cloudwaypoint
CLOUD PREPARATION + AUTHORIZATION

Find the decision in front of you.

Cloud Waypoint combines cloud foundation design and application dependency mapping to prepare modernization decisions and authorization inputs. Follow the work from ownership and system boundaries through evidence, review and handover.

THE ENGAGEMENT

Prepare the foundation, evidence and handover.

Bring mission priorities, existing architecture and documents, and the people who own the applications and decisions. Cloud Foundations prepares foundation design, draft security documents, corrective actions and an operating model for review. With ADM, approved observation and owner validation strengthen dependency and migration planning.

Week 4 and Week 8 describe the standard Foundations schedule, including two advance weeks for the data call. Foundations is approximately eight weeks; Application Dependency Mapping requires at least twelve weeks of observation, overlapping Foundations, with approximately eighteen to twenty weeks total for the combined engagement. Timing depends on agreed scope, access, telemetry and participant availability. ADM delivery and acceptance milestones are agreed for the combined scope, not promised at Week 8. These are preparation estimates, not authorization or migration completion dates.

Read the packages and their scope conditions →

START WITH THE DECISION

Choose the question in front of you.

Set directionWho decides, and which framework applies?Prepare authorizationWhat boundary, controls, evidence, and assessment are required?Understand dependenciesWhere do applications, data, shared services, and operators connect?Plan continuityWhat must transfer into operations and continuous monitoring?Pursue FedRAMPWhat does a commercial provider own on the Marketplace path?Choose a public-sector pathCompare DoD, federal, FedRAMP, state and CSF routes.
Integrated engagement detail
ONE ENGAGEMENT, DIFFERENT VIEWS

How the guide, questions and packages connect.

The Studio organizes the work in seven stages. The navigator asks nine delivery questions. Four packages group the work for review and acceptance. These are views of the same engagement, not competing timelines or authorization decisions.

  • Entry. 01 Authority · 02 Framework
  • Foundations. 01 Authority · 02 Framework · 03 Boundary
  • Assessment. 06 Evidence · 07 Assessment
  • GSS design. 03 Boundary · 04 Requirements · 05 Implementation
  • Package. 04 Requirements · 06 Evidence · 08 Risk decision
  • Operate. 05 Implementation · 09 Continuity
  • Closeout. 08 Risk decision · 09 Continuity

Delivery packages: Midpoint snapshot · Readiness package · Transformation package · Final package.

Stage names describe preparation and navigation; an engagement assessment does not replace an independent control assessment or an authorization decision. See each output’s prerequisites and limitations in the navigator.

SUPPORTING DETAIL

Explore the detail.

ONE METHOD

Activities across the engagement.

  1. Orient

    Set the outcome and preparation scope.

  2. Establish

    Define the foundation and draft its documents.

  3. Observe

    Map application flows with dependency mapping.

  4. Converge

    Review the design against the evidence.

  5. Launch

    Carry the evidence into workload preparation.

  6. Operate

    Document services, responsibilities and handover.

MOVE THE WORK FORWARD

Prepare the documents as the design takes shape.

START NOW

Give reviewers something to work with.

Capture the boundary, inherited controls and operating responsibilities in the draft security plan and concept of operations. Track gaps as corrective actions with owners.

STRENGTHEN WITH OBSERVATION

Bring application evidence into the review.

With dependency mapping, owners review observed flows to refine connections, control responsibilities and migration groupings.

Owners validate the required connections; the authorizing official retains every authorization decision. How dependencies become launch inputs →

Explore what moves when authorization is delayedSupporting detail
THE HOLD

What actually waits, and what only looks like it does.

Green work starts the day you decide to start. Dashed work genuinely waits for the landing-zone letter. Choose a later month for the letter and watch what moves: the blocked chain slides with it, and the green work never does, because it was never waiting.

When does the landing-zone letter arrive?

Letter at M1: the blocked chain finishes about six weeks later, at M2.5. By then 0 of the six unblocked workstreams are finished and 3 more are in motion. The queue in front of the letter was always longer than the queue behind it.

0unblocked lanes already finished when the letter lands
3more in motion that day
M2.5testers reach IL5 — moves month for month with the letter

Letter at M2: the blocked chain finishes about six weeks later, at M3.5. By then 0 of the six unblocked workstreams are finished and 5 more are in motion. The queue in front of the letter was always longer than the queue behind it.

