ARC-AMPE
CMS's NIST-aligned security and privacy framework for ACA administering entities and applicable partner entities. Volume II supplies tailored control baselines and system security and privacy plan templates; applicability depends on entity type, law, regulation, or contract.
v1.02 · CMS — Direct Enrollment Entity Resources · published 2025-04-10
00Answer
01Standing
A project opens into evidence lanes with a real control set behind them; collection is demonstrative until a test plan runs against a real target.
Blueprint with 10 evidence lanes and a control set; no registered test plans yet. A project opens into real lanes; collection is demonstrative until a READY plan or a release path exists.
- Engagement
- ARC-AMPE control baseline assessment
- Control set
- 308 controls (175 base, 133 enhancements) across 20 families, parsed from ARC-AMPE_Vol2_SSPP-DE-Entity_v1.0-508_07072025.xlsx, sheet "DEE Mandatory Baseline". This is the ingested DEE mandatory baseline, not the size of ARC-AMPE as published.
- Native identifiers
- NIST SP 800-53 Rev. 5 control identifiers as tailored by ARC-AMPE, e.g. AC-02, AC-02(01), SC-08(01).
- Evidence lanes
- 01Access Control and Identificationidentity provider configuration export · account inventory and access review records · privileged access authorization records · session and remote access configuration
- 02Audit and Accountabilitylog source inventory · audit record retention configuration · log review and alerting evidence
- 03Configuration, Acquisition, and Supply Chainbaseline configuration export · change control records · software inventory and provenance · supplier assessment records
- 04Contingency Planning and Incident Responsecontingency plan and test results · backup and restoration evidence · incident response plan and exercise records · incident tickets for the audit window
- 05Assessment, Authorization, Planning, and RiskSSPP · SAR · POA&M · risk assessment and vulnerability scan results · interconnection security agreements
- 06Personnel Security, Awareness, and Trainingrole-based training completion records · screening and onboarding records · separation and transfer records
- 07Physical Protection, Media, and Maintenancefacility access records or provider attestation · media handling and sanitization records · maintenance authorization records
- 08System and Communications Protectiontransport encryption configuration · cryptographic module and key management evidence · boundary protection configuration
- 09System and Information Integrityflaw remediation and patch records · malicious code protection configuration · monitoring and alerting evidence
- 10PII Processing and Transparencyprivacy notice and consent evidence · PII inventory and processing records · authority-to-process documentation
02Registry record
- Registry status
- Beta · catalog on diskParsed catalog: a source-pinned control or requirement catalog for this regime exists in the repo. `catalogPath` is non-null and `controlCount` is real. This does not mean tenant workflows are activated or that an assurance outcome has been earned.
- Control units
- 308308 controls (175 base, 133 enhancements) across 20 families, parsed from ARC-AMPE_Vol2_SSPP-DE-Entity_v1.0-508_07072025.xlsx, sheet "DEE Mandatory Baseline". This is the ingested DEE mandatory baseline, not the size of ARC-AMPE as published.
- Control families
- AC · AT · AU · CA · CM · CP · IA · IR · MA · MP · PE · PL · PM · PS · PT · RA · SA · SC · SI · SR
- Applies to
- healthcare · insurance · federal · US
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-30
03Version ledger
| MARS-E 2.2 | Superseded | 2021-02-23 |
| v1.02 | Current edition · supersedes MARS-E 2.2 | 2025-04-10 |
04Authority intelligence
Curated primary-source signals connected to this registry record. An authority change creates review work; it does not silently change tenant posture, evidence credit, or prior decisions.
- Program update
CMS publishes Year 9 EDE audit guidance for PY 2026–2027.
The current operational-readiness guidance preserves program-native requirements across application, API, privacy, security, and third-party audit work.
Operating moveKeep the CMS source identifier, scenario, persona, environment, collection method, blocker, and reviewer decision attached to every artifact candidate.
05Change history
06Related frameworks
- CMS Enhanced Direct EnrollmentYear 9 (PY 2026–PY 2027)
Also applies to healthcare · The pathway that lets a web broker or issuer run the whole ACA enrollment experience on its own site instead of handing the consumer off to HealthCare.gov.
- NAIC Insurance Data Security Model LawModel #668
Also applies to insurance · A model law for insurance-sector information security programs, incident response, and breach notification, adopted individually by roughly 25-28 US states as of 2026. It becomes enforceable law only where a state has enacted its own version — the requirements can vary state to state.
- FISMAFederal Information Security Modernization Act of 2014
Also applies to federal · The Federal Information Security Modernization Act of 2014 — the statutory authority a federal RFP names, implemented operationally through NIST SP 800-53 and the NIST Cybersecurity Framework, both already tracked as their own registry entries.
- GAO FISCAMJune 2026 (GAO-26-108633)
Also applies to federal · The federal audit methodology for assessing the design, implementation, and operating effectiveness of information-system controls under generally accepted government auditing standards. It is audit guidance, not an agency authorization or certification.