If you just landed your first ISSO role, eMASS for beginners guidance is hard to find. There’s one dense DISA manual, a paid course, and almost nothing written by people who actually work in the tool every day. This guide covers what eMASS is, how you get access, which screens you’ll actually use, and the mistakes that make new ISSOs look lost in week one.
Related reading: If you’re brand new in the seat, see your first 90 days as an ISSO for what nobody tells you before day one.
What eMASS Actually Is (and Isn’t)
eMASS — Enterprise Mission Assurance Support Service — is the DoD’s system of record for RMF. It’s where your system’s security posture lives: control implementation status, test results, artifacts, POA&M items, and the workflow that moves your package toward an ATO. When your Authorizing Official signs off, the decision is recorded in eMASS.
Here’s what nobody tells you: eMASS doesn’t do any security work. It documents work that happened somewhere else. Hardening happens on the system. Scans happen in ACAS. Fixes happen with your sysadmins. eMASS is where you prove all of it happened. New ISSOs who treat eMASS as the job — instead of the record of the job — build packages that fall apart the moment an assessor asks a real question.
Getting Access
Access is sponsored — you can’t self-register. Expect this sequence at most organizations:
- Complete the required eMASS training (your component will point you to the current course) and keep the certificate.
- Submit a system authorization access request (typically a DD Form 2875) through your ISSM.
- Get assigned a role on your specific system(s). Your role determines what you can edit versus only view.
Start this on day one. Access can take weeks, and you can’t do your job without it. While you wait, ask your ISSM for exported control listings and the current POA&M so you can learn the package on paper.
The Screens That Actually Matter
eMASS has a lot of menus. As a new ISSO, you’ll live in four places:
- System details — your system’s registration data: categorization, boundary description, personnel assignments. If the people listed here left two years ago, fix it. Assessors notice.
- Controls view — every NIST SP 800-53 control applicable to your baseline, with implementation status and narratives. This is the heart of the package. If you’re not solid on the control families yet, read my NIST 800-53 controls breakdown first.
- Artifacts — the evidence: SSP, scan results, policies, training records, test plans. Every claim in a control narrative should trace to an artifact here.
- POA&M — every open weakness, with milestones and target dates. This is what your ISSM reviews and what leadership reports roll up from. Stale dates here are the fastest way to lose credibility.
How the Workflow Moves
Packages move through eMASS in a workflow: you (ISSO) prepare and submit, your ISSM reviews and pushes forward, the Security Control Assessor evaluates, and the Authorizing Official makes the risk decision. Each step is recorded. Two practical implications: first, nothing you “save” is final until it’s submitted into the workflow; second, when something stalls, the workflow history tells you exactly whose queue it’s sitting in. Learn to read it before you send status-check emails.
Inheritance: The Feature That Saves You Months
Most systems don’t implement every control themselves — they inherit controls from the hosting environment, the base network, or enterprise services. In eMASS, you request inheritance from a providing system, and those controls arrive with the provider’s implementation evidence attached. Getting inheritance right is the single biggest workload reducer available to a new ISSO. Getting it wrong — claiming inheritance the provider doesn’t actually offer — is one of the common eMASS mistakes that delay ATOs.
Your First 30 Days in eMASS
- Read your system’s current ATO letter and note the expiration date and any conditions.
- Walk the POA&M line by line. Flag anything with a passed milestone date — those need updates or justification now.
- Spot-check ten control narratives against their artifacts. You’ll learn the package’s real condition fast.
- Verify personnel assignments and system details are current.
- Map where the evidence comes from: who runs scans, who owns the SSP, who signs off on what.
Where to Go From Here
Once you’re comfortable navigating, the next level is running a full package through eMASS — registration to ATO. I wrote a complete eMASS guide that covers that end-to-end process. And if you want the full RMF task list I actually use to track ATO work — all 7 steps, mapped to what assessors check — that’s the ISSO’s RMF Checklist.

Leave a Reply