Certificate of Networthiness (CoN): Meaning and Requirements
A Certificate of Networthiness (CoN) was a U.S. Army approval verifying that a software application met strict standards for security, integration, and reliability before operating on Army networks like LandWarNet. Issued by the U.S. Army Network Enterprise Technology Command (NETCOM), a Certificate of Networthiness applied strictly to software applications rather than individual personnel.
Although the Army largely replaced the traditional Certificate of Networthiness process in 2018 with the Risk Management Framework (RMF) “Assess Only” pathway, understanding the legacy and requirements of a CoN remains critical for legacy system management and defense compliance.
Who this article is for
- Cybersecurity and IT professionals encountering legacy references to a Certificate of Networthiness, RMF, or ATO within U.S. Army and Department of Defense environments.
- Defense contractors and software vendors navigating compliance frameworks and historical requirements related to a Certificate of Networthiness for military deployments.
- Cybersecurity students and job seekers looking to decode a CoN and modern DoD authorization terminology in technical documentation and job descriptions.

This guide breaks down what a Certificate of Networthiness meant, who required it, the core security mandates involved, how the evaluation process functioned, and how organizations navigate compliance now that RMF governs these authorizations.
What is a Certificate of Networthiness (CoN)?
A Certificate of Networthiness (CoN) was an official product-level validation issued by the U.S. Army Network Enterprise Technology Command (NETCOM) confirming that a specific software application met the military’s strict standards for security, interoperability, and integration before being permitted to operate on Army enterprise infrastructure, such as LandWarNet (LWN).
Core characteristics of a historical Certificate of Networthiness include:
- Issuer: Governed by Army CIO/G-6 oversight and officially issued by NETCOM.
- Scope: Focused primarily on standalone or client-side software applications (such as tools installable via standard operating system management without requiring a dedicated server architecture), rather than comprehensive enterprise information systems.
- Purpose: Enforced baseline cybersecurity, configuration control, and technical compatibility to prevent unauthorized or vulnerable software from compromising tactical and enterprise networks.
- Distinction from Professional Credentials: A CoN was strictly an authorization for software code and product versions, entirely separate from individual human certifications like CISSP or CompTIA Security+.
Why the Certificate of Networthiness Existed: Purpose and Problems Solved
The U.S. Army established the Certificate of Networthiness (CoN) process to address critical cybersecurity, stability, and administrative vulnerabilities across military infrastructure. Without a centralized review mechanism, deploying unvetted software introduced severe operational risks.
The historical Certificate of Networthiness solved several systemic challenges:
- Risk Mitigation: Verified that a software application met baseline cybersecurity and configuration standards before it ever touched Army networks, preventing vulnerabilities from entering the ecosystem.
- Network Interoperability: Ensured that incoming tools functioned seamlessly alongside existing Army systems, protocols, and hardware configurations without causing operational conflicts.
- Landscape and Inventory Control: Maintained an authoritative inventory of approved applications, eliminating redundant or unapproved tools while vetting software for foreign ownership, control, or influence (FOCI) concerns.
- Inter-Command Reciprocity: Established a centralized standard so that different Army commands and units could trust, share, and reuse approved software without running independent evaluations.
As a rigorous gatekeeping mechanism, the Certificate of Networthiness kept Army networks stable, secure, and manageable against an evolving threat landscape.
Who Needed a Certificate of Networthiness?
The mandate for a Certificate of Networthiness (CoN) applied broadly across the defense acquisition and IT ecosystem, governing who could introduce software into the military environment:
- Software Vendors and Defense Contractors: Commercial entities and defense contractors selling, developing, or deploying applications intended for use on Army enterprise networks were required to secure a CoN before product delivery.
- Army Organizations and Program Managers: Internal military program managers and command elements fielding commercial-off-the-shelf (COTS), government-off-the-shelf (GOTS), or open-source applications on LandWarNet (LWN) or related networks.
- Development Teams Requiring Testing: Products undergoing active testing needed a specialized variant known as a Test CoN (T-CoN), which was tied to an Interim Authority to Test (IATT) before the software could touch live network environments.
While individual IT and cybersecurity professionals did not acquire a Certificate of Networthiness for personal credentials, practitioners routinely encountered CoN compliance requirements when auditing, deploying, or managing software architectures within Department of Defense environments.
Certificate of Networthiness Requirements: What the Army Evaluated
While detailed technical checklists and evaluation criteria resided within official NETCOM guidance and the restricted Networthiness SharePoint Portal, the historical Certificate of Networthiness (CoN) review process generally examined several core operational and security pillars:
Security and Compliance Baseline
Strict alignment with applicable Security Technical Implementation Guides (STIGs) and overarching Army and Department of Defense security directives required to qualify for a Certificate of Networthiness.
