What Is eMASS? DoW Cybersecurity System Explained
The Enterprise Mission Assurance Support Service (eMASS) is the Department of War (DoW, formerly the Department of Defense) system of record for cybersecurity authorization: a government-owned, web-based application that the Defense Information Systems Agency (DISA) provides and maintains for the DoW.
DoD Instruction (DoDI) 8510.01, "Risk Management Framework (RMF) for DoD Systems" (last reissued July 19, 2022), requires program managers and system owners deploying systems across DoW components to post their security authorization documentation, and it supports more than 18,000 systems.
DoW systems subject to applicable registration requirements, and cloud offerings pursuing a DISA impact-level Provisional Authorization, are documented through applicable eMASS processes. What it stores, who can touch it, and its functional limits are the baseline facts for planning that work.
Key Takeaways
- DoW-owned, DISA-run. eMASS is a Government Off-the-Shelf (GOTS) web application, not a commercial product, and nearly all DoW organizations use it as the repository for Risk Management Framework (RMF) assessment and authorization.
- Seven RMF steps. National Institute of Standards and Technology (NIST) SP 800-37 Rev2 defines seven RMF steps, and DoDI 8510.01 requires authorization documentation to be posted to eMASS, from system registration through continuous monitoring and the Authority to Operate (ATO) decision.
- Stores scanner outputs. The Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP) Compliance Checker, and Security Technical Implementation Guide (STIG) Viewer produce the evidence, and eMASS stores it, so package quality depends on those upstream tools.
- DoW credentials required. Current DoW authentication requirements use Public Key Infrastructure (PKI), and National Industrial Security Program (NISP) eMASS accounts require the eMASS computer-based training, the Cyber Awareness Challenge, and a Defense Counterintelligence and Security Agency (DCSA) eMASS access request.
eMASS is the DoW's Authoritative System of Record for Cybersecurity Compliance
eMASS is a web-based Government Off-the-Shelf (GOTS) application that automates cybersecurity management for DoW information technology, providing controls scorecard measurement, dashboard reporting, and RMF package report generation. It serves as the DoW's authoritative repository for security authorization documentation across the department.
DISA provides eMASS under the joint sponsorship of DISA and the DoW CIO. DISA handles hosting and maintenance and operates the enterprise help desk and training program. It also publishes semi-annual releases.
DISA requires Non-classified Internet Protocol Router Network (NIPRNet) and Secret Internet Protocol Router Network (SIPRNet) systems to register in eMASS and run their RMF packages through it. DCSA runs a separate instance for cleared contractors under the NISP.
The GOTS classification matters for anyone comparing eMASS to a commercial governance, risk, and compliance product. eMASS is a DoW government service without a commercial purchase or licensing option. Its design goals include eliminating vendor licensing fees, paid software updates, and escalating operations and maintenance costs. A DoW system owner uses eMASS because DoW policy requires it. The RMF workflow recorded in the system makes that policy mandate operational.
eMASS Automates the Risk Management Framework Lifecycle From Categorization to Monitoring
(NIST) SP 800-37 Rev2 defines seven RMF steps, and DoDI 8510.01 adopts that framework for DoW systems, with eMASS as the place their outputs land. Each step maps to a defined set of eMASS actions.
- Prepare: The process begins with system registration in eMASS, which assigns roles such as Team Lead and Regional Authorizing Official (AO). Information Assurance Manager (IAM) is another assigned role.
- Categorize: This step records the system's purpose, mission, security categorization, and approved overlays in the package, while the categorization determines the applicable control baseline for NIST SP 800-53 Rev5 (September 2020).
- Select: eMASS uses the NIST SP 800-53 baseline matching the categorization, which the system owner then tailors through the eMASS workflow.
- Implement: Next, eMASS requires implementation status, narrative, and responsibility for every control in the full baseline, along with the hardware and software baseline.
- Assess: The process records results for each assessment procedure as compliant, not applicable, or non-compliant, and the package then moves through the Package Approval Chain.
