US · guidance
CMS Pub. 100-06, ch. 7, § 30.8
Statement on Standards for Attestation Engagements (SSAE)
Number 18, (SSAE 18) Reporting on Controls at Service Providers
(Rev. 11133, Issued:11-30-21, Effective: 10-01-21, Implementation: 12-31-21)
NOTE: This section is only applicable to the following listed A/B, DME, and
Specialty MACs:
# MAC Type & Jurisdiction/Workload
1 DME MAC Jurisdiction A
2 DME MAC Jurisdiction B
3 DME MAC Jurisdiction C
4 DME MAC Jurisdiction D
5 Parts A & B MAC Jurisdiction 5
6 Parts A & B MAC Jurisdiction 6
7 Parts A & B MAC Jurisdiction 8
8 Parts A & B MAC Jurisdiction 15
9 Parts A & B MAC Jurisdiction E
10 Parts A & B MAC Jurisdiction F
11 Parts A & B MAC Jurisdiction H
12 Parts A & B MAC Jurisdiction J
13 Parts A & B MAC Jurisdiction K
14 Parts A & B MAC Jurisdiction L
15 Parts A & B MAC Jurisdiction M
# MAC Type & Jurisdiction/Workload
16 Parts A & B MAC Jurisdiction N
17 Specialty MAC Railroad Board (RRB)
In lieu of receiving an A-123 Appendix A review, A/B, DME, and Specialty MACs are
required to undergo a SSAE 18 SOC 1, Type II audit.
CMS shall contract with an independent certified public accounting (CPA) firm to
perform the SSAE 18 audit. The A/B, DME, and Specialty MACs shall cooperate with
the audit which may include, but is not limited to, providing all documentation requested,
CPIC results, management assertions, coordinating interviews with key personnel,
participating in entrance and exit conferences, providing workspace, and internet
connectivity, etc.
The A/B, DME, and SMACs shall ensure that all subcontractors are properly identified as
inclusive and/or carved out. Based on the subcontractors’ impact on the MAC’s financial
statement, the subcontractor may be in scope (i.e. inclusive method) for the SSAE 18
audit.
The scope of the SSAE 18 audit begins October 1st of each federal fiscal year and ends
no earlier than March 31st (6 months) (e.g. For Federal Fiscal Year 2020, the scope of the
audit begins October 1st, 2019, and ends March 31st, 2020).
Initial SSAE 18 Control Objectives:
For new A/B, DME, and Specialty MACs, excluding cases where incumbent MACs
transition to a new MAC jurisdiction, initial SSAE 18 audit shall include the following
thirteen (13) listed CMS Control Objectives as described under Section 50 of this IOM:
# CMS Control Objective Areas for Initial SSAE 18 Audit Testing
1 50.1 – A Controls – Information Systems
2 50.2 – B Controls – Claims Processing
3 50.3 – C Controls – Appeals
4 50.4 – D Controls – Beneficiary / Provider Services
5 50.5 – E Controls – Complementary Credits
6 50.6 – F Controls – Medical Review (MR)
7 50.7 – G Controls – Medicare Secondary Payer (MSP)
8 50.8 – H Controls – Administrative
9 50.9 – I Controls – Provider Audit
10 50.10 – J Controls – Financial Reporting Review Requirements
11 50.11 – K Controls – Debt Referral (MSP and Non-MSP)
12 50.12 – L Controls – Non-MSP Debt Collection
13 50.13 – M Controls – Provider Enrollment
Recurring SSAE 18 Control Objectives:
In subsequent years, A/B, DME, and Specialty MACs SSAE 18 audits shall include the
following eight (8) control objectives:
# CMS Control Objective Areas for Recurring SSAE 18 Audit Testing
1 50.1 – A Controls – Information Systems
2 50.2 – B Controls – Claims Processing
3 50.6 – F Controls – Medical Review (MR)
4 50.7 – G Controls – Medicare Secondary Payer (MSP)
5 50.9 – I Controls – Provider Audit
6 50.10 – J Controls – Financial Reporting Review Requirements
7 50.11 – K Controls – Debt Referral (MSP and Non-MSP)
8 50.12 – L Controls – Non-MSP Debt Collection
The remaining Control Objectives may be audited based on professional judgment and/or
based on the risk identified from the annual CPIC assessment.
