MARS-E 2.2 superseded by ARC-AMPE v1.02
CMS Center for Consumer Information and Insurance Oversight · Direct Enrollment Entity mandatory baseline (Vol II SSPP)
ARC-AMPE v1.02 supersedes MARS-E 2.2 in full. There is no transition period and no partial adoption — from the compliance date, an assessment cites ARC-AMPE control IDs or it is not an assessment.
No transition period. Assessments after this date cite ARC-AMPE v1.02 control IDs.
Supersession
MARS-E 2.2 → ARC-AMPE v1.02
| Field | MARS-E 2.2superseded | ARC-AMPE v1.02operative |
|---|---|---|
| Publishing authority | CMS CCIIO | CMS CCIIO |
| Upstream catalog | NIST SP 800-53 Rev 4 tailoring | NIST SP 800-53 Rev 5 tailoring |
| Issued | 2015-11-10 | 2025-07-07 |
| Operative | until 2026-03-03 | from 2026-03-04 |
| Controls in baseline | 293 | 308 |
| Control families | 26 | 20 |
Provenance. ARC-AMPE v1.02 — Parsed from ARC-AMPE_Vol2_SSPP-DE-Entity_v1.0-508_07072025.xlsx · sheet "DEE Mandatory Baseline". MARS-E 2.2 — Reconstructed from the operative baseline plus the published NIST Rev 4 → Rev 5 change record.
Change profile
143 of 308 controls touched
Two control families in the operative baseline did not exist in Rev 4. MARS-E never asked for them, so no MARS-E artifact can answer them.
Going the other way, 8 families dissolved — AP · AR · DI · DM · IP · SE · TR · UL — 25 controls redistributed into the new families or withdrawn outright.
| Family | MARS-E 2.2 | ARC-AMPE v1.02 | Added | Removed | Renumbered | Retitled |
|---|---|---|---|---|---|---|
ACAccess Control | 45 | 46 | 3 | 3 | 1 | 5 |
ARAccountability, Audit, and Risk Managementdissolved | 7 | 0 | 0 | 5 | 0 | 0 |
ATAwareness and Training | 6 | 9 | 3 | 0 | 1 | 4 |
AUAudit and Accountability | 17 | 18 | 1 | 0 | 0 | 6 |
CAAssessment, Authorization, and Monitoring | 12 | 12 | 1 | 1 | 0 | 2 |
CMConfiguration Management | 25 | 25 | 2 | 2 | 0 | 5 |
CPContingency Planning | 15 | 16 | 1 | 0 | 0 | 5 |
DIData Quality and Integritydissolved | 2 | 0 | 0 | 1 | 0 | 0 |
DMData Minimization and Retentiondissolved | 3 | 0 | 0 | 1 | 0 | 0 |
IAIdentification and Authentication | 19 | 21 | 4 | 2 | 0 | 6 |
IPIndividual Participation and Redressdissolved | 4 | 0 | 0 | 2 | 0 | 0 |
IRIncident Response | 13 | 15 | 1 | 0 | 1 | 1 |
MAMaintenance | 11 | 12 | 2 | 1 | 0 | 1 |
MPMedia Protection | 8 | 8 | 0 | 0 | 0 | 2 |
PEPhysical and Environmental Protection | 9 | 9 | 0 | 0 | 0 | 2 |
PLPlanning | 5 | 6 | 1 | 0 | 0 | 4 |
PMProgram Management | 2 | 5 | 0 | 0 | 3 | 1 |
PSPersonnel Security | 8 | 8 | 0 | 0 | 0 | 2 |
PTPersonally Identifiable Information Processing and Transparencynew family | 0 | 10 | 6 | 0 | 4 | 0 |
RARisk Assessment | 8 | 8 | 1 | 2 | 1 | 3 |
SASystem and Services Acquisition | 16 | 18 | 2 | 0 | 0 | 8 |
SCSystem and Communications Protection | 26 | 28 | 2 | 0 | 0 | 3 |
SISystem and Information Integrity | 23 | 30 | 7 | 2 | 2 | 3 |
SRSupply Chain Risk Managementnew family | 0 | 4 | 4 | 0 | 0 | 0 |
TRTransparencydissolved | 3 | 0 | 0 | 2 | 0 | 0 |
ULUse Limitationdissolved | 2 | 0 | 0 | 2 | 0 | 0 |
AddedNo ancestor in the superseded baseline — every one of these needs evidence collected for the first time.41
| AC-06(07) | Review of User Privileges | Added | ACAccess Control |
| AC-12(02) | Termination Message | Added | ACAccess Control |
| AC-12(03) | Timeout Warning Message | Added | ACAccess Control |
| AT-02(03) | Social Engineering and Mining | Added | ATAwareness and Training |
| AT-02(05) | Advanced Persistent Threat | Added | ATAwareness and Training |
| AT-03(05) | Processing Personally Identifiable Information | Added | ATAwareness and Training |
| AU-03(03) | Limit Personally Identifiable Information Elements | Added | AUAudit and Accountability |
| CA-07(04) | Risk Monitoring | Added | CAAssessment, Authorization, and Monitoring |
| CM-12 | Information Location | Added | CMConfiguration Management |
| CM-13 | Data Action Mapping | Added | CMConfiguration Management |