0unblocked lanes already finished when the letter lands
5more in motion that day
M3.5testers reach IL5 — moves month for month with the letter

Letter at M3: the blocked chain finishes about six weeks later, at M4.5. By then 0 of the six unblocked workstreams are finished and 6 more are in motion. The queue in front of the letter was always longer than the queue behind it.

0unblocked lanes already finished when the letter lands
6more in motion that day
M4.5testers reach IL5 — moves month for month with the letter

Letter slips to M4, 1 month late. Testers now reach IL5 at M5.5, month for month with the slip. Notice what did not move: every green lane. The delay was added to the end, not saved — unless the green work idled too, which is the one mistake this chart exists to prevent.

1unblocked lanes already finished when the letter lands
5more in motion that day
M5.5testers reach IL5 — moves month for month with the letter

Letter slips to M5, 2 months late. Testers now reach IL5 at M6.5, month for month with the slip. Notice what did not move: every green lane. The delay was added to the end, not saved — unless the green work idled too, which is the one mistake this chart exists to prevent.

3unblocked lanes already finished when the letter lands
3more in motion that day
M6.5testers reach IL5 — moves month for month with the letter

Letter slips to M6, 3 months late. Testers now reach IL5 at M7.5, month for month with the slip. Notice what did not move: every green lane. The delay was added to the end, not saved — unless the green work idled too, which is the one mistake this chart exists to prevent.

4unblocked lanes already finished when the letter lands
2more in motion that day
M7.5testers reach IL5 — moves month for month with the letter

Letter slips to M7, 4 months late. Testers now reach IL5 at M8.5, month for month with the slip. Notice what did not move: every green lane. The delay was added to the end, not saved — unless the green work idled too, which is the one mistake this chart exists to prevent.

5unblocked lanes already finished when the letter lands
1more in motion that day
M8.5testers reach IL5 — moves month for month with the letter

Letter slips to M8, 5 months late. Testers now reach IL5 at M9.5, month for month with the slip. Notice what did not move: every green lane. The delay was added to the end, not saved — unless the green work idled too, which is the one mistake this chart exists to prevent.

6unblocked lanes already finished when the letter lands
0more in motion that day
M9.5testers reach IL5 — moves month for month with the letter

Can start before the landing-zone letter — needs no letter, start now

Categorize and select controlsM0–M4
Confirm inherited mission servicesM0–M5
Define the application shapeM0–M6
Map mission users to ICAM groupsM1–M5
Plan the dual run and the fail-backM1–M7
Draft the mission service catalogM2–M8

Genuinely waits for the landing-zone letter — and only for the letter

Vend the workload account to the test OU
Place the ZTNA connector in the IL VPC
Establish tester access to IL5

After the authorizationAdmitting production users and live CUI, then cutting over, belong to the authorization calendar, not to this chart.

Illustrative durations for a mid-sized program. The shape is the point: the unblocked column is longer than the blocked one, and every month spent not doing it is added to the end, not saved.

Timing, evidence and the two environmentsSupporting detail

Foundations is approximately eight weeks, including the two advance weeks of the data call, and can stand alone on mission-attested evidence. Dependency mapping is recommended: at least twelve weeks of observation, overlapping Foundations. The combined engagement is approximately eighteen to twenty weeks.

The scope covers IL5 and IL6. Shared decisions stay aligned; each environment retains its architecture, evidence and operating differences. The provider’s landing-zone authorization is a separate clock. Foundations mechanics · Dependency & Launch.

YOUR NEXT MOVE

Choose the on-ramp.
Carry the package forward.

Leave with a current-state picture, a transformation plan and a working start on the Risk Management Framework (RMF) package. Continue with your team, a delivery partner or a suitable platform, confirming what can be inherited and what remains yours.

Set the pace from evidence, team capacity and required approvals.

Find your starting point →
THE WIDER ROAD

Carry the preparation into the next authorization.

Where this sits

The mission map places foundation design, authorization preparation and operations on the wider cloud adoption road.

What follows

Carry the boundary, control responsibilities and evidence into ATO acceleration, a complementary follow-on supporting the mission system’s own authorization.

