Skip to main content
ControlFrame
First deep ControlFrame module

CMS EDE evidence infrastructure, not a demo shortcut.

ControlFrame CMS EDE helps EDE entities, web-brokers, issuers, and implementation partners turn CMS source requirements, private-runner collection, security artifacts, and reviewer decisions into one audit-readiness package path.

Repository receipt · public verification record

Checked-in CMS EDE proof

Repository record valid
Server-renderedSnapshot controlframe.public-commercial-proof.v1
Regulator source corpus
1,155CMS source rows
1,121 unique native IDs
Deterministic receipt
90verification inputs
59 artifact · 21 archive hash checks passed
Readiness ledger
41% weighted
Gate state
1 passed · 5 blocked · 3 in review
External close gates
16 open
CMS certification
Not claimed
Verification input root · SHA-256a8fbedd19bd7a1d553830ecc9700ab4af88498b6a614e1be35874b12c7ba8ce1
Repository-only record · no approval claimed

This receipt verifies checked-in counts, bytes, and hashes. It does not establish CMS approval, auditor acceptance, customer acceptance, economic impact, or production activation.

Buyer operating outputs

Secondary to the receipt · available through a governed engagement

  • CMS EDE source-row evidence map
  • Application UI and Eligibility toolkit coverage
  • API FIT request/response evidence slots
  • EDN, notice retrieval, and communications evidence
  • Privacy/security audit artifact index
  • Vulnerability scan and penetration-test evidence slots
  • Reviewer/redaction/export decision trail
  • Auditor package readiness dashboard
Repository-verified CMS EDE lighthouse · 2026-08-07

The strongest claim is the one the checked-in record can reproduce.

The verification snapshot confirms the checked-in regulator-native source corpus, exact verification inputs, and an honest readiness ledger. Blocked and review gates stay visible; the instrument never converts repository integrity into an approval claim.

CMS source rows
1,155
1,121 unique native IDs
Verification inputs
90
Counted in the deterministic receipt
Weighted gate readiness
41%
1 passed · 5 blocked · 3 in review
External close gates open
16
Deliberately unresolved, never auto-cleared
This record verifies repository counts, bytes, and hashes only. It does not establish CMS approval, auditor acceptance, customer acceptance, economic impact, or current production activation.
Evidence chain

CMS source row

Application UI, Eligibility Results, Partner Test Case Suite, API FIT, Communications, EDN, identity, onboarding, and security references stay native.

Private runner job

When activated for an authorized engagement, browser, API, document, and scanner collection runs inside the customer or operator boundary with scoped target access.

Mapped artifact

Screenshots, text extracts, JSON payloads, checksums, and sidecars are attached to source IDs instead of floating in folders.

Review gate

Redaction, blocker triage, sufficiency review, and export approval happen before evidence enters an auditor package.

Governed reuse walkthrough

Collect once. Reuse only what survives review.

Follow one versioned evidence object from its native CMS record into NIST and HIPAA. The artifact stays singular; every target mapping keeps its own authority, reviewer decision, freshness gate, and delta.

Synthetic reference workflowNo tenant data or write

Propose: The cited atlas proposes where the accepted source artifact may help. Every cross-framework edge remains a candidate and contributes zero.

Governed evidence objectSource accepted

consent-confirmation-event.json

EV-2048 · Runtime event

Version
v1.2
Digest
sha256:8df1…a43c
Source
Enrollment API
Owner
EDE product assurance
Sensitivity
Restricted · synthetic
Native mappings
2
Collection run
RUN-8837
Source review
Reviewer 01 · accepted
Freshness gatecurrent · 30-day policy
Current

Reuse invalidates when freshness expires, source version changes, scope changes, control changes.

Stage 01 · decision register

Find applicable controls

The cited atlas proposes where the accepted source artifact may help. Every cross-framework edge remains a candidate and contributes zero.

4 obligations · 2 frameworksNamed reviewer required
Candidate credit
0
4 awaiting review
Credited mappings
0
accepted or released only
Held deltas
0
targeted proof still required
Repeat asks avoided
0
reference framework lanes
  1. NIST CSF 2.0DE.CM-09
    Computing activity and technology usage monitoring

    Candidate support for monitoring evidence; it does not satisfy the outcome alone.

    NIST CSF 2.0
    Candidate · 0 creditNo status or request avoidance
  2. NIST CSF 2.0PR.DS-01
    Confidentiality, integrity, and availability of data at rest

    Candidate support from digest and custody metadata; reviewer confirmation is pending.

    NIST CSF 2.0
    Candidate · 0 creditNo status or request avoidance
  3. HIPAA164.312(b)
    Audit controls

    Candidate support for an audit-control record within the scoped system.

    45 CFR
    Candidate · 0 creditNo status or request avoidance
  4. HIPAA164.312(c)(1)
    Integrity

    Candidate support from the validated digest; it does not establish compliance alone.

    45 CFR
    Candidate · 0 creditNo status or request avoidance

A named reviewer must confirm scope, sufficiency, and the remaining delta.

Collection policyAsk the owner only for the delta—not for evidence already governed.

A repeat request is avoided only after a named reviewer accepts the mapping and while the exact artifact version remains current. The counts above explain this reference workflow; they are not measured customer savings.

Instructional projection over checked-in synthetic evidence. Stage controls do not write tenant state or represent customer, assessor, or regulator acceptance.

Private boundary

Collect regulated evidence without turning raw systems into another SaaS integration surface.

The web app remains the control plane. The runner executes inside the customer or operator environment, where target URLs, personas, CMS endpoints, MFA, certificates, and raw artifacts can be controlled.

Secrets stay local

Runner manifests describe required inputs and allowed commands without storing credentials, tokens, mTLS keys, or MFA details.

Every artifact is hashed

Screenshots, JSON, text extracts, source maps, and exports keep checksum and review metadata attached.

Durable runner jobs

Jobs are queued, claimed, heartbeated, finalized, and visible to operators before package release.

Audit-readiness language

ControlFrame organizes evidence and packages. Final audit decisions remain with the auditor and CMS process.

Implementation path

From scope to package without hiding blockers.

Step 1

Confirm entity, application, markets, environments, and EDE scope.

Step 2

Bind target URLs, personas, CMS UAT/API access, and approved collection windows.

Step 3

Run preflight against source rows, credentials, target boundaries, and blockers.

Step 4

Collect evidence through the private runner or approved manual/connector intake.

Step 5

Review, redact, approve, and package only source-mapped artifacts.

ControlFrame CMS EDE — Evidence Infrastructure for Audits