ARC-AMPE baseline
Change record · ARC-AMPE

MARS-E 2.2 superseded by ARC-AMPE v1.02

CMS Center for Consumer Information and Insurance Oversight · Direct Enrollment Entity mandatory baseline (Vol II SSPP)

ARC-AMPE v1.02 supersedes MARS-E 2.2 in full. There is no transition period and no partial adoption — from the compliance date, an assessment cites ARC-AMPE control IDs or it is not an assessment.

2026-03-04
Compliance date · 154 days ago

No transition period. Assessments after this date cite ARC-AMPE v1.02 control IDs.

Supersession

MARS-E 2.2 → ARC-AMPE v1.02

FieldMARS-E 2.2supersededARC-AMPE v1.02operative
Publishing authorityCMS CCIIOCMS CCIIO
Upstream catalogNIST SP 800-53 Rev 4 tailoringNIST SP 800-53 Rev 5 tailoring
Issued2015-11-102025-07-07
Operativeuntil 2026-03-03from 2026-03-04
Controls in baseline293308
Control families2620

Provenance. ARC-AMPE v1.02Parsed from ARC-AMPE_Vol2_SSPP-DE-Entity_v1.0-508_07072025.xlsx · sheet "DEE Mandatory Baseline". MARS-E 2.2Reconstructed from the operative baseline plus the published NIST Rev 4 → Rev 5 change record.

ARC-AMPE_Vol2_SSPP-DE-Entity_v1.0-508_07072025.xlsx

Change profile

143 of 308 controls touched

41
Added
26
Removed
13
Renumbered
63
Retitled
191
Carried unchanged

Two control families in the operative baseline did not exist in Rev 4. MARS-E never asked for them, so no MARS-E artifact can answer them.

PTPersonally Identifiable Information Processing and Transparency10 controls6 evidenced · 1 scheduled · 3 with nothing
SRSupply Chain Risk Management4 controls4 evidenced · 0 scheduled · 0 with nothing

Going the other way, 8 families dissolved — AP · AR · DI · DM · IP · SE · TR · UL 25 controls redistributed into the new families or withdrawn outright.

