Skip to main content
Framework library
Framework module · cms-ars-5-2

CMS Acceptable Risk Safeguards

CMS's minimum security and privacy control baseline for CMS information systems and CMS contractors. It is distinct from the Marketplace-focused ARC-AMPE baseline.

ARS 5.2 · CMS Information Security and Privacy Program · published 2026-07-01

Standing today
Directory entry

00Answer

from the registry record
What is CMS Acceptable Risk Safeguards?
CMS's minimum security and privacy control baseline for CMS information systems and CMS contractors. It is distinct from the Marketplace-focused ARC-AMPE baseline.
Who does CMS Acceptable Risk Safeguards apply to?
CMS Acceptable Risk Safeguards applies to federal healthcare, CMS contractors, US, per CMS Information Security and Privacy Program.
What is the current version of CMS Acceptable Risk Safeguards?
The current edition is ARS 5.2, issued by CMS Information Security and Privacy Program and published 2026-07-01. Source: https://security.cms.gov/policy-guidance/cms-acceptable-risk-safeguards-ars.
What does an assessment under CMS Acceptable Risk Safeguards require?
No control catalog has been ingested for CMS Acceptable Risk Safeguards yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

CMS Acceptable Risk Safeguards is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Metadata only; the ARS 5.2 catalog, overlays, and organizational parameters have not been ingested or modelled.

02Registry record

checked 2026-08-28
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
NIST SP 800-53 control families · Zero Trust implementation expectations · High Value Asset overlay · Federal Tax Information overlay · MAC ARS
Applies to
federal healthcare · CMS contractors · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-28

03Version ledger

2 editions
ARS 5.1Superseded2023-07-26
ARS 5.2Current edition · supersedes ARS 5.12026-07-01

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to CMS contractors · The IRS's safeguard requirements for any agency, contractor, or state/local entity that receives federal tax information — relevant to any government contractor or CMS-adjacent SaaS vendor handling federal tax data.

  2. GAO Green Book2025 Revision

    Same framework family · The federal internal-control standard for designing, implementing, operating, and evaluating controls over operations, reporting, and compliance. It supplies auditable criteria for federal entities; it is not an organizational certification.

  3. Same framework family · A standardized assessment, authorization, and continuous-monitoring program for cloud services used by state and local governments, built on NIST SP 800-53 Rev. 5. Core, Ready, and Authorized are service-offering statuses—not company-wide certifications. StateRAMP rebranded to GovRAMP on 2025-02-14; StateRAMP, Inc. remains the legal entity operating under the GovRAMP name.

  4. Same framework family · Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default.

CMS Acceptable Risk Safeguards | ControlFrame