eMASS Integration
Enterprise Mission Assurance Support Service automation
The Enterprise Mission Assurance Support Service (eMASS) is the authoritative system of record for DoD cybersecurity risk management. Thalorin integrates seamlessly with eMASS to automate data synchronization, streamline workflow processes, and ensure consistency between operational compliance activities and official authorization records.
The Department announced the Cybersecurity Risk Management Construct on 24 September 2025 as the successor to the Risk Management Framework that DoDI 8510.01 introduced in March 2014. What it did not do was replace the system of record. Systems are still registered in eMASS, control status is still recorded against Assessment Procedures derived from NIST SP 800-53, and an Authorizing Official still signs against what that record says. The ambition moved to five phases and ten tenets — automation, critical controls, continuous monitoring and ATO among them — well ahead of the plumbing underneath it.
eMASS is a name, not a single instance. Components and agencies run their own, on unclassified and classified networks alike, and DCSA operates NISP eMASS for cleared industry with its own accounts and its own authorization office. A system authorised in one instance is not visible from another merely because both are called eMASS. Reuse therefore begins with an export and a conversation rather than a query, and an organisation carrying registrations across several instances is maintaining several records of one control state.
The thing consistently underestimated is transcription. Control status, test results, POA&M milestones and artifacts originate in scanners, ticket queues and engineers' heads, and they reach eMASS because somebody typed them in. Between typings the record ages, and the package an Authorizing Official signs describes the system as it stood when the fields were last touched. DODIG-2022-041, dated 3 December 2021, found the adjacent failure: at two of the four organisations audited, nobody had been appointed as an eMASS reciprocity user, so assessments that already existed could not be found, let alone reused.
The integration Thalorin builds runs the opposite way from an export. Control state is held against the assets and evidence that produce it, and the eMASS write is a projection of that state — a test result posted against the Assessment Procedure it answers, carrying the scan, the date and the tester with it. A POA&M closes because its evidence closed. What an authorization record needs from an integration is provenance, not a bulk upload: which control, which asset, which finding, which day.
The path to authorization is complex
One name, several eMASS instances
Components and DCSA operate separate instances with separate accounts and registrations. A package held in one is not reachable from another, so reuse of an existing assessment starts with an export rather than a lookup.
The record ages between updates
Control status, test results and milestones are entered by hand from systems that change daily. An authorization decision therefore rests on the last date somebody edited the fields, which is rarely the date it is read.
Reciprocity only finds what was published
Two separate acts are needed: a component must make its package available in eMASS, and it must appoint reciprocity users who can review documentation across the other DoD instances. DODIG-2022-041 found organisations doing neither.
API credentials are issued per instance
The eMASS REST API authenticates with an issued API key alongside a client certificate and private key in PEM format, provisioned by the instance holding your systems. Integration schedules follow that provisioning, not engineering readiness.
How Thalorin helps
Bi-directional eMASS data sync
Read system, control and package state over the eMASS REST API and write back against the same identifiers, authenticated per instance with an issued key and a client certificate rather than a scripted browser session.
Automated control status updates
Compliance status posts as a test result against the Assessment Procedure it answers, carrying the tester, the description and the test date — which eMASS rejects outright if it is dated in the future.
POA&M synchronization
POA&M items move with their evidence: scheduled completion date, risk analysis and comments held against the finding that opened the item, so closure is argued from the result that cleared it.
Milestone tracking integration
Milestones are created, revised and closed against the POA&M item they belong to, so a slipped date shows as a change to a named milestone instead of a package that quietly went stale.
Authorization workflow automation
Submissions into the Control Approval Chain and the Package Approval Chain are driven from the state that justifies them, so a control reaches its reviewer with evidence attached rather than following behind it.
Artifact attachment management
Artifacts are versioned with the control and system they support, carrying the description and expiration date eMASS records, and split when a file exceeds the upload ceiling the API enforces.
eMASS Integration: common questions
Is eMASS going away now that CSRMC has replaced RMF?
No. The CSRMC, announced on 24 September 2025, replaces the Risk Management Framework as the Department's approach to managing cyber risk. eMASS is where authorization records are held. Its ten strategic tenets — automation, critical controls, continuous monitoring and ATO, reciprocity, and enterprise services with inheritance among them — describe how that record should be produced and consumed rather than where it lives. Programmes continue to register systems, record control status and route approvals through eMASS while the construct is implemented.
Can eMASS be updated programmatically instead of through the web interface?
Yes, through the eMASS REST API where it is enabled for your instance. Authentication uses an API key issued to the integration together with a client certificate and private key in PEM format, plus the user identifier the writes are attributed to. MITRE publishes an open-source client and command-line tool, eMASSer, against the public OpenAPI specification. Coverage includes systems, controls, test results, POA&Ms, milestones, artifacts, approval chains and hardware and software baselines.
Why can I not see another component's authorization package in eMASS?
Because you are almost certainly not in the same instance. eMASS is deployed separately by components and agencies, and a registration in one does not appear in another. Reciprocity search reaches only what a component published, and reviewing another component's documentation across DoD instances requires an appointed eMASS reciprocity user. DODIG-2022-041, dated 3 December 2021, found the Defense Logistics Agency and the Defense Human Resources Activity had appointed none, which is how an assessment that exists becomes impossible to reuse.
Is NISP eMASS the same system as DoD eMASS?
It is the same software serving a different population. DCSA operates NISP eMASS for cleared contractors authorising classified systems under 32 CFR Part 117, the NISPOM rule that took effect on 24 February 2021, with its own accounts, its own registrations and DCSA's authorization office in the deciding role. A contractor holding both a NISP eMASS registration and a component registration for a DoD programme is maintaining two records of overlapping controls, not one.
How do STIG scan results become control evidence in eMASS?
Through Control Correlation Identifiers. Each STIG rule carries one or more CCIs, DISA's decomposition of NIST SP 800-53 controls into single actionable statements, and eMASS holds Assessment Procedures tied to those CCIs. A scan result is therefore recorded against an Assessment Procedure rather than against a control as a whole, which is why one control can sit part-answered: a procedure closed by a benchmark, another still waiting on a manual check.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about eMASS Integration.
See how one evidence artifact satisfies eMASS Integration requirements alongside every other framework you carry.