Home › Blog

What Is a Certificate of Networthiness? A Complete Guide

Certificate of Networthiness Blog

Certificate of Networthiness

If you work in government IT, defense contracting, or enterprise software sales to federal agencies, you’ve likely come across the term “Certificate of Networthiness” β€” often abbreviated as CoN. While it sounds like a financial or legal term at first glance, it has nothing to do with a company’s financial net worth. Instead, it’s a critical compliance credential used specifically by the United States Army to govern what technology can connect to its network.

For vendors trying to sell hardware, software, or IT services to the U.S. Army, understanding the Certificate of Networthiness isn’t optional β€” it’s often the single biggest hurdle between a product demo and an actual contract. This guide breaks down exactly what a Certificate of Networthiness is, why it exists, who issues it, what the approval process looks like, and what it means for both government agencies and the vendors who serve them.

Defining the Certificate of Networthiness

A Certificate of Networthiness is a formal accreditation issued by the U.S. Army that certifies a piece of IT hardware, software, or a networked system meets the Army’s strict requirements for security, interoperability, sustainability, supportability, and usability before it can be connected to or operated on the Army’s enterprise network infrastructure, commonly referred to as LandWarNet (LWN).

In simpler terms: before any external software product, device, or system can be plugged into the Army’s network β€” whether that’s a cybersecurity tool, a learning management system, a storage solution, or an asset-tracking platform β€” it must first prove that it won’t introduce security vulnerabilities, compatibility conflicts, or operational risks into that network. The CoN is the Army’s way of formally documenting that proof.

The certification isn’t limited to the active-duty Army alone. It applies to all National Guard, Army Reserve, and Department of Defense organizations that use the Army Enterprise Infrastructure Network, which means the reach of this single certificate extends well beyond any one command or installation. avnetwork

Why the Certificate of Networthiness Exists

The Army manages one of the largest and most complex enterprise networks in the world, spanning installations, deployed units, reserve components, and countless connected systems across the globe. Every additional device or piece of software introduced into that environment is a potential point of failure or attack.

The Networthiness Program was created specifically to manage this risk. According to information from federal contracting notices, the CoN approval process exists to enhance and ensure interoperability and integration across the Army Enterprise, and Army Regulation (AR) 25-1 mandates the assessment of NetOps products against the architecture to ensure they meet functional and interoperability requirements. samdaily

Put another way, the certificate serves several overlapping purposes:

  1. Security assurance β€” verifying that a product won’t create exploitable vulnerabilities within the network
  2. Interoperability β€” confirming the product will work correctly alongside existing Army systems, rather than conflicting with them
  3. Sustainability β€” ensuring the vendor can support and maintain the product over its expected lifecycle
  4. Risk mitigation and compliance β€” aligning IT purchases with DoD and Army regulatory frameworks
  5. Standardization β€” preventing an uncontrolled sprawl of incompatible tools and systems across a network this large

As one vendor press release summarized it, the U.S. Army Networthiness Program was created for compliance and risk mitigation purposes and ensures that all IT purchases meet Federal Department of Defense and Army guidelines, regulations and requirements. cyberark

Who Issues the Certificate of Networthiness

The authority responsible for issuing the CoN is the U.S. Army Network Enterprise Technology Command, commonly known as NETCOM, working in conjunction with the 9th Signal Command (Army). This unit is tasked with operating, maintaining, and securing the Army’s global information network, which makes it the natural authority for deciding what is and isn’t allowed to connect to it.

Per federal solicitation documentation, NETCOM/9th Signal Command has responsibility to ensure all NetOps products are compliant to the LandWarrior Network Architecture (LNA) prior to issuing a Certificate of Networthiness to acquire, field, or connect to the Army’s Enterprise. samdaily

This means that regardless of which Army command, base, or program office wants to purchase or use a particular IT product, that product still has to go through NETCOM’s centralized vetting process. This centralization is deliberate β€” it prevents individual units from independently introducing unvetted technology into a shared, interconnected network.

What Products and Systems Require a CoN

Broadly speaking, any technology that will connect to, operate on, or interact with the Army’s enterprise network requires a Certificate of Networthiness. This has historically included a wide range of product categories, based on real-world examples of companies that have received the certification:

  • Cybersecurity and privileged access management tools β€” solutions that manage credentials, monitor for anomalous activity, and protect against insider or external threats
  • Storage and virtualization software β€” such as iSCSI SAN solutions used in virtualized data center environments
  • Enterprise resource and asset management platforms β€” including inventory tracking and resource management suites
  • Learning management systems (LMS) β€” platforms used for training and workforce development across Army organizations
  • Security information and event management (SIEM) tools β€” used for log analysis, threat detection, and compliance reporting
  • RFID and asset-tracking technologies β€” used for logistics, inventory, and supply chain visibility
  • Collaboration and content management platforms β€” such as enterprise content management or portal solutions

In short, if a product touches Army data, Army devices, or the Army network in any operational capacity, it very likely falls under the CoN requirement, as confirmed by the range of vendors β€” from cybersecurity firms to SIEM providers to LMS companies β€” that have publicly announced receiving this certification over the years.

