---
title: "Federal R&D: Continuous ATO Evidence"
description: "Continuous ATO for FFRDCs and federal research programs: NIST 800-53 Rev 5 evidence hash chained in your enclave, OSCAL 1.1.2 output, air-gap capable."
url: https://policycortex.com/solutions/federal-rd
sealed: 2026-09-02
amended: 2026-09-16
register: solutions/federal-rd
records: 6
digest: sha3:61cb91e052e7a1248afb5c8bd1a15b60873fe88290c622f15edf541e7bd70ebc
---

# Continuous ATO for federally funded research.

NIST SP 800-53 Rev 5 / OSCAL 1.1.2 / air-gap capable

FFRDCs, national laboratories, and university-affiliated research programs run on perpetual authorization cycles. PolicyCortex records every NIST SP 800-53 Rev 5 control implementation in the boundary as hash-chained evidence, generates the SSP, POA&M, and SAR from that record, and exports OSCAL 1.1.2, inside the enclave and, where the enclave is air gapped, on premises.

[Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

Access is reviewed. Scope and onboarding are agreed with your team.

## What a research enclave's authorization asks you to prove

Research computing changes faster than an authorization package can be rewritten: new instruments, new collaborators, new data-use agreements, new hosts inside the boundary. The authorizing official still signs a claim about the system as of a date, and the SAR still has to describe what the assessor found rather than what the program remembers. Between re-authorizations the POA&M has to move with the environment, and every closure needs closure evidence.

Some enclaves are disconnected by design. The obligation does not change: the record has to be produced inside the enclave and carried out through an approved transfer, with its chain intact.

- **rd.baseline**: NIST SP 800-53 Rev 5 at Low, Moderate, or High, with program overlays where the control selection is tailored.
- **rd.package**: SSP, SAR, and POA&M generated from one implementation record; OSCAL 1.1.2 and eMASS shapes.
- **rd.enclave**: Runs inside the enclave. On-premises delivery for air-gapped environments; evidence exported through your approved transfer mechanism.
- **rd.people**: The founder holds active DoD Secret and DoE Q clearances and is an active consultant at a DOE national laboratory.

## The evidence produced inside the enclave

The package is a projection of three records. Where each proof files under 800-53:

- **CA-7 · CA-2 · CA-6**: Proof of state: continuous monitoring and re-authorization grounded in point-in-time records of every control implementation, regenerable to the date the authorizing official names.
- **AU-9 · AU-10**: The chain itself: the audit record protected from modification, non-repudiable, retained seven years.
- **CM-3 · CM-8**: Proof of change and the system inventory: a new host, instrument, or collaborator account is a row with actor, authority, and timestamp, not a surprise at the next SAR.
- **AC-6 · SI-4**: Proof of agency: what autonomous tooling in the enclave was permitted to do before it ran, and what it did.
- **SSP · SAR · POA&M**: Generated from one implementation record, exported as OSCAL 1.1.2. Assessors with OSCAL tooling consume it directly; everyone else gets the evidence package.

![A PolicyCortex ATO collection overview: passing controls, six-stage lifecycle from scope to 3PAO assessment, control family coverage, and package readiness](https://policycortex.com/images/pcx-ato-collection-overview-1600.webp)

Exhibit SB-7 · one authorization package from scope to 3PAO assessment: passing controls, family coverage, next action. Illustrative demo data; the interface is real.

## How the record is verified after transfer

For a disconnected enclave the recomputation happens on the receiving side: the evidence leaves through your approved transfer mechanism with its chain intact, and the assessor recomputes it there without a connection back to the enclave.

Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.

A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.

**Stated limit.** PolicyCortex is not an assessor and does not certify anything. It produces the records a compliance decision rests on; the assessor, the authorizing official, or the accountable official makes the determination. What is not connected is not observed, and the record says so. Control identifiers cite NIST SP 800-53 Rev 5, NIST SP 800-171 Rev 2, PCI DSS 4.0, SOC 2 TSC, ISO/IEC 27001:2022 and 45 CFR 164 as published.

## Access and onboarding in a research enclave

We agree on the enclave scope, impact level, overlays, and onboarding before access is granted. Read-only captures run inside the connected or air-gapped enclave and file under the 800-53 families the SAR will cite.

Request access so we can review your environment, evidence needs, and onboarding scope. After access is approved, read-only onboarding uses SHADOW mode inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. You hold the records and can recompute the chain yourself.

- **eval.mode**: SHADOW. Watch only; nothing executes.
- **eval.onboarding**: Access is reviewed. Scope and onboarding are agreed with your team.
- **eval.location**: Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
- **eval.egress**: None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
- **eval.after**: You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.

## Delivery, if you want the record stood up for you

Licensing does not depend on it, but a fixed-scope delivery engagement is available: thirty days, one agreed primary cloud environment, an evidence package built and defended through assessor review. The independent assessor makes the certification decision. No certification is guaranteed.

Every engagement is delivered by the people who hold the clearances and wrote the code. Delivery inside a cleared or disconnected enclave is scoped with you before work begins.

- **engagement.scope**: Thirty days. One agreed primary cloud environment.
- **engagement.outcome**: An evidence package built and defended through assessor review.
- **engagement.limit**: The independent assessor decides. No certification is guaranteed.

[Every term of the engagement, on its own page.](https://policycortex.com/engagement)

## Questions assessors and buyers ask

**Q: Can assessors consume the OSCAL output?**
A: Yes. SSP, POA&M, and SAR export in OSCAL 1.1.2. Assessors with OSCAL-aware tooling consume it directly; everyone else receives the evidence package.

**Q: Does it run in an air-gapped enclave?**
A: Yes. On-premises delivery for air-gapped environments is available. Evidence is captured locally and exported through your approved transfer mechanism, with the chain intact so the receiving side can recompute it.

**Q: What about framework overlays?**
A: NIST SP 800-53 Rev 5 baselines with impact-level tailoring (Low, Moderate, High). Program overlays are supported when the control selection is tailored.

**Q: Who operates the platform?**
A: Your team, inside your enclave. Where an engagement is delivered, it is delivered by the people who hold the clearances and wrote the code; there is no sales organization between you and them.

**Q: Does PolicyCortex make us compliant?**
A: No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.

**Q: What happens when a collector is down?**
A: The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.

## Related solutions

- [Defense contractors](https://policycortex.com/solutions/defense-contractors)
- [FedRAMP](https://policycortex.com/solutions/fedramp)
- [ITAR compliance](https://policycortex.com/solutions/itar-compliance)
- [Azure](https://policycortex.com/solutions/azure)

Re-authorize from the record, not from memory. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | OBLIGATION | 2899be61bc5c | 94280fee476d |
| REC 0001 | EVIDENCE | 265bbce4a315 | 2899be61bc5c |
| REC 0002 | VERIFICATION | 2808a0f2e020 | 265bbce4a315 |
| REC 0003 | EVALUATION | 519ddeb358d6 | 2808a0f2e020 |
| REC 0004 | DELIVERY | 3c8e39a14bcb | 519ddeb358d6 |
| REC 0005 | QUESTIONS | 61cb91e052e7 | 3c8e39a14bcb |

Head sha3:61cb91e052e7a1248afb5c8bd1a15b60873fe88290c622f15edf541e7bd70ebc. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