| CP-09(08) | Cryptographic Protection | Added | CPContingency Planning |
| IA-11 | Re-Authentication | Added | IAIdentification and Authentication |
| IA-12 | Identity Proofing | Added | IAIdentification and Authentication |
| IA-12(01) | Supervisor Authorization | Added | IAIdentification and Authentication |
| IA-12(03) | Identity Evidence Validation and Verification | Added | IAIdentification and Authentication |
| IR-02(03) | Breach | Added | IRIncident Response |
| MA-03(05) | Execution with Privilege | Added | MAMaintenance |
| MA-03(06) | Software Updates and Patches | Added | MAMaintenance |
| PL-11 | Baseline Tailoring | Added | PLPlanning |
| PT-01 | Policy and ProceduresPT family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor. | Added | PTPersonally Identifiable Information Processing and Transparency |
| PT-04(03) | RevocationPT family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor. | Added | PTPersonally Identifiable Information Processing and Transparency |
| PT-05(01) | Just-in-time NoticePT family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor. | Added | PTPersonally Identifiable Information Processing and Transparency |
| PT-05(02) | Privacy Act StatementsPT family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor. | Added | PTPersonally Identifiable Information Processing and Transparency |
| PT-07 | Specific Categories of Personally Identifiable InformationPT family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor. | Added | PTPersonally Identifiable Information Processing and Transparency |
| PT-07(01) | Social Security NumbersPT family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor. | Added | PTPersonally Identifiable Information Processing and Transparency |
| RA-07 | Risk Response | Added | RARisk Assessment |
| SA-09(08) | Processing and Storage Location - U.S. Jurisdiction | Added | SASystem and Services Acquisition |
| SA-15(12) | Minimize Personally Identifiable Information | Added | SASystem and Services Acquisition |
| SC-7(24) | Boundary Protection | Personally Identifiable Information | Added | SCSystem and Communications Protection |
| SC-7(29) | Boundary Protection | Separate Subnets to Isolate Functions | Added | SCSystem and Communications Protection |
| SI-12(01) | Limit Personally Identifiable Information Elements | Added | SISystem and Information Integrity |
| SI-12(02) | Minimize Personally Identifiable Information in Testing, Training, and Research | Added | SISystem and Information Integrity |
| SI-18(04) | Individual Requests | Added | SISystem and Information Integrity |
| SI-18(05) | Notice of Collection or Deletion | Added | SISystem and Information Integrity |
| SI-19 | De-Identification | Added | SISystem and Information Integrity |
| SI-19(03) | Release | Added | SISystem and Information Integrity |
| SI-19(04) | Removal, Masking, Encryption, Hashing, or Replacement of Direct Identifiers | Added | SISystem and Information Integrity |
| SR-01 | Policy and ProceduresSR family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor. | Added | SRSupply Chain Risk Management |
| SR-02 | Supply Chain Risk Management PlanSR family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor. | Added | SRSupply Chain Risk Management |
| SR-02(01) | Establish SCRM TeamSR family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor. | Added | SRSupply Chain Risk Management |
| SR-03 | Supply Chain Controls and ProcessesSR family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor. | Added | SRSupply Chain Risk Management |
RemovedWithdrawn from the operative baseline — evidence pointed here no longer proves an obligation.26
| AC-02(10) | Shared / Group Account Credential TerminationWithdrawn — incorporated into AC-02. | Removed | ACAccess Control |
| AC-17(07) | Additional Protection for Security Function AccessWithdrawn — incorporated into AC-03. | Removed | ACAccess Control |