- Authorize: Stores the System Security Plan (SSP), the Security Assessment Report (SAR) signed by the Security Control Assessor, and the Authorizing Official's decision with an authorization date and termination date; that entry is the ATO milestone.
- Monitor: This step continues after the ATO and tracks Plan of Action and Milestones (POA\&M) items and updated assessment results through continuous monitoring.
The DoW CIO published the successor framework's strategic tenets, the Cybersecurity Risk Management Construct (CSRMC), on September 24, 2025. CSRMC restructures the lifecycle into five phases: Design, Build, Test, Onboard, and Operations. The official announcement describes CSRMC as DoW's new approach to cybersecurity risk management.
The published strategic tenets leave eMASS's future role under CSRMC unspecified. DoDI 8510.01 still requires posting applicable authorization documentation to eMASS, and DISA still describes eMASS as its RMF management service. Based on current official guidance, system owners should plan to update the same record more often and more automatically, rather than to replace the system.
eMASS Stores Security Controls, Hardware Inventories, Scan Results, and POA\&Ms
A working eMASS package is built from a handful of recurring data types. Five of them carry most of the weight.
- Security control implementation statements. For each NIST SP 800-53 control in the baseline, eMASS holds the implementation status, the narrative explaining how the control is met, and the responsible party. Independent assessor test results are attached to the same controls.
- Hardware and software baselines. The Asset Manager holds the system inventory, and the eMASS API exposes Hardware and Software Baseline endpoints. The asset baseline is what ties a vulnerability finding to a specific device.
- Vulnerability scan results. The eMASS API accepts ACAS scan results through designated ACAS scan types, and SCAP Compliance Checker results load under their own scan type.
- STIG compliance checklists. STIG results arrive as .ckl or .cklb files from DISA STIG Viewer, which reads official XCCDF-formatted STIG files. The STIG Viewer 3.x User Guide V1R6 (August 15, 2025) confirms the .cklb format can now be imported into eMASS. Completed checklists are then uploaded through the supported scan-result process.
- POA\&M items. Every non-compliant test result requires an associated POA\&M item for the affected control or assessment procedure. The associated POA\&M item records the weakness, its source, the responsible organization, resources, and milestone dates.
Upstream tools generate this evidence for eMASS. The eMASS API accepts scan results and assessment artifacts, while the DoW technical evidence guidance identifies STIGs and vulnerability scans as technical evidence for assessing software products.
ACAS, SCAP Compliance Checker, STIG Viewer, and the Evaluate-STIG assessment tool do the scanning and checking; vendors then load those outputs into eMASS. A package assembled from inconsistent scans or stale checklists is exactly as weak inside eMASS as it was outside it, and an assessor reviewing a consistent scan history draws a different conclusion than one reviewing a single recent upload.
The value and handling of that evidence depend on the authorization context in which the package is reviewed.
DoW Components, Contractors, and Cloud Providers All Use eMASS
eMASS use follows distinct authorization contexts:
- DoW components and military services record system ATOs in the standard eMASS.
- Cleared contractors under DCSA cognizance use the NISP eMASS for their facility systems.
- Assessment results for Cybersecurity Maturity Model Certification (CMMC) go into a dedicated CMMC instantiation.
- Cloud service providers work through DISA's cloud authorization process.
Across these contexts, clearer upstream evidence makes a package faster to assemble and easier for an assessor to defend, which drives the sponsor's review timeline.
eMASS Runs as a DISA-Hosted Service With CAC or External Certification Authority Access
DISA hosts and maintains eMASS as a centrally operated enterprise service. The service includes hosting, continuity of operations, the enterprise help desk, and semi-annual releases. Components don't install and patch eMASS locally. DISA's published service description assigns hosting and maintenance responsibility to DISA but does not identify a specific commercial cloud host.
Access is role-based and credentialed. eMASS uses DoW PKI authentication requirements. The DoD External Certification Authority program (ECA) supports issuance of DoW-approved certificates to industry partners and other external organizations that require access to DoW systems.