FamilyMARS-E 2.2ARC-AMPE v1.02AddedRemovedRenumberedRetitled
ACAccess Control
45463315
ARAccountability, Audit, and Risk Managementdissolved
700500
ATAwareness and Training
693014
AUAudit and Accountability
17181006
CAAssessment, Authorization, and Monitoring
12121102
CMConfiguration Management
25252205
CPContingency Planning
15161005
DIData Quality and Integritydissolved
200100
DMData Minimization and Retentiondissolved
300100
IAIdentification and Authentication
19214206
IPIndividual Participation and Redressdissolved
400200
IRIncident Response
13151011
MAMaintenance
11122101
MPMedia Protection
880002
PEPhysical and Environmental Protection
990002
PLPlanning
561004
PMProgram Management
250031
PSPersonnel Security
880002
PTPersonally Identifiable Information Processing and Transparencynew family
0106040
RARisk Assessment
881213
SASystem and Services Acquisition
16182008
SCSystem and Communications Protection
26282003
SISystem and Information Integrity
23307223
SRSupply Chain Risk Managementnew family
044000
TRTransparencydissolved
300200
ULUse Limitationdissolved
200200
Added41
AC-06(07)Review of User PrivilegesAdded
ACAccess Control
AC-12(02)Termination MessageAdded
ACAccess Control
AC-12(03)Timeout Warning MessageAdded
ACAccess Control
AT-02(03)Social Engineering and MiningAdded
ATAwareness and Training
AT-02(05)Advanced Persistent ThreatAdded
ATAwareness and Training
AT-03(05)Processing Personally Identifiable InformationAdded
ATAwareness and Training
AU-03(03)Limit Personally Identifiable Information ElementsAdded
AUAudit and Accountability
CA-07(04)Risk MonitoringAdded
CAAssessment, Authorization, and Monitoring
CM-12Information LocationAdded
CMConfiguration Management
CM-13Data Action MappingAdded
CMConfiguration Management
CP-09(08)Cryptographic ProtectionAdded
CPContingency Planning
IA-11Re-AuthenticationAdded
IAIdentification and Authentication
IA-12Identity ProofingAdded
IAIdentification and Authentication
IA-12(01)Supervisor AuthorizationAdded
IAIdentification and Authentication
IA-12(03)Identity Evidence Validation and VerificationAdded
IAIdentification and Authentication
IR-02(03)BreachAdded
IRIncident Response
MA-03(05)Execution with PrivilegeAdded
MAMaintenance
MA-03(06)Software Updates and PatchesAdded
MAMaintenance
PL-11Baseline TailoringAdded
PLPlanning
PT-01Policy and ProceduresPT family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor.Added
PTPersonally Identifiable Information Processing and Transparency
PT-04(03)RevocationPT family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor.Added
PTPersonally Identifiable Information Processing and Transparency
PT-05(01)Just-in-time NoticePT family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor.Added
PTPersonally Identifiable Information Processing and Transparency
PT-05(02)Privacy Act StatementsPT family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor.Added
PTPersonally Identifiable Information Processing and Transparency
PT-07Specific Categories of Personally Identifiable InformationPT family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor.Added
PTPersonally Identifiable Information Processing and Transparency
PT-07(01)Social Security NumbersPT family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor.Added
PTPersonally Identifiable Information Processing and Transparency
RA-07Risk ResponseAdded
RARisk Assessment
SA-09(08)Processing and Storage Location - U.S. JurisdictionAdded
SASystem and Services Acquisition
SA-15(12)Minimize Personally Identifiable InformationAdded
SASystem and Services Acquisition
SC-7(24)Boundary Protection | Personally Identifiable InformationAdded
SCSystem and Communications Protection
SC-7(29)Boundary Protection | Separate Subnets to Isolate FunctionsAdded
SCSystem and Communications Protection
SI-12(01)Limit Personally Identifiable Information ElementsAdded
SISystem and Information Integrity
SI-12(02)Minimize Personally Identifiable Information in Testing, Training, and ResearchAdded
SISystem and Information Integrity
SI-18(04)Individual RequestsAdded
SISystem and Information Integrity
SI-18(05)Notice of Collection or DeletionAdded
SISystem and Information Integrity
SI-19De-IdentificationAdded
SISystem and Information Integrity
SI-19(03)ReleaseAdded
SISystem and Information Integrity
SI-19(04)Removal, Masking, Encryption, Hashing, or Replacement of Direct IdentifiersAdded
SISystem and Information Integrity
SR-01Policy and ProceduresSR family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor.Added
SRSupply Chain Risk Management
SR-02Supply Chain Risk Management PlanSR family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor.Added
SRSupply Chain Risk Management
SR-02(01)Establish SCRM TeamSR family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor.Added
SRSupply Chain Risk Management
SR-03Supply Chain Controls and ProcessesSR family introduced in NIST SP 800-53 Rev 5 — no Rev 4 ancestor.Added
SRSupply Chain Risk Management
Removed26
AC-02(10)Shared / Group Account Credential TerminationWithdrawn — incorporated into AC-02.Removed
ACAccess Control
AC-17(07)Additional Protection for Security Function AccessWithdrawn — incorporated into AC-03.Removed
ACAccess Control
AC-17(08)Disable Nonsecure Network ProtocolsWithdrawn — incorporated into CM-07.Removed
ACAccess Control
AR-1Governance and Privacy ProgramWithdrawn — successor PM-18 is outside the DE-Entity baseline.Removed
ARAccountability, Audit, and Risk Management
AR-3Privacy Requirements for Contractors and Service ProvidersWithdrawn — incorporated into SA-04 and SA-09.Removed
ARAccountability, Audit, and Risk Management
