ASOM-Fedv6.1Open the explorer
The business case

What It Costs, Who Pays It, and What It Does Not Promise.

Roughly 2.3 full-time equivalents for 18 months — 780 person-days, peaking at about 2.8 FTE in the middle phase — drawn mostly from people who already hold these roles. Holding the result afterwards costs about 2 hunters. In exchange the program can state which forms of defensive maneuver it cannot perform, what share of its ground is currently cleared and for how long that claim stands, and whether its decision loop is closing faster than its adversaries adapt. None of those three questions has an answer today.

Every figure computed from the roadmap’s own per-role estimates · 230 working days per person-year

The Ask

Two and a Bit People, for Eighteen Months.

The effort has been in the roadmap since it was written, expressed as person-days inside a page about sequencing. That is the right place for a program lead planning a quarter and the wrong place for the conversation that decides whether the quarter happens.

780Person-daysAcross 18 months
2.3FTE averagePeaking at 2.8
3.4Person-yearsIf you budget that way
2Hunters afterTo hold the result
Exhibit 1

Where the Eighteen Months Land, and on Whom.

What adoption costs, and who actually pays it Both halves computed from the roadmap's own per-role effort estimates. 2 FTE A 3 mo · 117d Phase A — Doctrine: 117 person-days over 3 months, about 2 concurrent FTE. 2.8 FTE B 6 mo · 323d Phase B — Maneuvers: 323 person-days over 6 months, about 2.8 concurrent FTE. 2 FTE C 9 mo · 340d Phase C — Tempo: 340 person-days over 9 months, about 2 concurrent FTE. EFFORT OVER TIME 780 person-days · 18 months · 2.3 FTE average, 2.8 at peak WHO CARRIES IT PLAT 36% plat — 282 person-days, 36% of the program. CTI 19% cti — 145 person-days, 19% of the program. SOC 17% soc — 135 person-days, 17% of the program. ISSO 16% isso — 125 person-days, 16% of the program. HUNT 9% hunt — 71 person-days, 9% of the program. AO 3% ao — 22 person-days, 3% of the program. The signature is 3% of the work. The 36% is carried by people who sign nothing.

Left is what a staffing plan needs. Right is what a sponsor needs — and the inversion between them is the single most useful thing on this page.

Exhibit 2

And When Each Function Is Actually on the Hook.

The constraint is not the total — it is who is loaded in every phase Effort intensity by role and phase, from the roadmap’s own estimates. PHASE A 3 months PHASE B 6 months PHASE C 9 months PLAT PLAT in phase A: 32 days over 3 months — about 11 days a month. PLAT in phase B: 120 days over 6 months — about 20 days a month. PLAT in phase C: 130 days over 9 months — about 14 days a month. 282d CTI CTI in phase A: 45 days over 3 months — about 15 days a month. CTI in phase B: 60 days over 6 months — about 10 days a month. CTI in phase C: 40 days over 9 months — about 4 days a month. 145d SOC SOC in phase A: 10 days over 3 months — about 3 days a month. SOC in phase B: 70 days over 6 months — about 12 days a month. SOC in phase C: 55 days over 9 months — about 6 days a month. 135d ISSO ISSO in phase A: 20 days over 3 months — about 7 days a month. ISSO in phase B: 45 days over 6 months — about 8 days a month. ISSO in phase C: 60 days over 9 months — about 7 days a month. 125d HUNT HUNT in phase A: 6 days over 3 months — about 2 days a month. HUNT in phase B: 20 days over 6 months — about 3 days a month. HUNT in phase C: 45 days over 9 months — about 5 days a month. 71d AO AO in phase A: 4 days over 3 months — about 1 day a month. AO in phase B: 8 days over 6 months — about 1 day a month. AO in phase C: 10 days over 9 months — about 1 day a month. 22d TOTAL Bar height is days per month, not total. A short spike and a long flat commitment cost the same and are resourced differently. PLAT is the constraint: present in 3 of 3 phases and the heaviest role in 2 of them. That is the conversation to have before the one with the approving authority, not after it.

The bar above is the total; this is the sequence. A resourcing plan fails on the second one — a role that is loaded in every phase cannot be borrowed for a quarter and handed back.

PhaseDurationPerson-daysConcurrent FTE
A Establish doctrine3 months1172
B Emplace the maneuvers6 months3232.8
C Achieve tempo9 months3402

No dollar figures, deliberately. Loaded rates differ by a factor of three between an in-house GS-13, a contractor on an existing vehicle, and a consulting firm — a page that picks one is wrong for almost every reader while looking authoritative. FTE survives the translation; your finance office applies its own rate in one step. Phase A/B/C above is this rollout's own numbering, not the framework's six campaign phases — a program keeps declaring those long after this table is spent.

Where Adoption Actually Fails

The signature is 3% of the work.

The Authorizing Official approves the program and carries 22 days — that figure combined with the CISO, who sponsors rather than executes and carries no separate count. Platform engineering approves nothing and carries 282 — more than the next two functions combined.

That asymmetry is not a curiosity, it is the failure mode. The case gets made to the person who can approve it, approval is granted, and the work lands on a group who were not in the room and whose year is already committed. Anyone proposing this needs the second conversation more than the first — and needs to arrive at it with a bounded, scheduled ask rather than a mandate.

36%
Platform and product owners282 days

Carries more of the work than anyone and is usually told about it after the decision.

19%
Cyber Threat Intelligence cell145 days

Contributes across all three phases; see the role profile for the controls it owns.

17%
SOC / Defensive Operations135 days

Gains authority, and is the function most likely to already be at capacity.

16%
Governance / RMF / ISSO125 days

Contributes across all three phases; see the role profile for the controls it owns.

9%
Hunt team71 days

Contributes across all three phases; see the role profile for the controls it owns.