Points of Contact (POC) – The A/B, DME, and Specialty MACs shall assign a POC that
will assist to ensure that all required parties are invited to the following scheduled events.
Entrance Conference – The A/B, DME, and Specialty MACs shall participate in the
SSAE 18 entrance conference. The entrance conference is the start of each engagement
to discuss the scope, timeframe, and any other issues relating to the engagement.
Status Meetings – The A/B, DME, and Specialty MACs shall participate in the SSAE 18
status meetings. The status meetings will include discussion of the audit activities
performed to date. The meeting will including a status of CAPs, potential findings and/or
exceptions and any issues that may affect the completion of the work.
Preliminary Exit Conference – The A/B, DME, and Specialty MACs shall participate in
the SSAE 18 preliminary exit conference. The preliminary exit conference will include a
status of the engagement, any outstanding issues, additional documentation requests,
potential findings and/or exceptions to date, estimated exit conference date, and other
topics to be addressed.
Exit Conference Report – Prior to the exit conference, the A/B, DME, and Specialty
MACs will receive the SSAE 18 exit conference report from the CPA firm. The exit
conference report shall include any outstanding issues, summary of findings and/or
exceptions, and any other items that requires the MAC’s attention. The A/B, DME, and
Specialty MACs shall review the exit conference report in preparation of the exit
conference.
Exit Conference – The A/B, DME, and Specialty MAC shall participate in the SSAE 18
exit conference. The exit conference will include items such as the status of the
examination, outstanding issues, any findings and/or exceptions, agree disagree letter,
management representation letter, estimated draft report issuance date, etc.
Draft SSAE-18 and CAP Follow up Reports – The A/B, DME, and Specialty MACs
should receive the draft SSAE-18 and CAP Follow up reports no later than June 1st. The
A/B, DME, and Specialty MACs shall review the draft reports for accuracy and provide
any comments back to the CPA firm and CMS no later than ten (10) business days after
June 1st.
Final SSAE-18 and CAP Follow Up Reports – The A/B, DME, and Specialty MACs
will receive final SSAE 18 and CAP Follow Up reports no later than July 1st.
SSAE 18 Bridge Letters – The A/B, DME, and Specialty MACs shall submit a bridge
letter attesting to the internal controls environment for the period of April 1st to
September 30th. This bridge letter is critically important to the maintenance and
demonstration of a strong internal control environment that supports the CMS internal
control objectives: effective and efficient operations, reliable reporting, and compliance
with applicable laws and regulations. The bridge letter is due within five (5) business
days after September 30th and should be submitted via email to
InternalControls@cms.hhs.gov. The contractor shall complete/submit a separate bridge
letter for each jurisdiction. The bridge letter shall be signed by the Chief Financial
Officer (or designee).
A/B, DME, and Specialty MACs may use the attached sample language as the basis for
their bridge letter or they may submit original language. At a minimum, the bridge letter
shall have these key points addressed:
• Name of CPA firm who prepared the latest SSAE 18 report;
• Date the SSAE 18 report was issued;
• Audit period covered by the most recent SSAE 18 report;
• The date the service organization is providing this assertion (through the date of
the bridge letter or the as of date provided in the request for the bridge letter);
• Any material changes to the internal control environment (if applicable);
• Statement that the service organization is not aware of any material changes to the
control environment;
• Statement that user entities are responsible for adhering to complementary user
entity control from SSAE 18 report;
• Disclaimer that the bridge letter is not a substitute for the actual SSAE 18 report.
The bridge letter will be reviewed by the CMS A-123 Technical Team (ATT) for
compliance. If there are any questions regarding the letter, the ATT will contact the A/B,
DME, and Specialty MAC’s POC.