AR-4Privacy Monitoring and AuditingWithdrawn — incorporated into CA-07.Removed
ARAccountability, Audit, and Risk Management
AR-5Privacy Awareness and TrainingWithdrawn — incorporated into AT-02 and AT-03.Removed
ARAccountability, Audit, and Risk Management
AR-7Privacy-Enhanced System Design and DevelopmentWithdrawn — incorporated into SA-08.Removed
ARAccountability, Audit, and Risk Management
CA-03(05)Restrictions on External System ConnectionsWithdrawn — incorporated into SC-07(05).Removed
CAAssessment, Authorization, and Monitoring
CM-02(01)Reviews and UpdatesWithdrawn — incorporated into CM-02.Removed
CMConfiguration Management
CM-08(05)No Duplicate Accounting of ComponentsWithdrawn — incorporated into CM-08.Removed
CMConfiguration Management
DI-2Data Integrity and Data Integrity BoardWithdrawn — Data Integrity Board has no DE-Entity successor.Removed
DIData Quality and Integrity
DM-1Minimization of Personally Identifiable InformationWithdrawn — incorporated into SI-12(01) and PT-03.Removed
DMData Minimization and Retention
IA-05(03)In-Person or Trusted Third-Party RegistrationWithdrawn — incorporated into IA-12.Removed
IAIdentification and Authentication
IA-05(11)Hardware Token-Based AuthenticationWithdrawn — incorporated into IA-02(01).Removed
IAIdentification and Authentication
IP-3RedressWithdrawn — incorporated into SI-18(04).Removed
IPIndividual Participation and Redress
IP-4Complaint ManagementWithdrawn — incorporated into SI-18(04).Removed
IPIndividual Participation and Redress
MA-04(02)Document Nonlocal MaintenanceWithdrawn — incorporated into MA-04.Removed
MAMaintenance
RA-05(01)Update Tool CapabilityWithdrawn — incorporated into RA-05.Removed
RARisk Assessment
RA-05(03)Breadth / Depth of CoverageWithdrawn — incorporated into RA-05.Removed
RARisk Assessment
SI-03(01)Central ManagementWithdrawn — incorporated into PL-09.Removed
SISystem and Information Integrity
SI-03(02)Automatic UpdatesWithdrawn — incorporated into SI-03.Removed
SISystem and Information Integrity
TR-2System of Records Notices and Privacy Act StatementsWithdrawn — successor PT-06 is outside the DE-Entity baseline.Removed
TRTransparency
TR-3Dissemination of Privacy Program InformationWithdrawn — successor PM-20 is outside the DE-Entity baseline.Removed
TRTransparency
UL-1Internal UseWithdrawn — incorporated into PT-02 and PT-03.Removed
ULUse Limitation
UL-2Information Sharing with Third PartiesWithdrawn — incorporated into PT-07 and SA-09.Removed
ULUse Limitation
Renumbered or changed76
AC-01Policy and Procedureswas “Access Control Policy and ProceduresRetitled
ACAccess Control
IP-2AC-03(14)Individual AccessRenumbered
ACAccess Control
AC-06(09)Log Use of Privileged Functionswas “Auditing Use of Privileged FunctionsRetitled
ACAccess Control
AC-12(01)User-Initiated Logoutswas “User-Initiated Logouts / Message DisplaysRetitled
ACAccess Control
AC-20Use of External Systemswas “Use of External Information SystemsRetitled
ACAccess Control
AC-20(02)Portable Storage Devices — Restricted Usewas “Portable Storage DevicesRetitled
ACAccess Control
AT-01Policy and Procedureswas “Security Awareness and Training Policy and ProceduresRetitled
ATAwareness and Training
AT-02Literacy Training and Awarenesswas “Security Awareness TrainingRetitled
ATAwareness and Training
AT-03(04)AT-02(04)Suspicious Communications and Anomalous System BehaviorRenumbered
ATAwareness and Training
AT-03Role-Based Trainingwas “Role-Based Security TrainingRetitled
ATAwareness and Training
AT-04Training Recordswas “Security Training RecordsRetitled
ATAwareness and Training
AU-01Policy and Procedureswas “Audit and Accountability Policy and ProceduresRetitled
AUAudit and Accountability
AU-02Event Loggingwas “Audit EventsRetitled
AUAudit and Accountability
AU-06Audit Record Review, Analysis, and Reportingwas “Audit Review, Analysis, and ReportingRetitled
AUAudit and Accountability
AU-06(03)Correlate Audit Record Repositorieswas “Correlate Audit RepositoriesRetitled
AUAudit and Accountability
AU-07Audit Record Reduction and Report Generationwas “Audit Reduction and Report GenerationRetitled
AUAudit and Accountability
AU-12Audit Record Generationwas “Audit GenerationRetitled
AUAudit and Accountability
CA-01Policies and Procedureswas “Security Assessment and Authorization Policies and ProceduresRetitled
CAAssessment, Authorization, and Monitoring
CA-03Information Exchangewas “System InterconnectionsRetitled
CAAssessment, Authorization, and Monitoring
CM-01Policy and Procedureswas “Configuration Management Policy and ProceduresRetitled
CMConfiguration Management
CM-04Impact Analyseswas “Security Impact AnalysisRetitled
CMConfiguration Management
CM-05(05)Privilege Limitation for Production and Operationwas “Limit Production / Operational PrivilegesRetitled
CMConfiguration Management
CM-07(05)Authorized Software - Allow by Exceptionwas “Authorized Software - WhitelistingRetitled
CMConfiguration Management
CM-08System Component Inventorywas “Information System Component InventoryRetitled
CMConfiguration Management
CP-01Policy and Procedureswas “Contingency Planning Policy and ProceduresRetitled
CPContingency Planning
CP-02(03)Resume Missions and Business Functionswas “Resume Essential Missions / Business FunctionsRetitled
CPContingency Planning
CP-09System Backupwas “Information System BackupRetitled
CPContingency Planning
CP-09(01)Testing for Reliability and Integritywas “Testing for Reliability / IntegrityRetitled
CPContingency Planning
CP-10System Recovery and Reconstitutionwas “Information System Recovery and ReconstitutionRetitled
CPContingency Planning
IA-01Policy and Procedureswas “Identification and Authentication Policy and ProceduresRetitled