| AC-17(08) | Disable Nonsecure Network ProtocolsWithdrawn — incorporated into CM-07. | Removed | ACAccess Control |
| AR-1 | Governance and Privacy ProgramWithdrawn — successor PM-18 is outside the DE-Entity baseline. | Removed | ARAccountability, Audit, and Risk Management |
| AR-3 | Privacy Requirements for Contractors and Service ProvidersWithdrawn — incorporated into SA-04 and SA-09. | Removed | ARAccountability, Audit, and Risk Management |
| AR-4 | Privacy Monitoring and AuditingWithdrawn — incorporated into CA-07. | Removed | ARAccountability, Audit, and Risk Management |
| AR-5 | Privacy Awareness and TrainingWithdrawn — incorporated into AT-02 and AT-03. | Removed | ARAccountability, Audit, and Risk Management |
| AR-7 | Privacy-Enhanced System Design and DevelopmentWithdrawn — incorporated into SA-08. | Removed | ARAccountability, Audit, and Risk Management |
| CA-03(05) | Restrictions on External System ConnectionsWithdrawn — incorporated into SC-07(05). | Removed | CAAssessment, Authorization, and Monitoring |
| CM-02(01) | Reviews and UpdatesWithdrawn — incorporated into CM-02. | Removed | CMConfiguration Management |
| CM-08(05) | No Duplicate Accounting of ComponentsWithdrawn — incorporated into CM-08. | Removed | CMConfiguration Management |
| DI-2 | Data Integrity and Data Integrity BoardWithdrawn — Data Integrity Board has no DE-Entity successor. | Removed | DIData Quality and Integrity |
| DM-1 | Minimization of Personally Identifiable InformationWithdrawn — incorporated into SI-12(01) and PT-03. | Removed | DMData Minimization and Retention |
| IA-05(03) | In-Person or Trusted Third-Party RegistrationWithdrawn — incorporated into IA-12. | Removed | IAIdentification and Authentication |
| IA-05(11) | Hardware Token-Based AuthenticationWithdrawn — incorporated into IA-02(01). | Removed | IAIdentification and Authentication |
| IP-3 | RedressWithdrawn — incorporated into SI-18(04). | Removed | IPIndividual Participation and Redress |
| IP-4 | Complaint ManagementWithdrawn — incorporated into SI-18(04). | Removed | IPIndividual Participation and Redress |
| MA-04(02) | Document Nonlocal MaintenanceWithdrawn — incorporated into MA-04. | Removed | MAMaintenance |
| RA-05(01) | Update Tool CapabilityWithdrawn — incorporated into RA-05. | Removed | RARisk Assessment |
| RA-05(03) | Breadth / Depth of CoverageWithdrawn — incorporated into RA-05. | Removed | RARisk Assessment |
| SI-03(01) | Central ManagementWithdrawn — incorporated into PL-09. | Removed | SISystem and Information Integrity |
| SI-03(02) | Automatic UpdatesWithdrawn — incorporated into SI-03. | Removed | SISystem and Information Integrity |
| TR-2 | System of Records Notices and Privacy Act StatementsWithdrawn — successor PT-06 is outside the DE-Entity baseline. | Removed | TRTransparency |
| TR-3 | Dissemination of Privacy Program InformationWithdrawn — successor PM-20 is outside the DE-Entity baseline. | Removed | TRTransparency |
| UL-1 | Internal UseWithdrawn — incorporated into PT-02 and PT-03. | Removed | ULUse Limitation |
| UL-2 | Information Sharing with Third PartiesWithdrawn — incorporated into PT-07 and SA-09. | Removed | ULUse Limitation |
Renumbered or changedThe obligation survived under a new number or a new title — the artifact stands, the mapping does not.76
| AC-01 | Policy and Procedureswas “Access Control Policy and Procedures” | Retitled | ACAccess Control |
| IP-2→AC-03(14) | Individual Access | Renumbered | ACAccess Control |
| AC-06(09) | Log Use of Privileged Functionswas “Auditing Use of Privileged Functions” | Retitled | ACAccess Control |
| AC-12(01) | User-Initiated Logoutswas “User-Initiated Logouts / Message Displays” | Retitled | ACAccess Control |
| AC-20 | Use of External Systemswas “Use of External Information Systems” | Retitled | ACAccess Control |
| AC-20(02) | Portable Storage Devices — Restricted Usewas “Portable Storage Devices” | Retitled | ACAccess Control |
