CMS Acceptable Risk Safeguards
CMS's minimum security and privacy control baseline for CMS information systems and CMS contractors. It is distinct from the Marketplace-focused ARC-AMPE baseline.
ARS 5.2 · CMS Information Security and Privacy Program · published 2026-07-01
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
CMS Acceptable Risk Safeguards is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Metadata only; the ARS 5.2 catalog, overlays, and organizational parameters have not been ingested or modelled.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- NIST SP 800-53 control families · Zero Trust implementation expectations · High Value Asset overlay · Federal Tax Information overlay · MAC ARS
- Applies to
- federal healthcare · CMS contractors · US
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-28
03Version ledger
| ARS 5.1 | Superseded | 2023-07-26 |
| ARS 5.2 | Current edition · supersedes ARS 5.1 | 2026-07-01 |
05Change history
06Related frameworks
- IRS Publication 1075Rev. 11-2021
Also applies to CMS contractors · The IRS's safeguard requirements for any agency, contractor, or state/local entity that receives federal tax information — relevant to any government contractor or CMS-adjacent SaaS vendor handling federal tax data.
- GAO Green Book2025 Revision
Same framework family · The federal internal-control standard for designing, implementing, operating, and evaluating controls over operations, reporting, and compliance. It supplies auditable criteria for federal entities; it is not an organizational certification.
- GovRAMP (formerly StateRAMP)Rev. 5 baselines
Same framework family · A standardized assessment, authorization, and continuous-monitoring program for cloud services used by state and local governments, built on NIST SP 800-53 Rev. 5. Core, Ready, and Authorized are service-offering statuses—not company-wide certifications. StateRAMP rebranded to GovRAMP on 2025-02-14; StateRAMP, Inc. remains the legal entity operating under the GovRAMP name.
- NIST SP 800-172Rev. 3
Same framework family · Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default.