Skip to main content
—
Framework library
Framework module · arc-ampe-v1-02

ARC-AMPE

CMS's NIST-aligned security and privacy framework for ACA administering entities and applicable partner entities. Volume II supplies tailored control baselines and system security and privacy plan templates; applicability depends on entity type, law, regulation, or contract.

v1.02 · CMS — Direct Enrollment Entity Resources · published 2025-04-10

Standing today
Onboardable
10 evidence lanes · 308 control units

00Answer

from the registry record
What is ARC-AMPE?
CMS's NIST-aligned security and privacy framework for ACA administering entities and applicable partner entities. Volume II supplies tailored control baselines and system security and privacy plan templates; applicability depends on entity type, law, regulation, or contract.
Who does ARC-AMPE apply to?
ARC-AMPE applies to healthcare, insurance, federal, US, per CMS — Direct Enrollment Entity Resources.
What is the current version of ARC-AMPE?
The current edition is v1.02, issued by CMS — Direct Enrollment Entity Resources and published 2025-04-10. Source: https://www.cms.gov/marketplace/resources/regulations-guidance.
What does an assessment under ARC-AMPE require?
308 control units are on record (308 controls (175 base, 133 enhancements) across 20 families, parsed from ARC-AMPE_Vol2_SSPP-DE-Entity_v1.0-508_07072025.xlsx, sheet "DEE Mandatory Baseline". This is the ingested DEE mandatory baseline, not the size of ARC-AMPE as published.), organized into 20 control families: AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR.

01Standing

Onboardable

A project opens into evidence lanes with a real control set behind them; collection is demonstrative until a test plan runs against a real target.

Blueprint with 10 evidence lanes and a control set; no registered test plans yet. A project opens into real lanes; collection is demonstrative until a READY plan or a release path exists.

Engagement
ARC-AMPE control baseline assessment
Control set
308 controls (175 base, 133 enhancements) across 20 families, parsed from ARC-AMPE_Vol2_SSPP-DE-Entity_v1.0-508_07072025.xlsx, sheet "DEE Mandatory Baseline". This is the ingested DEE mandatory baseline, not the size of ARC-AMPE as published.
Native identifiers
NIST SP 800-53 Rev. 5 control identifiers as tailored by ARC-AMPE, e.g. AC-02, AC-02(01), SC-08(01).
Evidence lanes
  1. 01Access Control and Identificationidentity provider configuration export · account inventory and access review records · privileged access authorization records · session and remote access configuration
  2. 02Audit and Accountabilitylog source inventory · audit record retention configuration · log review and alerting evidence
  3. 03Configuration, Acquisition, and Supply Chainbaseline configuration export · change control records · software inventory and provenance · supplier assessment records
  4. 04Contingency Planning and Incident Responsecontingency plan and test results · backup and restoration evidence · incident response plan and exercise records · incident tickets for the audit window
  5. 05Assessment, Authorization, Planning, and RiskSSPP · SAR · POA&M · risk assessment and vulnerability scan results · interconnection security agreements
  6. 06Personnel Security, Awareness, and Trainingrole-based training completion records · screening and onboarding records · separation and transfer records
  7. 07Physical Protection, Media, and Maintenancefacility access records or provider attestation · media handling and sanitization records · maintenance authorization records
  8. 08System and Communications Protectiontransport encryption configuration · cryptographic module and key management evidence · boundary protection configuration
  9. 09System and Information Integrityflaw remediation and patch records · malicious code protection configuration · monitoring and alerting evidence
  10. 10PII Processing and Transparencyprivacy notice and consent evidence · PII inventory and processing records · authority-to-process documentation

02Registry record

checked 2026-08-30
Registry status
Beta · catalog on diskParsed catalog: a source-pinned control or requirement catalog for this regime exists in the repo. `catalogPath` is non-null and `controlCount` is real. This does not mean tenant workflows are activated or that an assurance outcome has been earned.
Control units
308308 controls (175 base, 133 enhancements) across 20 families, parsed from ARC-AMPE_Vol2_SSPP-DE-Entity_v1.0-508_07072025.xlsx, sheet "DEE Mandatory Baseline". This is the ingested DEE mandatory baseline, not the size of ARC-AMPE as published.
Control families
AC · AT · AU · CA · CM · CP · IA · IR · MA · MP · PE · PL · PM · PS · PT · RA · SA · SC · SI · SR
Applies to
healthcare · insurance · federal · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30

03Version ledger

2 editions
MARS-E 2.2Superseded2021-02-23
v1.02Current edition · supersedes MARS-E 2.22025-04-10

04Authority intelligence

reviewed 2026-08-30

Curated primary-source signals connected to this registry record. An authority change creates review work; it does not silently change tenant posture, evidence credit, or prior decisions.

  1. Program update

    CMS publishes Year 9 EDE audit guidance for PY 2026–2027.

    The current operational-readiness guidance preserves program-native requirements across application, API, privacy, security, and third-party audit work.

    Operating move

    Keep the CMS source identifier, scenario, persona, environment, collection method, blocker, and reviewer decision attached to every artifact candidate.

05Change history

06Related frameworks

scored from registry facts
  1. CMS Enhanced Direct EnrollmentYear 9 (PY 2026–PY 2027)

    Also applies to healthcare · The pathway that lets a web broker or issuer run the whole ACA enrollment experience on its own site instead of handing the consumer off to HealthCare.gov.

  2. Also applies to insurance · A model law for insurance-sector information security programs, incident response, and breach notification, adopted individually by roughly 25-28 US states as of 2026. It becomes enforceable law only where a state has enacted its own version — the requirements can vary state to state.

  3. FISMAFederal Information Security Modernization Act of 2014

    Also applies to federal · The Federal Information Security Modernization Act of 2014 — the statutory authority a federal RFP names, implemented operationally through NIST SP 800-53 and the NIST Cybersecurity Framework, both already tracked as their own registry entries.

  4. GAO FISCAMJune 2026 (GAO-26-108633)

    Also applies to federal · The federal audit methodology for assessing the design, implementation, and operating effectiveness of information-system controls under generally accepted government auditing standards. It is audit guidance, not an agency authorization or certification.

ARC-AMPE | ControlFrame