- Vulnerability and Supply Chain Analysis: Fundamental security evaluations, including checks for foreign ownership, control, or influence (FOCI) to mitigate supply chain risks before obtaining a Certificate of Networthiness.
- Risk Threshold Validation: Concrete technical evidence demonstrating that the software application could operate effectively without introducing unacceptable vulnerabilities or operational risk to the network infrastructure.
Architecture and Integration
Comprehensive confirmation that the software application would seamlessly integrate with existing Army infrastructure, standard directory services, and enterprise architectures as part of the Certificate of Networthiness evaluation.
- Environmental Behavior Verification: Strict verification that the application behaved predictably within the standardized Army environment, ensuring it utilized no unapproved network ports, unauthorized background services, or conflicting dependencies that could jeopardize a CoN approval.
Configuration Management and Version Control
Enforcement that a Certificate of Networthiness was tightly bound to specific major software versions (typically covering minor releases such as version 1.x up to 2.0), requiring vendors to meticulously track all modifications.
- Update and Recertification Triggers: Strict guidelines dictating that significant architectural updates, code rewrites, or functional expansions invalidated the existing Certificate of Networthiness, necessitating a formal re-evaluation.
- Enterprise Inventory Control: Leveraging the CoN process as an administrative ledger to maintain an authoritative application inventory, prevent software bloat, and eliminate redundant or conflicting tools across commands.
Documentation and Submission Requirements
Comprehensive administrative packages that vendors and program managers were required to compile to successfully navigate the Certificate of Networthiness review workflow, typically including:
- Detailed product descriptions outlining the exact operational purpose and intended use cases on Army enterprise networks.
- Precise version information, configuration details, and comprehensive deployment architecture diagrams.
- Security and hardening documentation strictly aligned with prevailing Army and Department of Defense compliance guidance.
- Pertinent test results, vulnerability scans, and security compliance evidence explicitly requested by NETCOM evaluators before issuing a Certificate of Networthiness.
Validity and Lifecycle Management
Standard approvals for a Certificate of Networthiness were typically valid for a period of three years, strictly covering the approved major software version before requiring a formal renewal.
- Limited Scope Deployments: Issuance of a Limited Certificate of Networthiness (LCoN), which granted operational authorization exclusively for specific regional commands, specialized missions, or restricted use cases rather than enterprise-wide Army deployment.
How the Certificate of Networthiness Process Worked (Historical View)
Historically, navigating the Certificate of Networthiness workflow required a structured, step-by-step approach to military compliance:
- Determine the Authorization Path (CoN vs. ATO): Assess whether the software product required a Certificate of Networthiness or a broader authorization. Standalone client applications (installable like typical desktop software without a dedicated backend server) required a CoN, whereas complex information systems featuring dedicated server components, persistent services, or custom open ports required an Authority to Operate (ATO) under the Risk Management Framework (RMF).
- Compile Documentation and Security Evidence: Gather comprehensive product descriptions, deployment architecture diagrams, vulnerability scan results, and configuration documentation aligned with Security Technical Implementation Guides (STIGs) to support the Certificate of Networthiness submission packet.
- Submit via the NETCOM Networthiness Portal: Upload the required artifacts through the dedicated NETCOM Networthiness SharePoint portal, an administrative environment accessible exclusively with valid U.S. Army credentials and a Common Access Card (CAC).
- Undergo NETCOM Review and Evaluation: NETCOM evaluators thoroughly analyzed the submission package for cybersecurity posture, enterprise network integration, supply chain risk, and configuration management concerns. Upon successful review, a Certificate of Networthiness was officially issued for the designated software version and operational scope.
- Manage Lifecycle, Expiry, and Renewal: Monitor the standard three-year validity window of the Certificate of Networthiness alongside major version upgrades. Submitting for formal renewal or re-assessment was mandatory whenever significant architectural modifications or code updates occurred.
Note: Because extensive standard operating procedures (SOPs), tactical techniques, and submission portals resided behind Department of Defense firewalls requiring a CAC, public-facing technical documentation regarding the legacy Certificate of Networthiness remains intentionally limited.
