Bindinglaw

US · guidance

CMS Pub. 100-06, ch. 7, § 30.1

Certification Package for Internal Controls (CPIC) Requirements

activein force · 2026-08-25 – presentas-observed

NOTE: This section is only applicable to the following listed CMS Contractors:

# Contractor Workload

1 DME MAC Jurisdiction A

2 DME MAC Jurisdiction B

3 DME MAC Jurisdiction C

4 DME MAC Jurisdiction D

5 Parts A & B MAC Jurisdiction 5

6 Parts A & B MAC Jurisdiction 6

7 Parts A & B MAC Jurisdiction 8

8 Parts A & B MAC Jurisdiction 15

9 Parts A & B MAC Jurisdiction E

10 Parts A & B MAC Jurisdiction F

11 Parts A & B MAC Jurisdiction H

12 Parts A & B MAC Jurisdiction J

13 Parts A & B MAC Jurisdiction K

14 Parts A & B MAC Jurisdiction L

15 Parts A & B MAC Jurisdiction M

16 Parts A & B MAC Jurisdiction N

17 Specialty MAC Railroad Board (RRB)

18 Pricing, Data Analysis, and Coding (PDAC) Contractor

19 Affordable Care Act Exchange Contractor

20 Benefits Coordination and Recovery Center (BCRC),

Medicare Secondary Payer Recovery Contractor (MSPRC)

21 Commercial Repayment Center (CRC), MSPRC

22 Retiree Drug Subsidy (RDS) Part D Contractor

The contractor certification process provides CMS with assurance that contractors are in compliance with

the FMFIA, OMB Circular A-123, and CFO Act of 1990 by incorporating internal control standards into

their operations. The contractor certification process supports the audit of CMS' financial statements by the

Office of Inspector General (OIG) and the CMS Administrator's FMFIA assurance statement.

This compliance is achieved by an annual certification statement included in its annual CPIC submission.

CMS has required each contractor to certify that internal controls are in place to identify and correct areas of

weakness in its operations. Contractors are expected to evaluate the effectiveness of their operations against

CMS' control objectives discussed above. The control objectives represent the minimum expectations for

contractor performance in the area of internal controls.

Contractors shall have written policies and procedures regarding their annual CPIC preparation and

submission process. Contractors shall also have written policies and procedures to address potential internal

control deficiencies identified by employees and managers in the course of their daily operations. This

includes the process for reporting issues upward through the appropriate levels of management, tracking and

correcting deficiencies, and inclusion in the CPIC submission.

The CPIC represents a summary of your internal control environment for the period October 1st through

June 30th (the CPIC period), as certified by your organization. It shall include an explicit conclusion as to

whether the internal controls over financial reporting are effective (see Section 30.1.1). All material

weaknesses identified during this period shall be included in the CPIC submission. Contractors should

consider the results of internal and external audits and reviews, such as GAO, OIG, and CFO Act audits,

consultant reviews, management control reviews, CPE reviews, SSAE 18 audits, A-123 Appendix A

reviews, and other similar activities. These findings should be classified as control deficiencies, significant

deficiencies, or material weaknesses based upon the definitions provided in Section 30.6.

The contractor shall submit one CPIC report for each type of contract (i.e., A/B, DME, & Specialty MAC

workloads, Retiree Drug Subsidy (RDS), and Medicare Secondary Payer Recovery Contractor (MSPRC)

workloads). The contractor shall follow these guidelines when submitting the CPIC for A/B, DME, &

Specialty MACs:

• Contractors with multiple A/B and DME MAC jurisdictions shall submit one CPIC report for each

type of contract (i.e., A/B, Durable Medical Equipment (DME), & Specialty MAC workloads).

Therefore. Contractors with multiple A/B and DME MACs jurisdiction shall submit a CPIC for each

jurisdiction.

Example Multiple A/B & DME CPIC Submission Situation:

• XYZ Corporation has four (4) A/B and DME MAC jurisdictions A, C, 6, & M.

• XYZ Corporation shall submit four (4) separate CPICs for each jurisdiction:

o CPIC for DME Jurisdiction A

o CPIC for DME Jurisdiction C

o CPIC for A/B Jurisdiction 6

o CPIC for A/B Jurisdiction M

• The Specialty MAC RRB shall submit a CPIC.

• Contractors that transitioned out of the program prior to June 30th, and are not assuming additional

workloads are not required to submit a CPIC.

Electronic CPIC reports shall be received by CMS within fifteen (15) business days after June 30th. The

contractor is not required to submit a hard copy report if it has the capability to insert electronic signatures

or if the CPIC is sent from the VP of Operations’ email or the CFO’s email.

An electronic version of all documents (including updates) submitted as part of your CPIC submission shall

be sent to CMS’ Office of Financial Management (OFM) at internalcontrols@cms.hhs.gov as Microsoft

Excel or Word files. Electronic copies shall also be sent as follows:

• A/B, DME, and Specialty MACs shall send to the:

o The assigned CFO Technical Monitor and the Financial Management (FM) Division Director

of that CMS office location area.

o Contracting Officer’s Representative (COR) of the A/B, DME, or Specialty MAC.

• RDS and MSPRC Contractors shall send to the CMS COR.

A hard copy is not required to be submitted.

The CPIC Report Package shall include:

• Certification Statement, see Section 30.2;

• Executive Summary, see Section 30.3;

• Description of your Risk Assessment Process, see Section 20.1. This should include a:

o Matrix to illustrate the prioritization of risk and exposure factors

o Narrative or flowchart that outlines the risk assessment process

• CPIC Report of Material Weaknesses, see Section 30.4.

Contractors shall submit an update for the period July 1st through September 30th to report any

subsequently identified material weaknesses. The update shall be no more than a one page summary of any

material weaknesses and the proposed corrective action. If no material weaknesses have been identified, the

contractor shall submit the following for each jurisdiction or a combined statement for all jurisdictions: “As

of September 30th, no material weaknesses (or no additional material weaknesses) have been identified

during the period July 1 through September 30th for Fiscal Year 20XX”. The submission of the update

should follow the same guidelines as the initial CPIC. The CPIC update is due within five (5) business days

after September 30th. If a material weakness is identified, then a CAP shall be completed in accordance to

the guidelines shown at Section 40.1.

The file names for all electronic files submitted, as part of your CPIC package should begin with the three,

four, or five letter abbreviation assigned to each contractor in Section 40.3. Additionally, in the subject line

of your email submission, you shall include the corporate name of the entity submitting the CPIC.

Maintain the appropriate and necessary documents to support any assertions and conclusions made during

the self-assessment process. In your working papers, you are required to document the respective policies

and procedures for each control objective reviewed. These policies and procedures should be in writing, be

updated to reflect any changes in operations, and be operating effectively and efficiently within your

organization.

The supporting documentation and rationale for your certification statement, whether prepared internally or

by an external organization, shall be available for review and copying by CMS and its authorized

representatives.

End Section 30.1 – Certification Package for Internal Controls (CPIC) Requirements: Back to Table of

Contents

History

(Rev. 11133, Issued:11-30-21, Effective: 10-01-21, Implementation: 12-31-21)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
2705215c00d3e2383a8a4100021737dc71e3a219000deb4b52944bf437778d35
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.