cloudwaypoint
AFTER READINESS · ATO ACCELERATION

An eight-month path, with every condition visible.

Not a universal promise: a planning model for the case where a usable vehicle exists, the boundary is acquired rather than invented, long-lead connections start on day one, and named owners let engineering, assessment, evidence and decisions overlap. It is the complementary follow-on to readiness, taking the mission system through its own authorization on the evidence readiness already built.

AN ACQUIRED BOUNDARY · EIGHT MONTHSM0M1M2M3M4M5M6M7M8Task order, funds obligateNetwork path orderedDiscovery and design sprintBoundary deployedWorkload in, hardenedPackage tailoredTest authorizationIndependent assessmentMonitored operation, ~90 daysAuthorizing-official decisionevidence clock startsAcquired, starts day oneLong-lead dependencyProving windowThe decisionThree lanes start the day the ink dries. The evidence clock starts when the boundary goes live.Illustrative, for a bounded first boundary. Planning guidance, not a promised authorization timeline.
HOW THIS RELATES TO READINESS

Readiness builds the evidence. Acceleration spends it well.

The readiness program runs inside the landing zone’s own authorization—typically 24–28 weeks, and the provider and JWCC work stream rather than this one. This calendar counts from the task order and assumes the boundary can be acquired pre-engineered. Where the landing zone is engineered and authorized through the provider stream instead, that clock sets the pace, and the readiness work runs inside it. Either way, the authorizing official owns the decision.

THE STORY · FIVE MOVES

Getting a mission system authorized is five moves.

They overlap—that overlap is where the calendar is won—but each has one owner and one artifact that says it is done.

  1. 01 Buy

    Get a contract that can pay for cloud.

    Cloud is bought, not requisitioned. An enterprise vehicle—the Department’s joint cloud contract, or your agency’s own—turns a funded need into a task order that can pay a cloud provider this fiscal year.

    Owner
    Your contracting office.
    Done when
    A task order is awarded and funds can obligate.
    What it is not
    A tenancy, a network path, or an authorization. It is permission to spend.
  2. 02 Connect

    Order the long-lead network path on day one.

    Systems reach a government cloud region over a dedicated, approved network path, and circuits and connection approvals are the longest lead item nobody starts early. Ordering the path the week the task order signs is free schedule; ordering it in month four is a stall you chose.

    Owner
    Your network organization, with the connection-approval office.
    Done when
    The path is provisioned and passes traffic to the test boundary.
    Why it hides
    Users arrive through a zero-trust front door, so the circuit feels optional. It is not: backups, replication and system-to-system traffic never ride the user door.
  3. 03 Occupy

    Land in a hardened boundary—acquired, not built.

    This is the move that sets the calendar. A landing zone can be engineered from scratch, or acquired as a pre-engineered boundary with the security stack already wired and the paperwork already mapped to the controls.

    Owner
    Your cloud foundation team, with the integration and authorization partners.
    Done when
    The boundary is live, hardened, monitored, and your workload is inside it.
    What you inherit
    A large share of the security controls arrive already implemented or shared, leaving your team the mission-specific remainder.
  4. 04 Prove

    Test it, assess it, and let the evidence accumulate.

    A test authorization lets real testers use the system for a bounded window. An independent assessor examines the boundary and the package. The monitoring that started the day the boundary went live accumulates the operating evidence the decision will rest on—roughly ninety days of it.

    Owner
    The assessor and your security team; testers from the mission.
    Done when
    The assessment is delivered and the evidence period has run.
    The trap
    Treating “package ready” as the finish line. Artifacts are not operations; the clock that matters is the one recording the system actually running.
  5. 05 Authorize

    A named official weighs the risk and signs.

    An authorization to operate is a risk decision by a named authorizing official, not a certificate that falls out of a toolchain. Then come production users, live data, and continuous monitoring for as long as the system runs.

    Owner
    The authorizing official. Only them.
    Done when
    The letter is signed and its conditions are named.
    What no partner sells
    This signature.

Moves 01–03 run in parallel from day one. Move 04 starts the day the boundary is live. Move 05 compresses for exactly one reason: everything handed to the official is finished, monitored, and familiar.

THE COMPARISON

Eight months becoming twenty-four, without anyone doing anything wrong.