Certificate of Networthiness vs. ATO vs. RMF: Clearing Up Common Confusion
These three terms frequently appear together in defense IT documentation, leading to widespread confusion among vendors and practitioners. Understanding how they differ clarifies the evolution of military software compliance.
| Term | What it is | Applies to | Current status in the Army |
| Certificate of Networthiness (CoN) | Legacy Army approval verifying software met technical standards to run on military networks. | Primarily client-side applications deployed on LandWarNet. | Largely replaced by the RMF “Assess Only” process since 2018. |
| Authority to Operate (ATO) | Formal risk-based executive authorization permitting an IT system to operate in a specific operational environment. | Full information systems, servers, complex services, and enclaves. | Actively utilized under the Risk Management Framework (Assess & Authorize). |
| Risk Management Framework (RMF) | Department-wide structured process for security categorization, assessment, authorization, and continuous monitoring. | All DoD information systems and assets processing government data. | The current overarching standard across all branches. |
Key Distinctions
- CoN vs. Personal Certifications: A Certificate of Networthiness was never an individual human credential or professional certification (such as CompTIA Security+, CISSP, or CISM) earned through an exam; it was strictly a product-level compliance approval.
- CoN vs. ATO: A Certificate of Networthiness governed individual software applications and client tools, whereas an Authority to Operate (ATO) governs comprehensive enterprise information systems, backend server infrastructures, and network enclaves.
- CoN vs. RMF: A CoN was an Army-specific legacy gatekeeping mechanism, whereas RMF is the universal Department of Defense framework. The modern RMF “Assess Only” pathway effectively absorbs the old Certificate of Networthiness functionality, providing a standardized mechanism to vet standalone software and commercial applications entering the defense ecosystem.
Is a Certificate of Networthiness Still Required? Current Status and What Replaced It
No, a traditional Certificate of Networthiness (CoN) is no longer the active approval mechanism for new software deployments across the U.S. Army.
The transition away from the legacy CoN process rolled out through specific military directives:
- April 2018 Directive: U.S. Army Cyber Command (ARCYBER) officially directed that the Risk Management Framework (RMF) “Assess Only” process would replace the legacy Army Certificate of Networthiness process.
- July 2018 Implementation: The RMF “Assess Only” workflow was mandated Army-wide for software and IT assets that did not require a full “Assess & Authorize” cycle.
- Phase-Out of Legacy Approvals: Existing approvals ran out their standard validity windows, with all renewals and incoming software products funneling directly into the RMF workflow.
What to Do Today in U.S. Army Contexts
When navigating military software deployment and compliance today, the modern framework operates as follows:
- Applications and Standalone IT: Software products that historically required a Certificate of Networthiness now navigate the RMF “Assess Only” pathway—typically managed within the Enterprise Mission Assurance Support Service (eMASS)—by satisfying relevant Security Technical Implementation Guides (STIGs) and security controls.
- Full Information Systems: Comprehensive enterprise systems, backend servers, and network enclaves continue to follow the traditional RMF “Assess & Authorize” path to secure a formal Authority to Operate (ATO).
- Legacy Documentation: Encountering references to a CoN in older contracts, legacy technical documentation, or outdated job descriptions requires treating it as a historical term that maps conceptually to today’s RMF “Assess Only” process for application-level products.
Practical Implications for Different Readers
The Certificate of Networthiness has different implications depending on whether you are an IT professional, cybersecurity practitioner, defense contractor, software vendor, or job seeker. Understanding these distinctions helps clarify when CoN knowledge is relevant and how it relates to modern Army cybersecurity and system authorization requirements.
For Cybersecurity and IT Professionals
- Individual Certifications: You cannot earn a Certificate of Networthiness as a personal credential; it remains exclusively a product-level compliance approval.
- Operational Responsibilities: Your day-to-day duties involving military software will likely require you to:
- Support RMF “Assess Only” packages for applications that historically required a Certificate of Networthiness.
- Map Security Technical Implementation Guide (STIG) findings directly to security controls within the Enterprise Mission Assurance Support Service (eMASS).
- Distinguish clearly between standalone applications (governed by “Assess Only”) and complex systems (governed by “Assess & Authorize”).
- Legacy Context: Understanding the history of the CoN allows you to accurately interpret legacy contracts, older technical documentation, and outdated baseline specifications for stakeholders.
For Defense Contractors and Software Vendors
- Modern Approval Pathways: If your commercial-off-the-shelf (COTS) or custom software targets U.S. Army networks, expect to navigate the RMF “Assess Only” pathway for application-type products or the full RMF process for comprehensive enterprise systems.
- Preparation Requirements: Be fully prepared to deliver:
- Rigorous STIG assessments, static/dynamic code analysis, and vulnerability scan reports.
- Thorough security control documentation mapped out in eMASS.
- Explicit definitions of deployment boundaries, data flows, and inherited security controls.
