Skip to main content
—
Framework library
Framework module · cms-ede-year-9

CMS Enhanced Direct Enrollment

The pathway that lets a web broker or issuer run the whole ACA enrollment experience on its own site instead of handing the consumer off to HealthCare.gov.

Year 9 (PY 2026–PY 2027) · CMS — Direct Enrollment Partners · published 2026-04-10

Standing today
Implemented
Controlled CMS EDE reference · repository-verified delivery record

00Answer

from the registry record
What is CMS Enhanced Direct Enrollment?
The pathway that lets a web broker or issuer run the whole ACA enrollment experience on its own site instead of handing the consumer off to HealthCare.gov.
Who does CMS Enhanced Direct Enrollment apply to?
CMS Enhanced Direct Enrollment applies to healthcare, insurance, US, per CMS — Direct Enrollment Partners.
What is the current version of CMS Enhanced Direct Enrollment?
The current edition is Year 9 (PY 2026–PY 2027), issued by CMS — Direct Enrollment Partners and published 2026-04-10. Source: https://www.cms.gov/marketplace-private-insurance/agents-brokers/direct-enrollment-partners.
What does an assessment under CMS Enhanced Direct Enrollment require?
1,155 control units are on record (Nine CMS EDE evidence lanes with a source-native requirement set (Application UI Toolkit items, Eligibility Results Toolkit cases, Partner Test Case Suite ids, API FIT ids, Communications Toolkit requirement numbers). CMS publishes the audit guidelines as PDFs; verbatim requirement text is not ingested, so there is no checksummed control catalog for this regime.), organized into 5 control families: Application UI, API FIT, Language access, Accessibility, ARC-AMPE baseline.

01Standing

Implemented

A project opens into working evidence lanes, and collection runs against a real target — a registered test plan or a production release path.

Blueprint with 9 evidence lanes. 6 of 6 registered test plans run against a real target. Sealed-package release route with a controlled CMS EDE UAT reference corpus behind it.

Engagement
CMS EDE Year 9
Control set
Nine CMS EDE evidence lanes with a source-native requirement set (Application UI Toolkit items, Eligibility Results Toolkit cases, Partner Test Case Suite ids, API FIT ids, Communications Toolkit requirement numbers). CMS publishes the audit guidelines as PDFs; verbatim requirement text is not ingested, so there is no checksummed control catalog for this regime.
Native identifiers
Application UI Toolkit UI Questions Item #, Eligibility Results Toolkit IDs, Partner Test Case Suite IDs, API Functional Integration Toolkit IDs, Communications Toolkit requirement numbers, ARC-AMPE / NIST / CMS control IDs.
Evidence lanes
  1. 01Application UI Toolkitconsumer flow screenshots · broker flow screenshots · agent flow screenshots · source-row evidence index · applicationAnswers JSON
  2. 02Eligibility Results Toolkiteligibility result screenshots · raw eligibility JSON · test scenario result CSV
  3. 03Partner Test Case SuiteCMS UAT test run log · test case screenshots · raw hub responses · auditor-ready package manifest
  4. 04API Functional Integration Toolkitrequest/response JSON · API scenario result CSV · mTLS/certificate evidence · payload security evidence
  5. 05Communications Toolkitlegal page screenshots · notice text extracts · Spanish-language option evidence · source mapping CSV
  6. 06Eligibility Determination Noticesgenerated EDN PDFs · notice metadata JSON · delivery/archive proof
  7. 07Identity Proofingconsumer identity-proofing screenshots · RBA/GetRecord response evidence · IDM/Okta configuration evidence · fallback/documentation path proof
  8. 08Registration and Onboardingagent registration screenshots · broker registration screenshots · MFA setup evidence · approval gate evidence
  9. 09Security Controls - ARC-AMPE / MARS-ESSPP · SAR · POA&M · ISA · security control screenshots · configuration exports

02Registry record

checked 2026-08-28
Registry status
Beta · catalog on diskParsed catalog: a source-pinned control or requirement catalog for this regime exists in the repo. `catalogPath` is non-null and `controlCount` is real. This does not mean tenant workflows are activated or that an assurance outcome has been earned.
Control units
1,155Nine CMS EDE evidence lanes with a source-native requirement set (Application UI Toolkit items, Eligibility Results Toolkit cases, Partner Test Case Suite ids, API FIT ids, Communications Toolkit requirement numbers). CMS publishes the audit guidelines as PDFs; verbatim requirement text is not ingested, so there is no checksummed control catalog for this regime.
Control families
Application UI · API FIT · Language access · Accessibility · ARC-AMPE baseline
Applies to
healthcare · insurance · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-28
Pending change
The Year 9 audit submission window closed 2026-07-01. CMS has said it intends to publish updated guidelines for calendar-year 2026 audit submissions (Year 10); no Year 10 document was found at this check.Expected: Unannounced

03Version ledger

2 editions
Year 8Superseded2025-04-16
Year 9 (PY 2026–PY 2027)Current edition · supersedes Year 82026-04-10

04Authority intelligence

reviewed 2026-08-30

Curated primary-source signals connected to this registry record. An authority change creates review work; it does not silently change tenant posture, evidence credit, or prior decisions.

  1. Program update

    CMS publishes Year 9 EDE audit guidance for PY 2026–2027.

    The current operational-readiness guidance preserves program-native requirements across application, API, privacy, security, and third-party audit work.

    Operating move

    Keep the CMS source identifier, scenario, persona, environment, collection method, blocker, and reviewer decision attached to every artifact candidate.

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to healthcare · CMS's NIST-aligned security and privacy framework for ACA administering entities and applicable partner entities. Volume II supplies tailored control baselines and system security and privacy plan templates; applicability depends on entity type, law, regulation, or contract.

  2. Also applies to insurance · A model law for insurance-sector information security programs, incident response, and breach notification, adopted individually by roughly 25-28 US states as of 2026. It becomes enforceable law only where a state has enacted its own version — the requirements can vary state to state.

  3. Also applies to healthcare · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

  4. NYDFS 23 NYCRR 50023 NYCRR 500 (2023 amendments)

    Also applies to insurance · New York's cybersecurity regulation for banks, insurers, and other DFS-licensed entities — with a named CISO, board reporting, and 72-hour incident notice.

CMS Enhanced Direct Enrollment | ControlFrame