IAIdentification and Authentication
IA-02(01)Multifactor Access to Privileged Accountswas “Network Access to Privileged AccountsRetitled
IAIdentification and Authentication
IA-02(02)Multifactor Access to Non-Privileged Accountswas “Network Access to Non-Privileged AccountsRetitled
IAIdentification and Authentication
IA-02(06)Access to Accounts - Separate Devicewas “Network Access to Privileged Accounts - Separate DeviceRetitled
IAIdentification and Authentication
IA-02(08)Access to Accounts - Replay Resistantwas “Network Access to Privileged Accounts - Replay ResistantRetitled
IAIdentification and Authentication
IA-08(02)Identification and Authentication (Non-Organizational Users) |Acceptance of External Party Credentialswas “Acceptance of Third-Party CredentialsRetitled
IAIdentification and Authentication
IR-01Policy and Procedureswas “Incident Response Policy and ProceduresRetitled
IRIncident Response
SE-2IR-08(01)Breacheswas “Privacy Incident ResponseRenumbered
IRIncident Response
MA-01Policy and Procedureswas “System Maintenance Policy and ProceduresRetitled
MAMaintenance
MP-01Policy and Procedureswas “Media Protection Policy and ProceduresRetitled
MPMedia Protection
MP-06(01)Review, Approve, Track, Document, and Verifywas “Review / Approve / Track / Document / VerifyRetitled
MPMedia Protection
PE-01Policy and Procedureswas “Physical and Environmental Protection Policy and ProceduresRetitled
PEPhysical and Environmental Protection
PE-06(01)Intrusion Alarms and Surveillance Equipmentwas “Intrusion Alarms / Surveillance EquipmentRetitled
PEPhysical and Environmental Protection
PL-01Policy and Procedureswas “Security Planning Policy and ProceduresRetitled
PLPlanning
PL-02System Security and Privacy Planwas “System Security PlanRetitled
PLPlanning
PL-04(01)Social Media and External Site / Application Usage Restrictionswas “Social Media and Networking RestrictionsRetitled
PLPlanning
PL-08Security and Privacy Architectureswas “Information Security ArchitectureRetitled
PLPlanning
PM-05System Inventorywas “Information System InventoryRetitled
PMProgram Management
SE-1PM-05(01)Inventory of Personally Identifiable InformationRenumbered
PMProgram Management
AR-8PM-21Accounting of DisclosuresRenumbered
PMProgram Management
DM-3PM-25Minimization of PII Used in Testing, Training, and ResearchRenumbered
PMProgram Management
PS-01Policy and Procedureswas “Personnel Security Policy and ProceduresRetitled
PSPersonnel Security
PS-07External Personnel Securitywas “Third-Party Personnel SecurityRetitled
PSPersonnel Security
AP-1PT-02Authority to Process Personally Identifiable Informationwas “Authority to CollectRenumbered
PTPersonally Identifiable Information Processing and Transparency
AP-2PT-03Personally Identifiable Information Processing Purposeswas “Purpose SpecificationRenumbered
PTPersonally Identifiable Information Processing and Transparency
IP-1PT-04ConsentRenumbered
PTPersonally Identifiable Information Processing and Transparency
TR-1PT-05Privacy NoticeRenumbered
PTPersonally Identifiable Information Processing and Transparency
RA-01Policy and Procedureswas “Risk Assessment Policy and ProceduresRetitled
RARisk Assessment
RA-05Vulnerability Monitoring and Scanningwas “Vulnerability ScanningRetitled
RARisk Assessment
RA-05(02)Update Vulnerabilities to be Scannedwas “Update by Frequency / Prior to New Scan / When IdentifiedRetitled
RARisk Assessment
AR-2RA-08Privacy Impact Assessmentswas “Privacy Impact and Risk AssessmentRenumbered
RARisk Assessment
SA-01Policy and Procedureswas “System and Services Acquisition Policy and ProceduresRetitled
SASystem and Services Acquisition
SA-04(01)Functional Properties of Controlswas “Functional Properties of Security ControlsRetitled
SASystem and Services Acquisition
SA-04(02)Design and Implementation Information for Security Controlswas “Design / Implementation Information for Security ControlsRetitled
SASystem and Services Acquisition
SA-04(09)Functions, Ports, Protocols, and Services in Usewas “Functions / Ports / Protocols / Services in UseRetitled
SASystem and Services Acquisition
SA-05System Documentationwas “Information System DocumentationRetitled
SASystem and Services Acquisition
SA-08Security and Privacy Engineering Principleswas “Security Engineering PrinciplesRetitled
SASystem and Services Acquisition
SA-09External System Serviceswas “External Information System ServicesRetitled
SASystem and Services Acquisition
SA-11Developer Testing and Evaluationwas “Developer Security Testing and EvaluationRetitled
SASystem and Services Acquisition
SC-01Policy and Procedureswas “System and Communications Protection Policy and ProceduresRetitled
SCSystem and Communications Protection
SC-07(07)Split Tunneling for Remote Deviceswas “Prevent Split Tunneling for Remote DevicesRetitled
SCSystem and Communications Protection
SC-08(01)Cryptographic Protectionwas “Cryptographic or Alternate Physical ProtectionRetitled
SCSystem and Communications Protection
SI-01Policy and Procedureswas “System and Information Integrity Policy and ProceduresRetitled
SISystem and Information Integrity
SI-02(06)Removal of Previous Versions of Software and Firmwarewas “Removal of Previous Versions of Software / FirmwareRetitled
SISystem and Information Integrity
SI-12Information Management and Retentionwas “Information Handling and RetentionRetitled
SISystem and Information Integrity
DM-2SI-12(03)Information Disposalwas “Data Retention and DisposalRenumbered
SISystem and Information Integrity
DI-1SI-18Personally Identifiable Information Quality Operationswas “Data QualityRenumbered
SISystem and Information Integrity

