Bindinglaw

US · guidance

CMS Pub. 100-06, ch. 7, § 30.2

Certification Statement

activein force · 2026-08-25 – presentas-observed

Contractors shall provide a certification statement to CMS pertaining to your internal

controls. On the following page is a generic certification statement. This statement should

be included as part of your CPIC. The statement is to be signed jointly by your Medicare

CFO and Vice President (VP) for Medicare, RDS or MSPRC or the equivalent Senior

Executive responsible for Medicare, RDS or MSPRC.

The CPIC is due within fifteen (15) business days after June 30th and shall cover the

period from October 1st through June 30th. An updated assurance statement for the period

July 1st through September 30th is due to CMS within five (5) business days after

September 30th. Your certification statement should follow this outline:

Sample Certification Statement:

Chief Financial Officer

Office of Financial Management

Attn: Accounting Management Group, C3-13-08

Centers for Medicare & Medicaid Services

7500 Security Boulevard

Baltimore, MD 21244-1850

Dear Chief Financial Officer:

As the (Chief Financial Officer and Vice President of (contractor name), we are writing

to provide certification of reasonable assurance for the period October 1 through June

30 that (contractor name) internal controls are in compliance with the Federal

Managers' Financial Integrity Act (FMFIA) and Chief Financial Officers (CFO) Act by

incorporating internal control standards into our operations. We are also providing an

unqualified [or qualified] statement of assurance that (contractor name) has effective

internal controls over financial reporting in compliance with revised OMB Circular A-

123, Appendix A [except for the SSAE 18 Section I finding(s) and/or material

weakness(es) identified in the attached Report of Material Weaknesses].

We are cognizant of the importance of internal controls. We have taken the necessary

actions to assure that an evaluation of the system of internal controls and the inherent

risks have been conducted and documented in a conscientious and thorough manner.

Accordingly, we have included an assessment and testing of the programmatic,

administrative, and financial controls for the (type of program) operations.

In the enclosures to this letter, we have provided an executive summary that identifies

a list of the minimum requirements. (See Section 30.3 - Executive Summary for the list of

minimum requirements to be provided in your CPIC.)

If material weaknesses have been identified, use the following language: "Material

weaknesses have been reported to you and the appropriate Innovation & Financial

Management (IFM) office, and/or COR. The respective Corrective Action Plans have

been forwarded to your office." If no material weaknesses were identified, use the

following language: "No material weaknesses have been identified during our review;

therefore no material weaknesses have been reported."

We have included a description of our risk assessment analysis and our CPIC Report of

Material Weaknesses. This letter and attachments summarize the results of our review.

We also understand that officials from the Centers for Medicare & Medicaid Services,

Office of Inspector General, Government Accountability Office, or any other

appropriate Government agency have authority to request and review the working

papers from our evaluation.

Sincerely,

______________________________________

[Chief Financial Officer Signature]

______________________________________

[Vice President for (type of program) Signature]

End Section 30.2 – Certification Statement: Back to Table of Contents

History

(Rev. 10614, Issued: 03-23-21, Effective: 10-01-20, Implementation: 04-22-21)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
abe78953293915db6b3232d4a790675555e59bc8fd9fec26e98cccf619a6b571
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.
CMS Pub. 100-06, ch. 7, § 30.2 — Certification Statem… · binding.law