| AT-01 | Policy and Procedureswas “Security Awareness and Training Policy and Procedures” | Retitled | ATAwareness and Training |
| AT-02 | Literacy Training and Awarenesswas “Security Awareness Training” | Retitled | ATAwareness and Training |
| AT-03(04)→AT-02(04) | Suspicious Communications and Anomalous System Behavior | Renumbered | ATAwareness and Training |
| AT-03 | Role-Based Trainingwas “Role-Based Security Training” | Retitled | ATAwareness and Training |
| AT-04 | Training Recordswas “Security Training Records” | Retitled | ATAwareness and Training |
| AU-01 | Policy and Procedureswas “Audit and Accountability Policy and Procedures” | Retitled | AUAudit and Accountability |
| AU-02 | Event Loggingwas “Audit Events” | Retitled | AUAudit and Accountability |
| AU-06 | Audit Record Review, Analysis, and Reportingwas “Audit Review, Analysis, and Reporting” | Retitled | AUAudit and Accountability |
| AU-06(03) | Correlate Audit Record Repositorieswas “Correlate Audit Repositories” | Retitled | AUAudit and Accountability |
| AU-07 | Audit Record Reduction and Report Generationwas “Audit Reduction and Report Generation” | Retitled | AUAudit and Accountability |
| AU-12 | Audit Record Generationwas “Audit Generation” | Retitled | AUAudit and Accountability |
| CA-01 | Policies and Procedureswas “Security Assessment and Authorization Policies and Procedures” | Retitled | CAAssessment, Authorization, and Monitoring |
| CA-03 | Information Exchangewas “System Interconnections” | Retitled | CAAssessment, Authorization, and Monitoring |
| CM-01 | Policy and Procedureswas “Configuration Management Policy and Procedures” | Retitled | CMConfiguration Management |
| CM-04 | Impact Analyseswas “Security Impact Analysis” | Retitled | CMConfiguration Management |
| CM-05(05) | Privilege Limitation for Production and Operationwas “Limit Production / Operational Privileges” | Retitled | CMConfiguration Management |
| CM-07(05) | Authorized Software - Allow by Exceptionwas “Authorized Software - Whitelisting” | Retitled | CMConfiguration Management |
| CM-08 | System Component Inventorywas “Information System Component Inventory” | Retitled | CMConfiguration Management |
| CP-01 | Policy and Procedureswas “Contingency Planning Policy and Procedures” | Retitled | CPContingency Planning |
| CP-02(03) | Resume Missions and Business Functionswas “Resume Essential Missions / Business Functions” | Retitled | CPContingency Planning |
| CP-09 | System Backupwas “Information System Backup” | Retitled | CPContingency Planning |
| CP-09(01) | Testing for Reliability and Integritywas “Testing for Reliability / Integrity” | Retitled | CPContingency Planning |
| CP-10 | System Recovery and Reconstitutionwas “Information System Recovery and Reconstitution” | Retitled | CPContingency Planning |
| IA-01 | Policy and Procedureswas “Identification and Authentication Policy and Procedures” | Retitled | IAIdentification and Authentication |
| IA-02(01) | Multifactor Access to Privileged Accountswas “Network Access to Privileged Accounts” | Retitled | IAIdentification and Authentication |
| IA-02(02) | Multifactor Access to Non-Privileged Accountswas “Network Access to Non-Privileged Accounts” | Retitled | IAIdentification and Authentication |
| IA-02(06) | Access to Accounts - Separate Devicewas “Network Access to Privileged Accounts - Separate Device” | Retitled | IAIdentification and Authentication |
| IA-02(08) | Access to Accounts - Replay Resistantwas “Network Access to Privileged Accounts - Replay Resistant” | Retitled | IAIdentification and Authentication |
| IA-08(02) | Identification and Authentication (Non-Organizational Users) |Acceptance of External Party Credentialswas “Acceptance of Third-Party Credentials” | Retitled | IAIdentification and Authentication |
| IR-01 | Policy and Procedureswas “Incident Response Policy and Procedures” | Retitled | IRIncident Response |
| SE-2→IR-08(01) | Breacheswas “Privacy Incident Response” | Renumbered | IRIncident Response |