[This letter should go on the A/B, DME, or Specialty MAC’s letter head]
Sample Bridge Letter – No Material Changes:
[Current Date]
Bridge Letter
Centers for Medicare & Medicaid Services
Office of Financial Management
7500 Security Boulevard, Mailstop C3-13-08
Baltimore, MD 21244-1850
Attn: Internal Control Team
Dear CMS Internal Controls Team:
We have received your request for information regarding material changes in internal
control related to the [list services here (A/B, DME, or Specialty MAC)]. [CPA firm
name] prepared the latest Type II SSAE 18 for these services and the report is dated
[report date]. This report includes tests of operating effectiveness for the period ending
[period end date].
[Name of A/B, DME, or Specialty MAC] recognizes the need to maintain an appropriate
internal control environment and report upon the effectiveness, as well as material
changes to its internal controls. As of [current date], I am not aware of any material
changes in our control environment that would adversely affect the Auditor’s Opinion
reached in the [report end date (not the same as the report date)] report for the above
named SSAE 18.
You should also be aware that [A/B, DME, or Specialty MAC name], as a normal part of
its operations, continually updates its services and technology as appropriate. In addition,
the controls for all of [A/B, DME, or Specialty MAC name] services were designed with
certain responsibilities required of the system users (See Complimentary User Entity
Control in the SSAE 18 report). [A/B, DME, or Specialty MAC name] controls must
always be evaluated in conjunction with an assessment of the strength of these user
controls.
Finally, in order to conclude upon the design and effectiveness of internal controls for
[A/B, DME, or Specialty MAC name], you must read the current SSAE 18 report. This
letter is not intended to be a substitute for the SSAE 18 report.
Sincerely,
[Name of Member of Management1]
[Title]
1 Should be a signature from one of the same persons that signed the letter of representations.
Sample Bridge Letter – Material Changes:
[Current Date]
Bridge Letter
Centers for Medicare & Medicaid Services
Office of Financial Management
7500 Security Boulevard, Mailstop C3-13-08
Baltimore, MD 21244-1850
Attn: Internal Control Team
Dear CMS Internal Controls Team:
We have received your request for information regarding material changes in internal
control related to the [list services here (A/B, DME, or Specialty MAC)]. [CPA firm
name] prepared the latest Type II SSAE 18 for these services and the report is dated
[report date]. This report includes tests of operating effectiveness for the period ending
[period end date].
[A/B, DME, or Specialty MAC name] recognizes the need to maintain an appropriate
internal control environment and report upon the effectiveness, as well as material
changes to its internal controls. On [date or approximate date material change happened],
[describe the control add/change/removal that was made. Two sentences is sufficient]. As
of [current date], I am not aware of any other material changes in our control
environment that would adversely affect the Auditor’s Opinion reached in the [report end
date (not the same as the report date)] report for the above named SSAE 18.
You should also be aware that [A/B, DME, or Specialty MAC name], as a normal part of
its operations, continually updates its services and technology as appropriate. In addition,
the controls for all of [A/B, DME, or Specialty MAC name] services were designed with
certain responsibilities required of the system users (See Complimentary User Entity
Control in the SSAE 18 report). [A/B, DME, or Specialty MAC name] controls must
always be evaluated in conjunction with an assessment of the strength of these user
controls.
Finally, in order to conclude upon the design and effectiveness of internal controls for
[A/B, DME, or Specialty MAC name], you must read the current SSAE 18 report. This
letter is not intended to be a substitute for the SSAE 18 report.
Sincerely,
[Name of Member of Management2]
[Title]
2 Should be a signature from one of the same person(s) that signed the letter of representations.
End Section 30.8 – Statement on Standards for Attestation Engagements (SSAE) Number
18, (SSAE 18) Reporting on Controls at Service Providers: Back to Table of Contents
History
(Rev. 11133, Issued:11-30-21, Effective: 10-01-21, Implementation: 12-31-21)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
d1a3c7b8d93bd266e5926edec01f2f32350110b7eca2347c8c028b03015198ad
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.