Package definitions and conditions
FOUNDATIONS PACKAGE SCHEDULE

Know what arrives, and why.

  1. Week 4Midpoint snapshotSee the contents →
  2. Week 8Readiness packageSee the contents →
  3. Week 8Transformation packageSee the contents →
  4. Week 8Final packageSee the contents →

Week 4 and Week 8 describe the standard Foundations schedule, including two advance weeks for the data call. Foundations is approximately eight weeks; Application Dependency Mapping requires at least twelve weeks of observation, overlapping Foundations, with approximately eighteen to twenty weeks total for the combined engagement. Timing depends on agreed scope, access, telemetry and participant availability. ADM delivery and acceptance milestones are agreed for the combined scope, not promised at Week 8. These are preparation estimates, not authorization or migration completion dates.

When Application Dependency Mapping (ADM) is included: Device42 and the practitioner produce the following work within these package families; these are not additional Studio export claims. The client supplies approved discovery access, credential owners, a migration list and application owners for validation. Discovery and observation take place only in the approved client environment. Foundations-only scope excludes these items.

Package contents and intended readersSupporting detail
Week 4

Midpoint snapshot

Where the mission stands, confirmed with the people who own it, while there is still time to change course.

  • Foundations receiptFor the sponsor The entry: the moment, the thesis, who signs.
  • AssessmentFor the engineer and the ISSM Fifty-one positions with their evidence quality and confidence, and the trace an assessor can follow.

With Application Dependency Mapping

Conditional on agreed ADM scope and its observation and review milestones.

  • Discovery design and prerequisitesFor the engineer and the ISSM Every in-scope class has a discovery method, a credential owner and a path; the design agreed with the ISSM. The ISSM's written approval of the appliance is tracked as a checkpoint, not a condition of acceptance.
Week 8

Readiness package

For the authorizing chain and operators: proposed foundation decisions, control evidence and gaps, draft security documents, corrective actions and operating responsibilities for review.

  • GSS exit receipt ZTFor the engineer and the ISSM The nine foundation decisions and their instruments.
  • Package readiness ZTFor the engineer and the ISSM Authority, boundary, categorization and inheritance, and where every selected control stands, read from the evidence.
  • System security plan — draft ZTFor the engineer and the ISSM Statements assembled from the record; refused rather than invented.
  • Plan of action & milestones ZTFor the engineer and the ISSM Findings with clocks, owners, and closure evidence.
  • CONOPS document ZTFor the program The eight-section concept of operations and its annex instruments, the RACI among them.

With Application Dependency Mapping

Conditional on agreed ADM scope and its observation and review milestones.

  • Discovery baseline reportFor the engineer and the ISSM Every in-scope class discovered; coverage of the migration list at the agreed threshold, the remainder named; every record owned or listed unowned; drawn on no less than thirty days of dependency sampling, across a month-end.
  • Dependency maps and affinity groupsFor the engineer and the ISSM Every business application on the list has a diagram reviewed by its owner; external dependencies, day-one flows and crossings marked.
  • Business application registerFor the engineer and the ISSM Every candidate workload is a defined business application with owner, hosting, data families and dependencies.
  • Data-quality reportFor the engineer and the ISSM Duplicates, unowned, stale and unreachable records counted at the baseline, and trended again at handover.
Week 8

Transformation package

For the program and its leadership: what moves, in what order, through which gates, the road from today's reading to the next level, and the brief leadership needs to decide.

  • Transformation plan ZTFor the program What moves, in what order, through which gates, with every workstream sized and placed on its horizon.
  • The road aheadFor the program From the reading to the next level, step by step, with guardrails.
  • Executive briefFor the sponsor What leadership needs to understand and decide.
Week 8

Final package

The handover: what was accepted, every open item with an owner, and the sealed record over all of it.

  • Closeout receiptFor the sponsor What was handed over and accepted, every open item with an owner, and the record sealed by digest.

With Application Dependency Mapping

Conditional on agreed ADM scope and its observation and review milestones.