Cleared contractors request NISP eMASS accounts through their assigned Information Systems Security Professional and the DCSA NISP Cybersecurity Office eMASS team. Prerequisites include DISA eMASS computer-based training and the Cyber Awareness Challenge. The request also requires a DCSA System Authorization Access Request (SAAR).
This access governance keeps the shared record controlled while allowing authorized participants to maintain and review the same package.
eMASS Evidence Quality Determines Authorization Reuse
Cloud service providers pursuing a DoW Provisional Authorization (PA) can use an existing Federal Risk and Authorization Management Program (FedRAMP) authorization or work with a DoW component sponsor. A FedRAMP Moderate authorization supports reciprocity at Impact Level 2 (IL-2), while the DoD Cloud Computing Security Requirements Guide V1R6 (December 2025) addresses Impact Level 4 (IL-4) and Impact Level 5 (IL-5): IL-4 and IL-5 offerings need a DoW Provisional Authorization.
FedRAMP authorizations are tracked on the official FedRAMP Marketplace rather than in eMASS, with Low and Moderate packages held in the FedRAMP repository on Connect.gov and High baseline packages held in the cloud service provider's own repository.
IL-5 requires a FedRAMP High certification, a DISA Provisional Authorization, and a mission-owner ATO, with the application routed through DISA's Risk Management Executive office (RE2) via the Cloud eMASS instance.
Cloud service providers pursuing a DoW impact-level authorization often shorten this path by inheriting controls from an existing pre-authorized FedRAMP boundary rather than assembling one from scratch. An inherited boundary that already covers most required NIST SP 800-53 controls transfers those authorization decisions to the tenant, leaving a smaller set of application-specific controls to document and defend in eMASS.
A Pre-Authorized FedRAMP Boundary Shortens the Path to a DoW Provisional Authorization
eMASS is a shared record, and the quality of what a system owner enters determines how far the package travels. Consistent scan histories, complete control narratives, and current POA\&Ms let other Authorizing Officials reuse the package instead of retesting it, which is where the real time and cost savings appear. Thin or inconsistent evidence, by contrast, remains visible to every reviewer and undermines reciprocity when vendors need it most.
Knox Systems places SaaS vendors inside a pre-authorized FedRAMP boundary that lets them inherit 60% to 80% of required NIST SP 800-53 Rev5 controls, with automated continuous monitoring that keeps the SSP current and supports vulnerability tracking. The authorization path is designed to take approximately 90 days at approximately 90% less cost than the traditional route, and Knox currently supports FedRAMP Moderate, FedRAMP High, and DISA IL-4, with IL-5 on the roadmap for December 2026.
Book a meeting to map an IL-4 path before the sponsor conversation starts.
FAQs about eMASS
Does eMASS Automate scans?
eMASS does not perform ACAS vulnerability scans, SCAP compliance checks, or STIG assessments. Those tools generate the evidence; eMASS stores the resulting artifacts and records their review through the RMF workflow.
Is eMASS the Same as CMMC?
eMASS and CMMC serve different functions: eMASS records NIST SP 800-53 RMF authorizations, while CMMC Level 2 assesses contractor environments against NIST SP 800-171 Rev2. CMMC Phase 2 was suspended on July 13, 2026, but Phase 1 self-assessment and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 obligations remain in force while later phases are in abeyance.
What Is eMASS Training, and Who Offers It?
The Center for Development of Security Excellence offers DISA-created self-paced eLearning on RMF, continuous monitoring, and enterprise reporting. BAI Information Security separately provides the instructor-led eMASS eSSENTIALS course cataloged by the National Initiative for Cybersecurity Careers and Studies.
Who Approves an eMASS Package?
An eMASS package moves through a Package Approval Chain before the Authorizing Official records the authorization decision. Team Leads, Information Assurance Managers, assessors, and other assigned roles maintain or review package content according to their permissions.