a312fab8f5c55567154a5c9912137b4ac5prev:7db58a5548efWhat this page is not.
Hand the assessor a package built to be verified.
Request verification