This diff is itself evidence.

143 control changes derived from the two baselines and sealed to the evidence chain — the record of what the regulator changed, verifiable independently of the tenant that read it.

CHANGE RECORD2550ba9a · 2025-04-10

Evidence impact

81 artifacts affected · 19 controls with nothing on file

81
Artifacts to re-point or retire
19
Controls with no evidence
4
Of those, new in this version
254/308
Baseline evidenced today
ConsequenceCountRemedyCost
Artifacts bound to a renumbered control10Re-point the mapping to the new control ID — no re-collection.Mapping change
Artifacts bound to a retitled control48Refresh the control title on the artifact record — no re-collection.Mapping change
Artifacts bound to a control folded into another21Re-file under the absorbing control and re-review sufficiency.Collection run
Artifacts bound to a withdrawn control with no successor2Retire from the active program; retain for the prior audit period.Mapping change
New controls with no evidence on file4First-time collection required before the next assessment.Collection run
New controls with collection already scheduled2Covered by an existing run plan — verify the plan targets the new ID.Collection run
New controls already evidenced35Satisfied by evidence collected against the shared control spine.Mapping change

254 evidenced + 35 scheduled + 19 with nothing on file = 308 — the same posture carried on the ARC-AMPE v1.02 baseline and the command board.

Re-collection plan

5 run plans · every result seals to the chain

PlanScopeControlsWhy it has to runCadence
ampe-privacy-transparency-sweepPTPT family · 10 controls10Family did not exist under MARS-E. Consent, privacy notice and PII-processing evidence has never been collected against these IDs.new · quarterly
ampe-supply-chain-baselineSRSR family · 4 controls4SCRM plan, SCRM team and supply-chain process evidence has no MARS-E ancestor to inherit from.new · annual
access-review-deltaAC · IAOkta · 1,284 identities6Picks up IA-11 re-authentication, IA-12 identity proofing and AC-06(07) privilege review — all new IDs in Rev 5.weekly
evidence-freshness-sweepallAll programs · 764 controls65Control-ID map has to be re-pointed before the sweep can score the ARC-AMPE lane; renumbered and retitled controls currently read as unmapped.daily 06:00 UTC
poam-assembly-dry-runallARC-AMPE · Q3 POA&M19Every control still without evidence has to carry a POA&M item citing the ARC-AMPE ID, not the MARS-E one.gate − 21 days

Plans run on the continuous compliance ledger, against the operative control IDs. Until the map is re-pointed, a renumbered control reads as unmapped, not as covered.