  • Utilization and right-sizing reportFor the engineer and the ISSM Eight weeks of samples on every in-scope server; a sizing per workload with its basis.
  • Dependency-informed wave planFor the program Every wave lists its members and crossings; receiving team and rollback written by the practitioner with the Program; no affinity group split without a recorded reason.
  • Device42 runbook and handover receiptFor the program Discovery schedule, credential rotation, refresh and data-quality pass documented and run once by the platform owner.
A USABLE HANDOVER

Prepare once. Carry the work forward.

Keep the documents aligned.

Shared boundaries, control responsibilities and findings feed the documents from one record. The executive brief and transformation plan give leadership a concise view of the work.

Give the receiving team a working foundation.

The concept of operations carries the service catalog, responsibility assignments and interconnection specifications. The closeout receipt records acceptance and open work with owners.

Where the Zero Trust inputs liveSupporting detail

The pre-plan travels inside the existing deliverables. Migration sequencing, operating responsibilities, boundaries and control responsibilities stay connected. The draft system security plan and plan of action and milestones (POA&M) are assembled from the record for review, with supporting evidence and gaps visible.

What the method reads against · The open Reference Studio.

DECISIONS WITH THEIR OWNERS

Equip the people who decide.

Decision packages support the officials responsible for funding, procurement, release and deployment. The authorizing official retains every authorization decision.

Workshop scope and agenda
WHAT YOU LEAVE WITH

A defined move. A named owner.

The preparation priorities

Which existing designs and documents to build on, where the gaps are and which workstream should begin first.

The next accountable action

A scoped next step: the documents and evidence to prepare, who reviews them and who owns the work.

SOURCING THE WORK

Build, contract, acquire or join.

Build

Own the foundation, staffing, operations and authorization responsibilities directly.

Contract

Use specialist capacity for defined work; specify the responsibilities retained by the mission.

Acquire

Consume a service where capability is better bought than engineered.

Join

Inherit enterprise capabilities and tenancy obligations through an existing program.

Apply these choices to the environment and to individual services. Paths may be combined. See the same sourcing choices on the mission map →. The mission retains the decision to adopt cloud, retain, modernize in place or defer.

The questions behind the starting recommendationSupporting detail
FROM MANDATE TO NEXT MOVE

Move from a mandate to a defensible next move.

The road every mission walks, in the order it asks its questions. The workshop starts it; the preparation that follows carries it.

  1. 01
    Mandate

    Move or modernize.

    Question
    What mission result makes the change worthwhile?
    Outcome
    A clear statement of the mission result the change must deliver.
  2. 02
    Uncertainty

    See the whole decision field.

    Question
    What must be understood before anyone chooses a path?
    Outcome
    One view of the applications, infrastructure, dependencies, authorization, data, funding, shared services, and owners involved.
  3. 03
    Cloud Waypoint

    Build a shared understanding.

    Question
    What can the mission use, inherit, or trust today?
    Outcome
    A shared view of what exists, what the Department provides, and what is genuinely missing.
  4. 04
    Path

    Leverage. Establish. Sequence.

    Question
    What should carry forward, be established, and begin first?
    Outcome
    A practical path showing what to reuse, what foundations to establish, and which engineering and authorization decisions come first.
  5. 05
    Decision

    Name the value before the move.

    Question
    Where can cloud create enough mission value to justify movement?
    Outcome
    A specific value case: enable a focused AI or machine-learning use case, inherit resilience, decouple a constrained back end, or improve mission speed, continuity, security, or cost.
  6. 06
    Next move

    Turn the decision into owned work.

    Question
    What happens next, and who owns the decision?
    Outcome
    A defined move, its value case, its decision owner, the next engineering action, and who operates and pays for it after launch—carried into Foundations as the first accountable work.

Movement is optional. Retain, modernize in place, or defer when cloud would add cost without enough mission value.

THREE HOURS · FOUR CONVERSATIONS

The working agenda.

  1. 00–30

    Mission & outcomes

    What must improve, and who decides?

  2. 30–75

    Foundation & responsibilities

    What can be inherited, and who designs and operates the rest?

  3. 75–135

    Applications & documents

    What evidence and paperwork exist, and what needs preparation?

  4. 135–180

    Scope & ownership

    What should we prepare first, and who owns the next action?

CLOUD WAYPOINT

Move preparation forward.
Start with a conversation.

Let’s talk