Server racks with glowing lights in a data center

How to Submit an Authorization Package in eMASS: The Pre-Flight Checklist and Workflow

To submit an authorization package in eMASS, open your system, go to the Packages (or Authorization / Workflow) tab, click Create Package, choose the package type (assess and authorize, assess only, reauthorization, or decommission), select the controls and artifacts to include, add the required attachments, fill in the package comments, and submit. The package enters the Package Approval Chain and travels from your ISSM to the SCA to the AO’s office. Whether it comes back or keeps moving is decided almost entirely by what you did in the week before you clicked submit.

Choose the right package type

  • Assess and Authorize: the full package for a new system or a system whose ATO is expiring. Ends in an authorization decision.
  • Assess Only: for components or systems that will be authorized under another system’s ATO. Ends in an assessment, not a decision. Assess only vs full ATO explains when this applies.
  • Reauthorization: same shape as assess and authorize, but reviewers expect you to show what changed since the last ATO. ATO reauthorization covers those expectations.
  • Decommission: closing out a system. Short, but it still goes through the chain.

Picking the wrong type is a guaranteed return, because the workflow and required attachments differ. When unsure, ask the ISSM before creating anything.

The pre-flight checklist (do this before Create Package)

Controls

  • Every control in the baseline has a status. No blanks.
  • Every Compliant control has at least one artifact and test results on its CCIs. Entering test results is the procedure.
  • Every N/A control has a justification tied to the boundary diagram or hardware/software list.
  • Controls have cleared the Control Approval Chain to whatever stage your process requires before packaging. PAC vs CAC explains the dependency.
  • Inherited controls show current provider validation and a current provider ATO.

POA&M

  • Every Non-Compliant CCI has a POA&M item, and every POA&M item maps to a finding source.
  • No overdue items without an updated milestone and a comment explaining the slip.
  • CAT I items either have a remediation date inside the AO’s tolerance or a risk acceptance already signed. An open CAT I with no plan is a denial waiting to happen.

System record and artifacts

  • System details are current: categorization, boundary description, system owner, ISSO, ISSM, AO of record, and the authorization termination date being requested.
  • The boundary diagram, hardware/software list, SSP, and any required plans (contingency, incident response, configuration management, ConMon) are uploaded, dated within the last year, and attached where the package requires them.
  • Scan evidence is recent: ACAS results and STIG checklists within the window your SCA expects, typically 30 days.
  • No artifact with zero control associations. Associate it or delete it.

The rejected-package checklist is the longer version of this list, built from actual return comments.

Creating the package

  • Packages tab, Create Package, choose the type.
  • Name it clearly: system acronym, package type, and the month. “SYSX A&A Package 2026-09” is findable later; “Package” is not.
  • Select controls. For a full package, select the entire baseline. eMASS snapshots the control status at this point; changes you make to controls afterward do not flow into the package unless you refresh or recreate it.
  • Select or attach artifacts. Instances vary on whether all system artifacts are included automatically or you pick them. Either way, confirm the SSP, boundary diagram, POA&M export, and scan summaries are present.
  • Fill in the package comments. This is the cover letter: what the system is, what is being requested (ATO for three years, for example), the compliance and validation percentages, the count of open CAT I/II/III items, notable risks and their mitigations, and anything the AO’s staff will otherwise have to hunt for. Two or three tight paragraphs.
  • Submit. Confirm the package status changes and the first PAC stage shows the ISSM as the assignee.

What happens after submission

The ISSM reviews first. Expect questions within a week; if you hear nothing in two, ask. Then the SCA performs or finalizes the assessment, produces the Security Assessment Report, and assigns residual risk. Then the AO’s staff builds the recommendation and the AO decides. Realistic timelines by system type are in how long an ATO takes; the short version is that a clean package moves in weeks and a returned package loses its place in every queue it was in.

While it is in the chain, keep working the system. Continue scans, close POA&M items, and log the ConMon activity. If the SCA asks for a refreshed scan, you want to hand it over the same day.

If the package is returned

Read every return comment and sort them into two piles: control-level (fix the control, it goes back through the CAC) and package-level (fix the POA&M, comments, or attachments, then resubmit). Reply to each comment in the package notes so the reviewer can see what changed without re-reading the whole package. Then resubmit. Returned packages that come back with a clear change log get processed fast, because reviewers would also like this to be over.

The one habit that prevents returns

Ask your ISSM to do a fifteen-minute pre-review of the package comments and the POA&M before you submit. Not the controls, just those two things. They are what every reviewer reads first, and an ISSM who has seen a hundred packages will catch the phrasing that triggers a return. It is the cheapest fifteen minutes in the entire RMF process.

For the full ordered task list from Categorize through submission, the RMF Checklist is what I keep open during package week.

Pro Tools for Working ISSOs

Working a real ATO package right now?

Skip the spreadsheet rebuild. These are the exact tools I use in the field as an active DoD ISSO.


Get the free RMF Quick Reference

All 7 RMF steps on one page — free when you subscribe to the weekly ISSO Insider.

Leave a Reply

Discover more from RMFInsider

Subscribe now to keep reading and get access to the full archive.

Continue reading