| MA-01 | Policy and Procedureswas “System Maintenance Policy and Procedures” | Retitled | MAMaintenance |
| MP-01 | Policy and Procedureswas “Media Protection Policy and Procedures” | Retitled | MPMedia Protection |
| MP-06(01) | Review, Approve, Track, Document, and Verifywas “Review / Approve / Track / Document / Verify” | Retitled | MPMedia Protection |
| PE-01 | Policy and Procedureswas “Physical and Environmental Protection Policy and Procedures” | Retitled | PEPhysical and Environmental Protection |
| PE-06(01) | Intrusion Alarms and Surveillance Equipmentwas “Intrusion Alarms / Surveillance Equipment” | Retitled | PEPhysical and Environmental Protection |
| PL-01 | Policy and Procedureswas “Security Planning Policy and Procedures” | Retitled | PLPlanning |
| PL-02 | System Security and Privacy Planwas “System Security Plan” | Retitled | PLPlanning |
| PL-04(01) | Social Media and External Site / Application Usage Restrictionswas “Social Media and Networking Restrictions” | Retitled | PLPlanning |
| PL-08 | Security and Privacy Architectureswas “Information Security Architecture” | Retitled | PLPlanning |
| PM-05 | System Inventorywas “Information System Inventory” | Retitled | PMProgram Management |
| SE-1→PM-05(01) | Inventory of Personally Identifiable Information | Renumbered | PMProgram Management |
| AR-8→PM-21 | Accounting of Disclosures | Renumbered | PMProgram Management |
| DM-3→PM-25 | Minimization of PII Used in Testing, Training, and Research | Renumbered | PMProgram Management |
| PS-01 | Policy and Procedureswas “Personnel Security Policy and Procedures” | Retitled | PSPersonnel Security |
| PS-07 | External Personnel Securitywas “Third-Party Personnel Security” | Retitled | PSPersonnel Security |
| AP-1→PT-02 | Authority to Process Personally Identifiable Informationwas “Authority to Collect” | Renumbered | PTPersonally Identifiable Information Processing and Transparency |
| AP-2→PT-03 | Personally Identifiable Information Processing Purposeswas “Purpose Specification” | Renumbered | PTPersonally Identifiable Information Processing and Transparency |
| IP-1→PT-04 | Consent | Renumbered | PTPersonally Identifiable Information Processing and Transparency |
| TR-1→PT-05 | Privacy Notice | Renumbered | PTPersonally Identifiable Information Processing and Transparency |
| RA-01 | Policy and Procedureswas “Risk Assessment Policy and Procedures” | Retitled | RARisk Assessment |
| RA-05 | Vulnerability Monitoring and Scanningwas “Vulnerability Scanning” | Retitled | RARisk Assessment |
| RA-05(02) | Update Vulnerabilities to be Scannedwas “Update by Frequency / Prior to New Scan / When Identified” | Retitled | RARisk Assessment |
| AR-2→RA-08 | Privacy Impact Assessmentswas “Privacy Impact and Risk Assessment” | Renumbered | RARisk Assessment |
| SA-01 | Policy and Procedureswas “System and Services Acquisition Policy and Procedures” | Retitled | SASystem and Services Acquisition |
| SA-04(01) | Functional Properties of Controlswas “Functional Properties of Security Controls” | Retitled | SASystem and Services Acquisition |
| SA-04(02) | Design and Implementation Information for Security Controlswas “Design / Implementation Information for Security Controls” | Retitled | SASystem and Services Acquisition |
| SA-04(09) | Functions, Ports, Protocols, and Services in Usewas “Functions / Ports / Protocols / Services in Use” | Retitled | SASystem and Services Acquisition |
| SA-05 | System Documentationwas “Information System Documentation” | Retitled | SASystem and Services Acquisition |
| SA-08 | Security and Privacy Engineering Principleswas “Security Engineering Principles” | Retitled | SASystem and Services Acquisition |
| SA-09 | External System Serviceswas “External Information System Services” | Retitled | SASystem and Services Acquisition |
| SA-11 | Developer Testing and Evaluationwas “Developer Security Testing and Evaluation” | Retitled | SASystem and Services Acquisition |
