What It Costs, Who Pays It, and What It Does Not Promise.
Roughly 2.3 full-time equivalents for 18 months — 780 person-days, peaking at about 2.8 FTE in the middle phase — drawn mostly from people who already hold these roles. Holding the result afterwards costs about 2 hunters. In exchange the program can state which forms of defensive maneuver it cannot perform, what share of its ground is currently cleared and for how long that claim stands, and whether its decision loop is closing faster than its adversaries adapt. None of those three questions has an answer today.
Every figure computed from the roadmap’s own per-role estimates · 230 working days per person-year
Two and a Bit People, for Eighteen Months.
The effort has been in the roadmap since it was written, expressed as person-days inside a page about sequencing. That is the right place for a program lead planning a quarter and the wrong place for the conversation that decides whether the quarter happens.
Where the Eighteen Months Land, and on Whom.
Left is what a staffing plan needs. Right is what a sponsor needs — and the inversion between them is the single most useful thing on this page.
And When Each Function Is Actually on the Hook.
The bar above is the total; this is the sequence. A resourcing plan fails on the second one — a role that is loaded in every phase cannot be borrowed for a quarter and handed back.
| Phase | Duration | Person-days | Concurrent FTE |
|---|---|---|---|
| A Establish doctrine | 3 months | 117 | 2 |
| B Emplace the maneuvers | 6 months | 323 | 2.8 |
| C Achieve tempo | 9 months | 340 | 2 |
No dollar figures, deliberately. Loaded rates differ by a factor of three between an in-house GS-13, a contractor on an existing vehicle, and a consulting firm — a page that picks one is wrong for almost every reader while looking authoritative. FTE survives the translation; your finance office applies its own rate in one step. Phase A/B/C above is this rollout's own numbering, not the framework's six campaign phases — a program keeps declaring those long after this table is spent.
The signature is 3% of the work.
The Authorizing Official approves the program and carries 22 days — that figure combined with the CISO, who sponsors rather than executes and carries no separate count. Platform engineering approves nothing and carries 282 — more than the next two functions combined.
That asymmetry is not a curiosity, it is the failure mode. The case gets made to the person who can approve it, approval is granted, and the work lands on a group who were not in the room and whose year is already committed. Anyone proposing this needs the second conversation more than the first — and needs to arrive at it with a bounded, scheduled ask rather than a mandate.
Carries more of the work than anyone and is usually told about it after the decision.
Contributes across all three phases; see the role profile for the controls it owns.
Gains authority, and is the function most likely to already be at capacity.
Contributes across all three phases; see the role profile for the controls it owns.
Contributes across all three phases; see the role profile for the controls it owns.
Accountable for a risk decision they currently take on evidence that describes controls rather than position.
Six Conversations, and What Each One Will Say.
Not strawmen. Each objection below is the reasonable thing that person says, and the answer carries its caveat rather than dodging it — a case that survives only unchallenged is not a case.
Authorizing Official
22 days (AO + CISO combined) — the smallest load and the only signatureAccountable for a risk decision they currently take on evidence that describes controls rather than position.
What makes it worth their while. To be able to say what the agency can and cannot do defensively, in a sentence, under questioning.
“This is another framework and another set of documents for me to sign.”
Six decisions per phase, not documents — and one of them, the defensive intent, has to name something you are willing to see degraded. That is the hardest hour in the program and it is the one nobody else can do for you. Everything downstream is a consequence of that paragraph.
Platform and system owners
282 days — 36% of the programCarries more of the work than anyone and is usually told about it after the decision.
What makes it worth their while. A bounded, scheduled ask with an end date, spread across the owners who already hold the systems.
“Another security program that wants my engineers for an unbounded period.”
Most of it is ground truth you are the only source of — inventory, ownership, zones, connections, recovery objectives — and it is front-loaded into the first two phases. It is spread across six to ten people rather than landing on one, and the sequence is published so a system owner can see their own quarter.
CISO or program lead
Sponsorship rather than execution — counted inside the AO’s day figure above, not tracked separatelySponsors it, and owns the answer when someone asks whether the program is getting better.
What makes it worth their while. A defensible trend, and a way to make a capability argument that survives a budget conversation.
“We already run the RMF and report against CSF. Why add a third thing?”
Because neither answers what your defense can do. Both are organized around whether controls are in place; this is organized around whether the defense can move, and the two are not the same estate. Every control here inherits from SP 800-53 rather than competing with it, so nothing you have done is re-done.