3%
Authorizing Official / CISO22 days

Accountable for a risk decision they currently take on evidence that describes controls rather than position.

Who Has to Agree

Six Conversations, and What Each One Will Say.

Not strawmen. Each objection below is the reasonable thing that person says, and the answer carries its caveat rather than dodging it — a case that survives only unchallenged is not a case.

Authorizing Official

22 days (AO + CISO combined) — the smallest load and the only signature

Accountable for a risk decision they currently take on evidence that describes controls rather than position.

What makes it worth their while. To be able to say what the agency can and cannot do defensively, in a sentence, under questioning.

“This is another framework and another set of documents for me to sign.”

Six decisions per phase, not documents — and one of them, the defensive intent, has to name something you are willing to see degraded. That is the hardest hour in the program and it is the one nobody else can do for you. Everything downstream is a consequence of that paragraph.

Platform and system owners

282 days — 36% of the program

Carries more of the work than anyone and is usually told about it after the decision.

What makes it worth their while. A bounded, scheduled ask with an end date, spread across the owners who already hold the systems.

“Another security program that wants my engineers for an unbounded period.”

Most of it is ground truth you are the only source of — inventory, ownership, zones, connections, recovery objectives — and it is front-loaded into the first two phases. It is spread across six to ten people rather than landing on one, and the sequence is published so a system owner can see their own quarter.

CISO or program lead

Sponsorship rather than execution — counted inside the AO’s day figure above, not tracked separately

Sponsors it, and owns the answer when someone asks whether the program is getting better.

What makes it worth their while. A defensible trend, and a way to make a capability argument that survives a budget conversation.

“We already run the RMF and report against CSF. Why add a third thing?”

Because neither answers what your defense can do. Both are organized around whether controls are in place; this is organized around whether the defense can move, and the two are not the same estate. Every control here inherits from SP 800-53 rather than competing with it, so nothing you have done is re-done.

Budget and resourcing

Approves roughly 2.3 FTE for 18 months

Approves the FTE, and has heard a security business case before.

What makes it worth their while. The ask in a unit they budget in, and an honest account of what it does not do.

“We already spend heavily on security tooling. What does this retire?”

No tooling, and it may reveal a gap that needs buying. What it retires is the annual maturity exercise and the narrative half of continuous-monitoring reporting — and it converts “we need more detection”, which cannot be adjudicated, into a named capability the program cannot perform, which can.

SOC leadership

135 days — 17% of the program

Gains authority, and is the function most likely to already be at capacity.

What makes it worth their while. Pre-authorized action. Most of the SOC load here buys the standing authority to act without escalating.

“We are drowning in alerts. This adds process on top of that.”

The pre-authorized set is the point: containment actions the SOC may take without a phone call, with their reverse actions written down. The framework measures the latency of every action that waited on an approval, which makes the case for widening that set with evidence instead of argument.

ISSO, IG and external oversight

125 days — mostly inheritance mapping and the authority record

Reads the output, and is the one audience whose interests are already aligned.

What makes it worth their while. Evidence with a denominator, and a record of what was decided under what authority.

“Is this a self-assessment we are being asked to take on trust?”

It is a self-assessment, stated as one, against a published method with the procedures written out per control. What makes it checkable is that the tier is reported with the constraint that bound it and coverage is reported with its remainder — both of which are findings against the program rather than claims for it.

Against the Spend

Four Things It Retires, and None of Them Is a Product.

The list is shorter than a vendor’s and longer than nothing. A case that claims this replaces tooling loses the room the first time somebody checks.

01
The annual maturity exercise

A consultancy is engaged, scores the program against a model nobody uses afterwards, and leaves a slide. The tier is computed from the same evidence the cycle already produces, every cycle, by the people who produced it.

02
Unstructured hunt effort

Hunting without a denominator re-covers ground nobody recorded as covered. The clearing drill makes each pass a dated statement with an expiry, so the second pass starts where the first stopped rather than where the last conference talk pointed.

03
The narrative half of POA&M and continuous-monitoring reporting

The cycle record is written to be read as continuous-monitoring evidence. That does not remove the obligation; it removes the separate exercise of assembling a story for it after the fact.

04
Capability arguments that cannot be settled

“Do we need more detection?” cannot be adjudicated by anyone. “We cannot perform four of the eleven forms of maneuver, and these are the four” can be — it names a capability, it can be priced, and it can be argued against on its merits rather than on whose turn it is.

Before You Commit

Five Things This Does Not Do.

Each is something a reader might reasonably assume from the rest of this site, and each assumption is expensive to discover in month nine.

Say the fifth one out loud, early. A tier ladder invites the reading that somebody external confers it, and a sponsor who briefs it that way will be corrected in public by the first person who checks. Brief it as what it is — a number the program computes about itself, by a method anyone can rerun — and the same fact stops being a weakness in the case and becomes the reason to trust the number.

What the Money Buys

Spend Maps to Tier, and Tier Maps to a Sentence You Can Say.

The phases are sequenced to reach a tier, not to finish a checklist. What a sponsor is buying is the right to make a specific claim, and to have it checked.

TierThe claim it entitles
Tier 1 MappedWe know what ground we hold.
Tier 2 ArrayedWe have decided what we are defending and how.
Tier 3 ManeuveringThe loop turns, and we can perform every form of maneuver.
Tier 4 MeasuredWe know whether it is working, and we have been wrong.

The full tier definitions, their gates and what each one explicitly does not mean are on the assessment method. The phase-by-phase sequence is on the adoption path.

Next

The Cheapest Version of This Is One Room, in One Cycle.

Before committing eighteen months, run the drill once on the highest-consequence segment you have. It takes half an analyst-day, it produces a real clearance record, and the time it takes is the input that turns the whole staffing model from an estimate into your number.