In September 2025, the Department of Defense announced the DoD CSRMC — the Cybersecurity Risk Management Construct — as the successor to the Risk Management Framework that has governed DoD authorizations for over a decade. If you’re a working ISSO, you’ve probably seen the headlines, a few vendor hot takes, and almost nothing that answers the only question that matters: what does this actually change about my job?
This post is that answer, written from the practitioner side. What CSRMC is, why DoD is making the change, what the five phases and ten tenets say, and — most importantly — what to do about it while your systems are still operating under RMF today.
What Is the DoD CSRMC?
The Cybersecurity Risk Management Construct is DoD’s new approach to managing cyber risk across the system lifecycle, formally unveiled on September 24, 2025. Where RMF organized work around six framework steps ending in an authorization decision that got revisited roughly every three years, CSRMC organizes work around five lifecycle phases — Design, Build, Test, Onboard, and Operate — with continuous monitoring feeding real-time dashboards throughout.
The stated goal is a “constant ATO posture”: instead of proving your system was secure at a snapshot in time and coasting on that authorization for three years, the system continuously demonstrates its security state through automated evidence, and the authorization is a living status rather than a calendar event.
Why DoD Is Replacing RMF
Anyone who has built an ATO package knows the criticism, because we’ve lived it: RMF as practiced became a documentation exercise. Control narratives written once and left to age. Artifacts assembled for the assessor, not for the defender. A three-year reauthorization cycle that told you a system was secure once, past tense. I’ve written before about how the real value of continuous monitoring gets lost in checklist thinking — that argument, from Continuous Monitoring in RMF: What Actually Matters, is essentially the argument DoD itself is now making at the enterprise level.
To be clear about what’s not changing: risk management isn’t going away, NIST SP 800-53 controls don’t vanish, and nobody is un-inventing the security work. CSRMC changes how risk is assessed, evidenced, and kept current — not whether systems have to be secure.
The Five Phases
| CSRMC Phase | What it covers | Rough RMF equivalent |
|---|---|---|
| Design | Security architecture and risk decisions made before anything is built | Categorize + Select |
| Build | Implementing the system with security embedded, DevSecOps-style | Implement |
| Test | Validating security continuously, not as a one-time assessment event | Assess |
| Onboard | Bringing the system into the operational environment with its monitoring wired in | Authorize |
| Operate | Continuous monitoring, real-time dashboards, constant authorization posture | Monitor |
The mapping isn’t one-to-one, and that’s the point. RMF steps were process gates you passed through; CSRMC phases are lifecycle stages the system lives in, with security evidence generated continuously in each one.
The Ten Tenets
DoD grounds CSRMC in ten tenets: automation, critical controls, continuous monitoring and ATO, DevSecOps, cyber survivability, training, enterprise services and inheritance, operationalization, reciprocity, and cybersecurity assessments. Most of these will sound familiar — they’re the things RMF was always supposed to deliver and mostly didn’t at scale.
Three of them deserve an ISSO’s particular attention. Automation means the evidence you currently produce by hand — screenshots, scan exports, control narratives — is expected to become machine-generated and machine-readable. Continuous monitoring and ATO means the Monitor step stops being the neglected afterthought of the lifecycle and becomes the lifecycle. And reciprocity — one organization accepting another’s security evidence instead of re-assessing from scratch — finally has a technical foundation, because structured, current data travels between AOs in a way that stale PDFs never did.
What Changes for ISSOs Day-to-Day
Here’s my honest read on how the role shifts, based on what DoD has published and how these transitions have gone historically. The daily rhythm I described in What ISSOs Actually Do All Day doesn’t disappear — it rebalances.
- Less narrative writing, more data plumbing. If dashboards become the evidence, the valuable skill becomes making sure the right telemetry flows from scanners, SIEMs, and endpoints into whatever the authorization dashboard reads — and knowing what the numbers mean when the AO asks.
- Continuous monitoring stops being deferrable. Under RMF you could, in practice, let ConMon slide between assessment cycles. Under a constant-ATO model, a red dashboard is visible to decision-makers immediately. The ISSOs who already run disciplined ConMon will feel vindicated; the ones who don’t will feel exposed.
- Assessments become smaller and more frequent. Instead of a giant assessment event every three years, expect ongoing validation — which means your artifacts have to be current every week, not just assessment week.
- Your RMF knowledge still matters. The control catalog, categorization logic, and risk-decision structure underneath CSRMC are still recognizably NIST. If you understand how RMF actually works, you’re learning a new interface to concepts you already know — not a new profession.
What We Still Don’t Know
Plenty, and it’s worth being honest about it. As of mid-2026, component-level implementation guidance is still rolling out unevenly. How eMASS evolves or gets replaced, how existing ATOs transition, what happens to systems mid-package, and how quickly the services actually operationalize continuous authorization — all of that is being worked out in real time, and anyone who tells you they know the exact timeline is selling something. DoD transitions of this scale historically take years, and 8510.01-based processes will keep governing many systems during the overlap.
How to Prepare Without Panicking
Three moves that pay off regardless of how fast the transition lands. First, get serious about continuous monitoring now — it’s the center of gravity of the new construct and the most portable skill on the list. Second, learn the automation side of your existing tools: scheduled scans, exportable dashboards, structured findings. Third, keep your current packages disciplined, because systems with clean, current RMF evidence will have the easiest on-ramp to whatever the transition requires. The fundamentals still run on the same discipline — my RMF ATO Checklist ($27) keeps every artifact and phase gate tracked in one place while RMF still governs your systems.
Final Thoughts
The DoD CSRMC is the most significant change to DoD authorization in over a decade, and it’s aimed squarely at the pain every practitioner already knew: point-in-time compliance doesn’t equal security. The ISSOs who thrive through the transition will be the ones who treated continuous monitoring as the real job all along. I’ll keep covering CSRMC as implementation guidance drops — subscribe below and you’ll get each update as it publishes.

Leave a Reply