Budget and resourcing
Approves roughly 2.3 FTE for 18 monthsApproves the FTE, and has heard a security business case before.
What makes it worth their while. The ask in a unit they budget in, and an honest account of what it does not do.
“We already spend heavily on security tooling. What does this retire?”
No tooling, and it may reveal a gap that needs buying. What it retires is the annual maturity exercise and the narrative half of continuous-monitoring reporting — and it converts “we need more detection”, which cannot be adjudicated, into a named capability the program cannot perform, which can.
SOC leadership
135 days — 17% of the programGains authority, and is the function most likely to already be at capacity.
What makes it worth their while. Pre-authorized action. Most of the SOC load here buys the standing authority to act without escalating.
“We are drowning in alerts. This adds process on top of that.”
The pre-authorized set is the point: containment actions the SOC may take without a phone call, with their reverse actions written down. The framework measures the latency of every action that waited on an approval, which makes the case for widening that set with evidence instead of argument.
ISSO, IG and external oversight
125 days — mostly inheritance mapping and the authority recordReads the output, and is the one audience whose interests are already aligned.
What makes it worth their while. Evidence with a denominator, and a record of what was decided under what authority.
“Is this a self-assessment we are being asked to take on trust?”
It is a self-assessment, stated as one, against a published method with the procedures written out per control. What makes it checkable is that the tier is reported with the constraint that bound it and coverage is reported with its remainder — both of which are findings against the program rather than claims for it.
Four Things It Retires, and None of Them Is a Product.
The list is shorter than a vendor’s and longer than nothing. A case that claims this replaces tooling loses the room the first time somebody checks.
A consultancy is engaged, scores the program against a model nobody uses afterwards, and leaves a slide. The tier is computed from the same evidence the cycle already produces, every cycle, by the people who produced it.
Hunting without a denominator re-covers ground nobody recorded as covered. The clearing drill makes each pass a dated statement with an expiry, so the second pass starts where the first stopped rather than where the last conference talk pointed.
The cycle record is written to be read as continuous-monitoring evidence. That does not remove the obligation; it removes the separate exercise of assembling a story for it after the fact.
“Do we need more detection?” cannot be adjudicated by anyone. “We cannot perform four of the eleven forms of maneuver, and these are the four” can be — it names a capability, it can be priced, and it can be argued against on its merits rather than on whose turn it is.
Five Things This Does Not Do.
Each is something a reader might reasonably assume from the rest of this site, and each assumption is expensive to discover in month nine.
- It does not replace NIST SP 800-53, the RMF, or your ATO. Every control here inherits rather than competes, and an agency that adopts this still does all of that.
- It does not reduce tooling spend. Nothing in the framework is a product, and reaching tier 3 is more likely to reveal a gap that needs buying than to retire a license.
- It does not lower headcount. The 780 person-days are additional work in the first eighteen months, drawn mostly from people who already have jobs.
- It does not promise fewer incidents. What it measures is temporal advantage, and a program can be winning on that measure in the same quarter it is breached. Anyone selling this internally on incident counts is setting up a promise the framework never made.
- It is not a certification. No accrediting body, no registered assessor, no badge. What a tier claims is weaker than a certificate and more useful: the scoring method is published, so a skeptic can rerun it and reach a different number, and then you have an argument about evidence rather than about credentials.
Say the fifth one out loud, early. A tier ladder invites the reading that somebody external confers it, and a sponsor who briefs it that way will be corrected in public by the first person who checks. Brief it as what it is — a number the program computes about itself, by a method anyone can rerun — and the same fact stops being a weakness in the case and becomes the reason to trust the number.
Spend Maps to Tier, and Tier Maps to a Sentence You Can Say.
The phases are sequenced to reach a tier, not to finish a checklist. What a sponsor is buying is the right to make a specific claim, and to have it checked.
| Tier | The claim it entitles |
|---|---|
| Tier 1 Mapped | “We know what ground we hold.” |
| Tier 2 Arrayed | “We have decided what we are defending and how.” |
| Tier 3 Maneuvering | “The loop turns, and we can perform every form of maneuver.” |
| Tier 4 Measured | “We know whether it is working, and we have been wrong.” |
The full tier definitions, their gates and what each one explicitly does not mean are on the assessment method. The phase-by-phase sequence is on the adoption path.
The Cheapest Version of This Is One Room, in One Cycle.
Before committing eighteen months, run the drill once on the highest-consequence segment you have. It takes half an analyst-day, it produces a real clearance record, and the time it takes is the input that turns the whole staffing model from an estimate into your number.