Skip to main content
Framework library
Framework module · fisma-2014

FISMA

The Federal Information Security Modernization Act of 2014 — the statutory authority a federal RFP names, implemented operationally through NIST SP 800-53 and the NIST Cybersecurity Framework, both already tracked as their own registry entries.

Federal Information Security Modernization Act of 2014 · Cybersecurity and Infrastructure Security Agency · published 2014-12-18

Standing today
Directory entry

00Answer

from the registry record
What is FISMA?
The Federal Information Security Modernization Act of 2014 — the statutory authority a federal RFP names, implemented operationally through NIST SP 800-53 and the NIST Cybersecurity Framework, both already tracked as their own registry entries.
Who does FISMA apply to?
FISMA applies to federal, federal contractors, US, per Cybersecurity and Infrastructure Security Agency.
What is the current version of FISMA?
The current edition is Federal Information Security Modernization Act of 2014, issued by Cybersecurity and Infrastructure Security Agency and published 2014-12-18. Source: https://www.cisa.gov/topics/cyber-threats-and-advisories/federal-information-security-modernization-act.
What does an assessment under FISMA require?
No control catalog has been ingested for FISMA yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

FISMA is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Statutory authority only; implemented through NIST SP 800-53 and the NIST Cybersecurity Framework, both already tracked separately. No FISMA-specific control catalog exists to ingest.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Agency information security programs · OMB oversight · Annual independent evaluation · Incident reporting
Applies to
federal · federal contractors · US
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
Pending change
No modernization bill has passed since 2014. A 2023 reform bill advanced through Senate committee markup but did not become law; no equivalent bill has been tracked in the current Congress as of this check.Expected: No pending legislation identified

03Version ledger

2 editions
Federal Information Security Management Act of 2002Superseded2002-12-17
Federal Information Security Modernization Act of 2014Current edition · supersedes Federal Information Security Management Act of 20022014-12-18

05Change history

06Related frameworks

scored from registry facts
  1. GAO Green Book2025 Revision

    Also applies to federal · The federal internal-control standard for designing, implementing, operating, and evaluating controls over operations, reporting, and compliance. It supplies auditable criteria for federal entities; it is not an organizational certification.

  2. Also applies to federal · CMS's NIST-aligned security and privacy framework for ACA administering entities and applicable partner entities. Volume II supplies tailored control baselines and system security and privacy plan templates; applicability depends on entity type, law, regulation, or contract.

  3. GAO FISCAMJune 2026 (GAO-26-108633)

    Also applies to federal · The federal audit methodology for assessing the design, implementation, and operating effectiveness of information-system controls under generally accepted government auditing standards. It is audit guidance, not an agency authorization or certification.

  4. Also applies to federal contractors · NIST's current recommended security requirements for Controlled Unclassified Information in non-federal systems. Contractual applicability is agreement-specific; CMMC Phase I continues to use Rev. 2 rather than automatically inheriting Rev. 3.

FISMA | ControlFrame