| SC-01 | Policy and Procedureswas “System and Communications Protection Policy and Procedures” | Retitled | SCSystem and Communications Protection |
| SC-07(07) | Split Tunneling for Remote Deviceswas “Prevent Split Tunneling for Remote Devices” | Retitled | SCSystem and Communications Protection |
| SC-08(01) | Cryptographic Protectionwas “Cryptographic or Alternate Physical Protection” | Retitled | SCSystem and Communications Protection |
| SI-01 | Policy and Procedureswas “System and Information Integrity Policy and Procedures” | Retitled | SISystem and Information Integrity |
| SI-02(06) | Removal of Previous Versions of Software and Firmwarewas “Removal of Previous Versions of Software / Firmware” | Retitled | SISystem and Information Integrity |
| SI-12 | Information Management and Retentionwas “Information Handling and Retention” | Retitled | SISystem and Information Integrity |
| DM-2→SI-12(03) | Information Disposalwas “Data Retention and Disposal” | Renumbered | SISystem and Information Integrity |
| DI-1→SI-18 | Personally Identifiable Information Quality Operationswas “Data Quality” | Renumbered | SISystem and Information Integrity |
This diff is itself evidence.
143 control changes derived from the two baselines and sealed to the evidence chain — the record of what the regulator changed, verifiable independently of the tenant that read it.
Evidence impact
81 artifacts affected · 19 controls with nothing on file
| Consequence | Count | Remedy | Cost |
|---|---|---|---|
| Artifacts bound to a renumbered control | 10 | Re-point the mapping to the new control ID — no re-collection. | Mapping change |
| Artifacts bound to a retitled control | 48 | Refresh the control title on the artifact record — no re-collection. | Mapping change |
| Artifacts bound to a control folded into another | 21 | Re-file under the absorbing control and re-review sufficiency. | Collection run |
| Artifacts bound to a withdrawn control with no successor | 2 | Retire from the active program; retain for the prior audit period. | Mapping change |
| New controls with no evidence on file | 4 | First-time collection required before the next assessment. | Collection run |
| New controls with collection already scheduled | 2 | Covered by an existing run plan — verify the plan targets the new ID. | Collection run |
| New controls already evidenced | 35 | Satisfied by evidence collected against the shared control spine. | Mapping change |
254 evidenced + 35 scheduled + 19 with nothing on file = 308 — the same posture carried on the ARC-AMPE v1.02 baseline and the command board.
Re-collection plan
5 run plans · every result seals to the chain
| Plan | Scope | Controls | Why it has to run | Cadence |
|---|---|---|---|---|
| ampe-privacy-transparency-sweepPT | PT family · 10 controls | 10 | Family did not exist under MARS-E. Consent, privacy notice and PII-processing evidence has never been collected against these IDs. | new · quarterly |
| ampe-supply-chain-baselineSR | SR family · 4 controls | 4 | SCRM plan, SCRM team and supply-chain process evidence has no MARS-E ancestor to inherit from. | new · annual |
| access-review-deltaAC · IA | Okta · 1,284 identities | 6 | Picks up IA-11 re-authentication, IA-12 identity proofing and AC-06(07) privilege review — all new IDs in Rev 5. | weekly |
| evidence-freshness-sweepall | All programs · 764 controls | 65 | Control-ID map has to be re-pointed before the sweep can score the ARC-AMPE lane; renumbered and retitled controls currently read as unmapped. | daily 06:00 UTC |
| poam-assembly-dry-runall | ARC-AMPE · Q3 POA&M | 19 | Every control still without evidence has to carry a POA&M item citing the ARC-AMPE ID, not the MARS-E one. | gate − 21 days |
Plans run on the continuous compliance ledger, against the operative control IDs. Until the map is re-pointed, a renumbered control reads as unmapped, not as covered.