Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 1.1

Additional Requirements for MACs

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

MACs are responsible for fulfilling all existing business partner requirements. Additional

requirements include the following:

• The contractor shall comply with the CMS MAC tailored list of controls found in

Attachment 1. This list of controls, known as the MAC ARS, includes all of the CMS

required controls plus optional controls are included specifically for the MACs. MAC ARS

controls will be tailored via the BPSSM as what is included in the BPSSM overrides the

MAC ARS controls with the intent of being more restrictive.

• The contractor shall correct weaknesses, findings, gaps, or other deficiencies within 90 days

of receipt of any final audit or evaluation report regardless of finding severity, unless

otherwise authorized by CMS. If additional time is required, follow the process specified

within section 3.5.2.

• The 90-day finding resolution requirement does not include findings identified by the

Cyber Risk Management (CRM) program at CMS (e.g., Known Exploitable

Vulnerabilities (KEVs), Common Vulnerabilities and Exposures (CVEs), etc.). These

types of findings relate to patch management and shall follow the requirements set

forth in the BPSSM, Section 3.10 - Patch Management.

• The contractor shall document system security controls in the CMS FISMA Controls

Tracking System (CFACTS) tool to demonstrate compliance with MAC ARS controls and

documentation. The contractor shall also use CFACTS to maintain documentation that

supports the Authority to Operate (ATO) process, including certification of the

documentation.

• The contractor shall conduct or undergo an independent security control assessment of its

system security program in accordance with Section 912 of the MMA. The first test shall be

completed before the contractor commences claims payment under the contract.

• The contractor shall appoint a Chief Information Officer (CIO) to oversee its compliance

with the CMS information security requirements. The contractor’s principal Systems

Security Officer (SSO) shall be a full-time position dedicated to assisting the business

partner CIO in fulfilling these requirements.

• The contractor must implement systems in a manner that is compliant with the CMS Target

Lifecycle (TLC) and the Technical Reference Architecture (TRA). When directed by CMS,

compliance with the TLC and the TRA will be demonstrated by presenting system updates

to the CMS Technical Review Board (TRB). For situations where the TRA conflicts with

the MAC ARS, the MAC ARS shall take precedence.

• The contractor shall meet all contingency planning and disaster recovery requirements

included in the MAC ARS and the Business Partners Systems Security Manual (BPSSM),

with the goal of restoring key claims processing and operations within 72 hours.

• The contractor shall review, update and approve all policies and procedures every 365 days

and not every three years as stated in the MAC ARS.

• The contractor shall review system accounts (as defined in ARS control AC-02), at least

once every ninety (90) days. Any other accounts shall be reviewed at least annually.

2 – Information Technology (IT) Systems Security Roles and

Responsibilities

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
5e3c7d891c137f6faf932675b21528d08dec7ff651114b8bd1a9c03d6823672c
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.