What is a reasonable cost estimate for a System Certification and Accreditation?
OMB Circular A-130 requires federal agencies to plan for security, ensure that appropriate officials are assigned security responsibility, and authorize system processing prior to operations and, periodically, thereafter. This authorization by senior agency officials is sometimes referred to as accreditation. The technical and non-technical evaluation of an IT system that produces the necessary information required by the authorizing official to make a credible, risk-based decision on whether to place the system into operation, is known as certification. The cost of doing a Certification and Accreditation for a system depends on the completeness of the supporting documentation, the sensitivity of the system, and the complexity of the system. Therefore, the costs may vary widely. Those who have input to NIST on this question have reported figures ranging from $80,000 to $500,000. We have no official figures for the entire federal sector. In future C & A activity, we hope to collect more