Back to Blog

Federal FY-Close: What You Can and Can't Ship Before Q4 Spend Closes

A FedRAMP Moderate authorization takes nine to twelve months on the fast path. Six weeks of FY26 remaining is not enough for the ATO — but it is enough for the SSP, gap assessment, vendor diligence, and continuous-monitoring instrumentation that make FY27 execution clean. What to sign for, and what not to.

Quick Answer

A FedRAMP Moderate authorization takes nine to twelve months on the fast path. Six weeks of FY26 remaining is not enough for the ATO — but it is enough for the SSP, gap assessment, vendor diligence, and continuous-monitoring instrumentation that make FY27 execution clean. What to sign for, and what not to.

The federal fiscal year closes on September 30. Any dollar in a FY26 line item that has not been obligated by then goes back. Every year, a portion of that money ends up spent on the wrong thing at the wrong time, and cybersecurity is a favorite bucket because it is easy to defend the line item and hard to defend the outcome. This piece is about what you can actually deliver against a FY26 cyber obligation in the six weeks remaining, and what you should not sign a statement of work for even if the money is on the table.

The dishonest version of this conversation happens in every capture manager's inbox in August. A prime asks a subcontractor to write a proposal to stand up a FedRAMP Moderate authorization boundary, cover an integration to an existing agency system, and pass a preliminary readiness assessment before September 30. The subcontractor writes the proposal because refusing the proposal loses the relationship, not just the deal. Everyone signs. The work does not happen on that schedule because it structurally cannot happen on that schedule, and the awkward conversation happens in December when the milestone slips and the money is either de-obligated (bad for the prime) or re-scoped into something the delivery team never intended to produce (worse for everyone).

This piece exists so that conversation happens now, at scoping, rather than in December at the invoice.

9-12 mo
FedRAMP Moderate cold-start ATO on the fast path
6 wk
Enough for SSP + gap assessment + monitoring turn-on, not the ATO
$0
What the IG will let you claim for a milestone you did not deliver

Why the deadline math is unforgiving

Those numbers hide a set of dependencies that most Q4-planning conversations skip. FedRAMP Moderate on the fast path is 3PAO selection, SSP authoring, penetration testing, agency sponsorship, and a JAB or agency ATO decision, in that order and mostly sequential. DoD IL-4 takes longer. A HIPAA-adjacent BAA for a federally-funded state health program can close in weeks, but only if the vendor's SOC 2 is current and the BAA template does not go through general counsel iteration. Six weeks buys visible progress on any of these; six weeks does not buy the signed authorization on any of them.

Federal cyber programs are not just capacity-bound; they are sequenced. Some steps have external dependencies that will not compress no matter how much the delivery team wants them to. A 3PAO cannot start pen testing without a stable SSP; the SSP cannot stabilize without decisions on inheritance boundaries; the inheritance decisions require an authorization boundary diagram that has been reviewed by the agency's ISSO. Each of those is a real handoff with a real review period. Compressing them requires the agency to compress its side, and the agency's calendar is set by staffing and rotation, not by your obligation deadline.

The scheduling reality that most subcontractors do not want to say out loud: the agency's ISSO is on leave for two weeks in August, the ISSM position turned over in July and the successor is still ramping, the prime's federal-facing security lead is at Black Hat and DEF CON the first week, and the 3PAO you want to book is over-committed through October because every other subcontractor in your position tried to book them in mid-August too. None of those constraints appear in the proposal. All of them determine whether the timeline is real.

The IG-report pattern

The Q4 spend that goes badly is almost never the money that was spent on something modest. It is the money that was spent on something ambitious that could not finish in time and that no one wanted to admit was slipping. The IG report writes itself.

What is actually shippable in six weeks

The work that fits inside the FY26 window and produces defensible artifacts is not the ATO itself. It is the pre-work that makes the ATO cheaper and faster in FY27. Four categories, all of which produce a paper trail that can be pointed at when the inspector general asks what the money bought.

An SSP that is actually usable

A first-pass System Security Plan authored against the current NIST 800-53 Rev 5 baseline, with the moderate control set tailored to your actual architecture. This is not a compliance shelf document. Done well, it becomes the working reference for the 3PAO and the agency reviewer. Six weeks is enough time for a competent author who has done this before. It is not enough time for a firm learning on your dollar.

