Integrations · eMASS

Keep eMASS. Stop hand-feeding it.

eMASS is where your authorization data has to live. It is not where the work happens. CertiField imports what is already there, holds the operational record as the system changes, and exports back — so the system of record stays current without anyone re-keying it.

  • Round-trip
  • mTLS
  • Control info
  • CCI test results
  • POA&M
  • Inventory
Ref
I-11
Kind
Inbound
Sessions
baseline · POA&M

Import what you already have.

Bring in the control baseline and the POA&M as import sessions, so the load is a reviewable event rather than a silent overwrite. Both files in a two-file import are validated before either is persisted — a bad second file does not leave you half-imported.

Imported metadata stays labeled as imported. Inheritance recorded upstream is carried as what eMASS said, not promoted into a native determination CertiField never made.

Ref
I-12
Kind
Outbound
Transport
mutual TLS
Upsert key
external POA&M id

Export back, without creating duplicates.

Push control information, per-CCI test results, POA&M items and inventory, or assemble the whole authorization package as a bundle. The connection is mutual TLS with the client certificate held as an environment secret, never in configuration a diff would carry.

POA&M items upsert on the external identifier eMASS assigned them, which is what makes the round trip safe: a second export updates the item your reviewers already have open instead of raising a new one beside it.

  • Control information — implementation state per control
  • CCI test results — per-CCI assessment outcomes
  • POA&M — upserted on external identifier
  • Inventory — the current asset picture
  • Package bundle — assembled from the record on demand
Ref
I-13
Kind
Position

Why this is not a competitive claim.

We do not position CertiField against eMASS, and we would be suspicious of anyone who did. A program that is required to submit through eMASS is going to submit through eMASS. The question worth asking is what maintains the data that ends up there, and today the honest answer for most programs is a person, a spreadsheet and a deadline.

Good. Keep it. CertiField makes maintaining it dramatically less manual.

The same applies to Xacta and to other repositories a customer is required to feed. CertiField is designed to coexist with an existing authorization system of record; eMASS is the built integration, and other repositories are supported through the package export.

Next step

See what your RMF process looks like when the package keeps up with the system.