The Certificate of Networthiness Approval Process

While the exact procedural details can vary depending on the type of product and the specific regulatory guidance in effect at the time, the general CoN process follows a consistent structure:

Step 1: Product Assessment Submission

The vendor or requiring Army activity submits the product for assessment, along with technical documentation describing its architecture, security posture, and intended use case within the network.

Step 2: Compliance Checklist Review

The product is evaluated against compliance checklists tied to the LandWarNet Network Architecture (LNA). Federal contracting documentation notes that these checklists provide an overview of the specific LNA capability requirements, along with detailed compliance checklists outlining functional and interoperability requirements, and vendors are encouraged to self-assess their products against these criteria before formal submission. samdaily

Step 3: Technical and Security Evaluation

NETCOM technical teams evaluate the product across the core pillars of security, interoperability, sustainability, supportability, and usability. This is typically the most rigorous phase, involving detailed technical review of how the product handles data, authentication, network traffic, and potential attack surfaces.

Step 4: Risk-Based Determination

The assessment culminates in a risk-based determination. As one accreditation notice put it, the CoN is based on a set of consistent, risk-based assessment criteria that supports interoperability across the Army’s systems. cyberark

Step 5: Certificate Issuance

If the product satisfies all requirements, NETCOM issues the formal Certificate of Networthiness, often paired with an Authority to Operate (ATO), which permits the product to be fielded and used within defined Army networks.

Step 6: Renewal and Recertification

Certificates are typically not permanent. Many CoNs are issued with expiration dates, after which the product must be reassessed β€” particularly if there are major software updates, version changes, or shifts in the regulatory framework. For example, one enterprise software solution was reported to have received certification valid through a specific date, requiring recertification as that period ended. executivebiz

Certificate of Networthiness vs. Authority to Operate (ATO)

These two terms are often mentioned together, which can cause confusion. While related, they are distinct:

  • Certificate of Networthiness (CoN): Focuses specifically on whether a product is suitable to connect to and operate within the Army’s network from a technical, security, and interoperability standpoint.
  • Authority to Operate (ATO): A broader risk management authorization (often tied to the DoD Risk Management Framework) that grants formal permission for a system to operate within a given environment, based on an assessment of its overall risk posture.

In many cases, vendors pursue both simultaneously, and public announcements often reference receiving “CoN and ATO” together, since the two work in tandem to authorize a product’s use on Army networks.

Why the CoN Matters for Vendors

For companies selling into the federal and defense space, the Certificate of Networthiness carries significant business value beyond mere compliance. It functions as:

  • A competitive differentiator β€” signaling to government buyers that the product has already cleared a rigorous, independent technical vetting process
  • A sales enabler β€” since many Army program offices simply cannot purchase or deploy a product without an active CoN, having one removes a major procurement obstacle
  • A trust signal β€” extending beyond the Army itself, since other DoD components and even commercial clients often view Army certification as validation of a product’s security and reliability standards more broadly

As one CEO put it following his company’s certification, the CoN accreditation confirms full compliance with security, interoperability, supportability, sustainability, and usability regulations, guidelines, and policies issued by federal, DoD, and Combatant Command/Service/Agency components β€” a distinction that resonates with buyers well beyond the Army alone. netsurion

Common Misconceptions

“Certificate of Networthiness” is not about financial net worth. Despite the similar-sounding name, this certification has no relationship whatsoever to a company’s financial statements, balance sheet, or fiscal health. It is purely a technical and security accreditation related to network connectivity.

It’s not a one-time, universal approval. A CoN is typically tied to a specific product version and use case. Major updates, new deployment environments, or expired certification windows often require reassessment.

It doesn’t guarantee a sale. While the CoN is often a prerequisite for Army procurement, it doesn’t automatically result in a contract β€” it simply clears the technical and security gate that allows a product to be considered for use.

Final Thoughts

The Certificate of Networthiness plays a foundational role in how the U.S. Army protects one of the largest and most mission-critical networks in the world. For vendors, it represents both a regulatory hurdle and a valuable credential β€” one that demonstrates a product has been rigorously tested against some of the toughest security and interoperability standards in the federal government. For Army program managers and IT leaders, it provides assurance that every piece of technology entering the network has been vetted, reducing risk across a system that supports operations ranging from routine administrative tasks to mission-critical, potentially life-or-death communications.

Understanding this certification β€” what it covers, who issues it, and how the process works β€” is essential for any organization hoping to do business with the U.S. Army’s technology ecosystem.