CMS Enhanced Direct Enrollment
The pathway that lets a web broker or issuer run the whole ACA enrollment experience on its own site instead of handing the consumer off to HealthCare.gov.
Year 9 (PY 2026–PY 2027) · CMS — Direct Enrollment Partners · published 2026-04-10
00Answer
01Standing
A project opens into working evidence lanes, and collection runs against a real target — a registered test plan or a production release path.
Blueprint with 9 evidence lanes. 6 of 6 registered test plans run against a real target. Sealed-package release route with a controlled CMS EDE UAT reference corpus behind it.
- Engagement
- CMS EDE Year 9
- Control set
- Nine CMS EDE evidence lanes with a source-native requirement set (Application UI Toolkit items, Eligibility Results Toolkit cases, Partner Test Case Suite ids, API FIT ids, Communications Toolkit requirement numbers). CMS publishes the audit guidelines as PDFs; verbatim requirement text is not ingested, so there is no checksummed control catalog for this regime.
- Native identifiers
- Application UI Toolkit UI Questions Item #, Eligibility Results Toolkit IDs, Partner Test Case Suite IDs, API Functional Integration Toolkit IDs, Communications Toolkit requirement numbers, ARC-AMPE / NIST / CMS control IDs.
- Evidence lanes
- 01Application UI Toolkitconsumer flow screenshots · broker flow screenshots · agent flow screenshots · source-row evidence index · applicationAnswers JSON
- 02Eligibility Results Toolkiteligibility result screenshots · raw eligibility JSON · test scenario result CSV
- 03Partner Test Case SuiteCMS UAT test run log · test case screenshots · raw hub responses · auditor-ready package manifest
- 04API Functional Integration Toolkitrequest/response JSON · API scenario result CSV · mTLS/certificate evidence · payload security evidence
- 05Communications Toolkitlegal page screenshots · notice text extracts · Spanish-language option evidence · source mapping CSV
- 06Eligibility Determination Noticesgenerated EDN PDFs · notice metadata JSON · delivery/archive proof
- 07Identity Proofingconsumer identity-proofing screenshots · RBA/GetRecord response evidence · IDM/Okta configuration evidence · fallback/documentation path proof
- 08Registration and Onboardingagent registration screenshots · broker registration screenshots · MFA setup evidence · approval gate evidence
- 09Security Controls - ARC-AMPE / MARS-ESSPP · SAR · POA&M · ISA · security control screenshots · configuration exports
02Registry record
- Registry status
- Beta · catalog on diskParsed catalog: a source-pinned control or requirement catalog for this regime exists in the repo. `catalogPath` is non-null and `controlCount` is real. This does not mean tenant workflows are activated or that an assurance outcome has been earned.
- Control units
- 1,155Nine CMS EDE evidence lanes with a source-native requirement set (Application UI Toolkit items, Eligibility Results Toolkit cases, Partner Test Case Suite ids, API FIT ids, Communications Toolkit requirement numbers). CMS publishes the audit guidelines as PDFs; verbatim requirement text is not ingested, so there is no checksummed control catalog for this regime.
- Control families
- Application UI · API FIT · Language access · Accessibility · ARC-AMPE baseline
- Applies to
- healthcare · insurance · US
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-28
- Pending change
- The Year 9 audit submission window closed 2026-07-01. CMS has said it intends to publish updated guidelines for calendar-year 2026 audit submissions (Year 10); no Year 10 document was found at this check.Expected: Unannounced
03Version ledger
| Year 8 | Superseded | 2025-04-16 |
| Year 9 (PY 2026–PY 2027) | Current edition · supersedes Year 8 | 2026-04-10 |
04Authority intelligence
Curated primary-source signals connected to this registry record. An authority change creates review work; it does not silently change tenant posture, evidence credit, or prior decisions.
- Program update
CMS publishes Year 9 EDE audit guidance for PY 2026–2027.
The current operational-readiness guidance preserves program-native requirements across application, API, privacy, security, and third-party audit work.
Operating moveKeep the CMS source identifier, scenario, persona, environment, collection method, blocker, and reviewer decision attached to every artifact candidate.
05Change history
06Related frameworks
- ARC-AMPEv1.02
Also applies to healthcare · CMS's NIST-aligned security and privacy framework for ACA administering entities and applicable partner entities. Volume II supplies tailored control baselines and system security and privacy plan templates; applicability depends on entity type, law, regulation, or contract.
- NAIC Insurance Data Security Model LawModel #668
Also applies to insurance · A model law for insurance-sector information security programs, incident response, and breach notification, adopted individually by roughly 25-28 US states as of 2026. It becomes enforceable law only where a state has enacted its own version — the requirements can vary state to state.
- HITRUST CSFv11.8.0
Also applies to healthcare · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
- NYDFS 23 NYCRR 50023 NYCRR 500 (2023 amendments)
Also applies to insurance · New York's cybersecurity regulation for banks, insurers, and other DFS-licensed entities — with a named CISO, board reporting, and 72-hour incident notice.