The longer path is not a slower team. It is the same team building in sequence what the eight-month path acquires: the landing zone designed and built, the security stack procured and tuned, the package written from a blank page, and only then the proving window and the decision.

SAME WORK · ACQUIRED VS HAND-ROLLEDM0M6M12M18M24ACQUIRED BOUNDARYBuyConnectOccupyProveAuthorizeHAND-ROLLED, SEQUENTIAL BY NECESSITYTask orderNetwork pathLanding zone builtSecurity stack tunedPackage authoredTest authorizationAssessmentMonitored operationDecision windowNot a slower team: the same team building in sequence what the eight-month path acquires.Illustrative durations. A real program plans against its own estate.
WHERE THE MONTHS COME FROM

Open each claim.

A calendar this short earns skepticism. Here is each month-saving claim and what it rests on, because the compression is real, and it is also specific.

The boundary is acquired, not built

Hand-rolling a landing zone means designing the account structure, guardrails, logging, key management and network segmentation from first principles, then documenting all of it. A pre-engineered boundary arrives with those decisions made, deployed, and already described in authorization language, so the calendar spends weeks configuring it to the mission instead of quarters inventing it.

The security stack is already wired

Vulnerability scanning, centralized logging, endpoint protection and alerting are in the boundary on day one rather than procured, integrated and tuned one tool at a time. That is also why the evidence clock can start at month three: there is a monitoring system running to produce evidence.

The package starts pre-filled

The security plan, policies and procedures for the boundary’s controls exist before the engagement starts, matured across prior authorizations. Your team writes the part only it can write—the mission system’s own behavior.

Inheritance does most of the lifting

In an acquired boundary, most controls are implemented by the platform, shared with it, or inherited from the cloud provider’s own authorization. The mission team’s share is the slice only it can own; fewer controls to satisfy is fewer months to satisfy them.

The assessor is not learning on your time

Assessment stretches when the assessor meets a novel architecture and a hand-written package. A boundary pattern assessed before, described the same way each time, gets examined rather than reverse-engineered.

Parallelism is scheduled, not hoped for

The most common stall is sequencing: award, then order the circuit, then start the boundary. Every lane that can start on day one does, and the long-lead network path is ordered in week one because nothing else on the chart can absorb its delay.

WHAT EIGHT MONTHS DOES NOT SHRINK

Four things the calendar refuses to compress.

It compresses engineering and paperwork, and refuses to compress judgment, testing, or evidence. An eight-month plan that shrank those too would not deserve anyone’s signature.

01

The official’s judgment

An authorization is a risk decision by a named person. It takes what it takes, and rushing it is how programs lose the second one.

02

The evidence period

Roughly ninety days of the system actually operating, monitored. Artifacts can be accelerated; operating history can only be accumulated.

03

The test window

Real testers, bounded time, the same front door production will use. A skipped test authorization is a finding, not a shortcut.

04

Your own decision cadence

The plan assumes your named owners show up and decide weekly. Every deferred decision is added to the end of the calendar, not saved.

SIX TERMS, WITHOUT THE ACRONYM FOG

The words on the calendar.

ATO — authorization to operate
A named official’s signed risk decision that a system may run in production with real data. Not a certification, not a product, not transferable.
Authorizing official
The senior official who owns the risk decision and signs the ATO. Everything on this page is preparation for one person’s informed judgment.
Landing zone
The prepared cloud environment a system lives inside: accounts, guardrails, network, logging and security tooling.
Test authorization (IATT)
A bounded permission for real testers to use the system before production: specific people, specific data, specific end date.
Continuous monitoring
The standing watch—scanning, logging, alerting and reporting—that starts when the boundary goes live. Its first ninety days are the evidence the decision rests on.
Inheritance
Controls satisfied by the platform or provider beneath you, so your team answers only for its own slice.
WHAT NO PARTNER SELLS

This signature.

A marketplace acceleration service can compress engineering and documentation, and continuous monitoring and authorization support can structure the evidence stream. Neither can grant or transfer an authorization. Everything on this page exists to put a complete, honest picture in front of the one person who decides—and anyone who implies otherwise is selling theater.

CLOUD WAYPOINT

Know what you are moving.
Design where it is going.
Build security into the plan.

Test the calendar against my mission