The specific outputs of a well-authored SSP: authorization boundary diagram at the network and data-flow level, control implementation summaries that name specific technologies and configurations (not "we have MFA" but "Duo Federal via SAML with hardware-token backup on privileged accounts"), inheritance mapping if the target environment is on a FedRAMP-authorized platform (AWS GovCloud, Azure Government, GCP Assured Workloads), and a plan of action and milestones (POA&M) for controls not yet fully implemented. That POA&M is the artifact that carries into FY27 and becomes the funded work.

A gap assessment with dollarized remediation

Every control not currently implemented, priced with a specific remediation approach, sequenced by dependency. This is the artifact the CFO reads before approving the FY27 request. Six weeks is enough for a two-person assessor team on a boundary of moderate complexity.

The gap assessment should distinguish between three categories of missing controls: fastest to close (implemented but not documented, a documentation exercise), medium (implemented partially and needs technical work, engineering effort), and highest (not implemented at all, new tooling or process). Every mid-market federal-adjacent shop we have worked with has a mix of all three, and the split usually surprises the CFO because "we have MFA" turns out to mean "some employees have MFA on some systems some of the time." The gap assessment writes that gap in a dollar amount.

Vendor and supply-chain diligence for named subcontractors

If the prime is going to route agency data through a subcontractor, the subcontractor's SOC 2 needs to be verified as current, the BAA or DPA needs to be executed, and the incident-notification SLA needs to be in the master agreement rather than a side letter. This is legal-and-procurement work, not engineering. It moves at the speed of your general counsel, but the artifacts are real and defensible.

The specific check on a subcontractor SOC 2: it must be Type II, cover the trust service criteria your data will touch (Security is table stakes; add Availability and Confidentiality for anything supporting a federal mission), be current (dated within the last twelve months with no material qualifications), and cover the subcontractor's OWN infrastructure, not the SOC 2 of a cloud provider they resell. This last point catches many first-time federal buyers because subcontractors are happy to hand over a Snowflake or AWS SOC 2 as if it satisfied the check. It does not.

Continuous-monitoring instrumentation on the systems you already run

Turn on the audit logging you have not been running. Send it to a WORM store. Set up the daily and weekly reports the ATO will eventually require. When the 3PAO shows up in FY27, this is six to nine months of real evidence rather than the two-week burst that fools nobody.

The specific controls this addresses in the NIST 800-53 Rev 5 moderate baseline: AU-2 (event logging), AU-3 (content of audit records), AU-6 (audit record review, analysis, and reporting), AU-11 (audit record retention), and SI-4 (system monitoring). All five want evidence of continuous operation, not point-in-time attestation. The six-week window in FY26 is exactly the setup work; the twelve months of operation before the ATO is the actual evidence.

What not to sign for in the FY26 window

Anything that requires an agency signature you do not yet have — an ATO letter, a JAB provisional authorization, an incident-response memorandum of understanding — should not be on a September 30 delivery schedule. The signer's calendar does not care about your obligation deadline. Booking a delivery date against an external signer's availability is how you end up with a subcontractor invoice that stares back from a spreadsheet in December while the ATO is still six months out.

Anything that requires infrastructure your team has never operated should also come off the table for FY26. Standing up a new cloud region, cutting over to a new identity provider, migrating from an on-premise system to a FedRAMP-authorized SaaS — these are FY27 initiatives that get scoped and priced in FY26, not delivered.

Ship in FY26 (six weeks)
Scope in FY26, deliver in FY27
First-pass SSP against NIST 800-53 Rev 5 Moderate
3PAO-signed final SSP
Gap assessment with dollarized remediation
ATO letter or JAB provisional authorization
Subcontractor SOC 2 + BAA + incident SLA verification
New subcontractor onboarding + FedRAMP inheritance
Continuous-monitoring instrumentation turn-on
Twelve months of evidence for the AU control family
POA&M with sequenced FY27 milestones
Cloud migration to FedRAMP-authorized platform

What the defensible proposal reads like

The scope language that survives an IG review names what will be delivered and what will not. The proposal you want to write in the next two weeks, if you are the subcontractor with a Q4 obligation on the table, sounds like this: "Deliverables by September 30 FY26 include (1) a first-pass System Security Plan authored against NIST 800-53 Rev 5 Moderate for the [named boundary], (2) a gap assessment with dollarized remediation cost and dependency-sequenced POA&M, (3) verification of SOC 2 currency and executed data-processing agreements for named subcontractors, and (4) continuous-monitoring instrumentation configured against the AU control family with weekly report artifacts. Deliverables explicitly out of scope for this obligation include the 3PAO engagement, agency ATO sponsorship, pen-testing execution, and any migration of workloads to new infrastructure — these are dependencies for FY27 and scoped separately."