- Resource Allocation: Budget for ongoing compliance maintenance and recertification cycles rather than treating military deployment authorization as a one-time administrative check.
For Students and Job Seekers
- Decoding Terminology: When encountering terms like Certificate of Networthiness, RMF, or ATO in job descriptions, recognize them as institutional compliance frameworks and authorization mechanics rather than personal certifications you can study for and take an exam to pass.
- High-Leverage Skill Development: Focus your professional development on practical competencies that defense employers value:
- Mastery of the six-step Risk Management Framework (Categorize, Select, Implement, Assess, Authorize, Monitor).
- Practical application of STIGs, baseline security controls, and vulnerability assessment methodologies.
- A clear grasp of the architectural distinctions between application-level compliance and enterprise-level system authorization.
Common Misconceptions About the Certificate of Networthiness
The Certificate of Networthiness (CoN) is often misunderstood as a professional cybersecurity certification that individuals can earn. In reality, it was primarily an Army process for evaluating whether IT products and systems met requirements for use on Army networks. Understanding the most common misconceptions helps distinguish CoN from professional certifications, security frameworks, and modern authorization processes such as RMF and ATO.
- “A Certificate of Networthiness is a personal credential I can earn.”False. A Certificate of Networthiness was strictly a product-level compliance and security approval for software applications, never a professional certification or individual human credential (such as CISSP or Security+).
- “If my software had a Certificate of Networthiness once, it is approved forever.”False. Approvals were time-bound (typically expiring after three years) and rigidly tied to specific major software versions. Any significant code updates, architectural changes, or minor version upgrades could invalidate the existing Certificate of Networthiness and require formal re-evaluation.
- “A Certificate of Networthiness and an Authority to Operate (ATO) are the same thing.”False. A Certificate of Networthiness governed individual client applications and standalone tools, whereas an ATO governs comprehensive enterprise information systems, backend server infrastructures, and network enclaves under the Risk Management Framework.
- “A Certificate of Networthiness is still the primary process for new Army software.”False. Since 2018, U.S. Army Cyber Command officially replaced the legacy CoN process with the RMF “Assess Only” workflow for application-type products.
What does CoN stand for?
CoN stands for Certificate of Networthiness, which was a mandatory U.S. Army approval confirming that a software application met military standards for security, interoperability, and reliability before operating on Army networks.
Who issues a Certificate of Networthiness?
Historically, a Certificate of Networthiness was issued by the U.S. Army Network Enterprise Technology Command (NETCOM) under the oversight of the Army CIO/G-6
Do individuals get a Certificate of Networthiness?
No. A Certificate of Networthiness was never a personal credential or professional certification; it was strictly a product-level compliance and security approval for software applications.
Is a Certificate of Networthiness still used by the U.S. Army?
Not as the primary mechanism. Since 2018, the Army has transitioned away from the legacy Certificate of Networthiness process, replacing it with the RMF “Assess Only” workflow for application-type products.
What replaced the Certificate of Networthiness?
The Department of Defense Risk Management Framework (RMF) “Assess Only” process replaced the Certificate of Networthiness for applications, while comprehensive enterprise systems continue to use the standard RMF “Assess & Authorize” pathway to secure an Authority to Operate (ATO).
How long was a Certificate of Networthiness valid?
A standard Certificate of Networthiness was typically valid for three years and covered the approved major software version (e.g., version 1.0 covering minor updates up to 2.0).
What is the difference between a Certificate of Networthiness and an ATO?
A Certificate of Networthiness was a legacy Army-specific approval for individual software applications, whereas an Authority to Operate (ATO) is a formal, risk-based authorization for comprehensive information systems, servers, and network enclaves under RMF.
In Conclusion
A historical Certificate of Networthiness (CoN) served as an essential U.S. Army product approval verifying that a software application met strict security, integration, and configuration mandates before operating on military networks like LandWarNet. Issued by NETCOM, a Certificate of Networthiness applied strictly to software versions rather than individual human credentials.
Evaluations focused on baseline security compliance, architectural integration, and configuration management, with approvals typically remaining valid for three years per major software release.
Because the Army officially replaced the legacy Certificate of Networthiness process with the Risk Management Framework (RMF) “Assess Only” workflow, defense software and applications no longer pursue a traditional CoN.
Practical Next Step
If you are developing, selling, or deploying software for the U.S. Army, prepare to navigate the RMF “Assess Only” pathway for application-level products or the full RMF “Assess & Authorize” cycle for enterprise systems. Begin aligning your product architecture directly with applicable Security Technical Implementation Guides (STIGs) and mapping security controls in eMASS.