That paragraph reads defensive. It is defensive on purpose. Every phrase is an artifact that already got argued when the FY25 IG cycle ran through subcontractors who over-promised on similar work. The subcontractors that survived those reviews got to keep working with those primes; the ones that did not, did not.

What the prime actually needs

The most valuable thing a subcontractor can hand a prime in August is not an aggressive timeline. It is a scope the prime can defend to the contracting officer without hedging.

The FY27 pipeline reality

What happens after September 30 is where the FY26 setup pays off. The FY27 request that lands in October with a signed SSP, a costed gap assessment, and six weeks of continuous-monitoring data behind it moves through agency review faster than a FY27 request that starts from a blank sheet. The gap assessment becomes the FY27 line item. The SSP becomes the deliverable that starts the ATO clock rather than delaying it. The monitoring data is the evidence the 3PAO uses to shorten the audit window.

The compounding effect is real. Programs that do the FY26 setup work properly land their ATOs in Q3 FY27; programs that try to skip the setup and rush the authorization in FY26 either miss the FY26 obligation or blow the FY27 audit and land the ATO in Q3 FY28. The eighteen-month delta is what separates programs that are on the FY27 accreditation curve from programs that are perpetually one cycle behind.

Sequencing FY26 setup into FY27 execution

Treat the six weeks remaining in FY26 as the setup for a clean FY27 execution. The obligations you make now should be for work that produces artifacts you will use in the first ninety days of FY27, not for delivery dates that overlap with the fiscal-year rollover. That means front-loading assessment, planning, and instrumentation work now; back-loading engineering, migration, and authorization work into FY27 where it belongs.

Vendors who tell you they can deliver a FedRAMP Moderate authorization in six weeks are either misunderstanding the process or hoping you are. Vendors who tell you they can deliver an SSP, a gap assessment, and continuous-monitoring instrumentation in six weeks are describing normal work at a normal pace. The difference between the two conversations is the difference between a defensible obligation and one you will have to explain to an auditor.

Common objections, answered

"Our incumbent said they could do the ATO in FY26." Ask them for two references at the same size, in the same authorization tier, whose ATOs were signed in a similar compressed timeline. If they cannot produce those references, they are not telling you what they have done; they are telling you what they wish they could do. The gap between the sales pitch and the delivery reality on federal cyber is where careers ossify and IG reports get written.

"We already have a SOC 2, so the SSP should be quick." A SOC 2 covers a different control set with different evidence expectations. Some controls overlap (access control, monitoring, change management) but the mapping is not one-to-one. Expect the SSP to reuse maybe forty percent of your SOC 2 evidence and require net-new work for the other sixty. Any consultant who tells you the SOC 2 gives you the SSP for free is undercounting.

"The agency wants the ATO by January." Then the agency needs to compress its side of the review, not just yours. Ask for a specific ISSO/ISSM commitment on review turnaround (72 hours per iteration, not "we'll get to it"), a named agency sponsor with authority to approve the authorization boundary, and a written commitment to fund the 3PAO on the agency's paper if agency budget is the pacing item. If the agency cannot commit to those on their side, the January date was aspirational to start with.

"We can save money by using our internal team instead of a 3PAO." You cannot. FedRAMP explicitly requires an accredited 3PAO for the assessment. Internal teams can do the pre-assessment, the gap analysis, and the ongoing continuous monitoring, but the ATO itself needs the 3PAO signature. Trying to route around this is the exact failure mode that gets ATOs revoked in the first agency review post-authorization.

The bottom line

Six weeks is a real window for a specific kind of work: assessment, planning, evidence-collection setup, procurement cleanup. It is not the window for anything that ends with an agency signature, and pretending otherwise is how a defensible Q4 obligation turns into a Q1 IG finding. The subcontractors that win the follow-on FY27 work are the ones whose FY26 statements of work delivered exactly what they scoped, on time, with no renegotiation memo attached. The ones that lose the FY27 work are the ones whose FY26 milestones slipped into November while the invoice sat.

The federal Q4 window is not for shipping the destination. It is for buying yourself the map, the fuel, and the vehicle so the drive in October actually starts. Scope for that. Bill for that. And save the ATO delivery for the fiscal year where it can actually land.

Where this matters next

Share this article:

Ready to build your security program?

See how easy it can be.