US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.02
Reporting Requirements
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Key Requirements
Business partners are required to provide documentation to CMS regarding the status of
their IT security program. Documentation shall be reported to CMS according to the
appropriate procedures, which are summarized in Table 3.1.
Meeting requirements does not validate the quality of a program. Managers with oversight
responsibility shall understand the processes and methodology behind the requirements. Table 3.1
identifies key requirements and their high-level descriptions. As appropriate, Table 3.1 refers to
other parts of this document that provide details on ways to accomplish each requirement.
In addition, Table 3.1 indicates how often these requirements need to be performed, the disposition
of output or documentation, comments, and a space to indicate completion or a “do by” date. The
number accompanying each entry in the requirement column indicates the section in this document
that deals with that particular requirement. Use this table as a checklist to ensure that all required IT
systems security tasks are completed on schedule. Consult the referenced sections for clarifying
details.
Table 3.1. Reporting Requirements Planning Table
Requirement Frequency Send To Comments
Complete
(check when
complete)
System Security
Profile – Section
3.7
As necessary • On file with the
Principal SSO
The System Security Profile
documents may be stored as paper
documents, electronic documents, or
any combination thereof.
CMS Annual
FISMA
Assessment (FA)
– Section 3.5.1
One third of the controls
shall be tested each year
so all controls are tested
during a 3-year period.
• COR with a copy
to CMS CO via
CFACTS
• System Security
Profile
FA results recorded in the CFACTS
are to be discussed in the
Certification Package for Internal
Controls (CPIC).
System Security
and Privacy Plan
(SSPP) – Section
3.1
The SSPP for each
General Support System
(GSS) and MA shall be
reviewed, updated, and
approved by management
every 365 days, or upon
significant change1F
2.
• CMS CO via
CFACTS
• System Security
Profile
Information system security and
privacy plans are to be generated via
CFACTS, reviewed, updated, and
approved by management and the
approved SSPP saved in CFACTS,
the CPIC and Statement of
Certification, and the System
Security Profile.
Information
Security Risk
Assessment –
Section 3.2
The information security
risk assessment for each
GSS and MA shall be
reviewed, updated, and
approved by management
every 365 days, or upon
significant change.1
• CMS CO via
CFACTS
• System Security
Profile
Information security risk assessments
are to be generated via CFACTS,
reviewed, updated, and approved by
management and saved in the
CFACTS, the CPIC and Statement of
Certification, and the System
Security Profile. The information
security risk assessment is submitted
with the system security and privacy
plan2F
3.
Certification
(CPIC) – Section
3.4
Each federal FY • COR with a copy
to CMS CO via
CFACTS
• System Security
Profile
Business Partners should include a
statement of certification as part of
their CPIC. Each year CMS will
publish in Chapter 7 (Internal
Controls) of its Financial
Management Manual (Pub 100-06)
information on certification
requirements including where, when,
and to whom these certifications shall
be submitted. All other contractors
should submit a statement of security
certification to their CMS CORs.
IT System
Contingency
Planning –
Section 3.3
CPs shall be reviewed,
updated, and approved by
management every
365 days, or upon
significant change.1
CPs shall be tested
annually.
• CMS CO via
CFACTS
• System Security
Profile
Business partner management and the
Business Owner shall approve the
CP.
The ITSCP is to be developed (in
accordance with Appendix A and
CMS RMH documents), reviewed,
updated, and approved by
management—and saved in
CFACTS, the Certification
Package/Statement of Certification,
and the System Security Profile3F
4.
2 NIST defines “significant change” as “any change that the responsible agency official believes is likely to affect the
confidentiality, integrity, or availability of the system, and thus, adversely impact agency operations (including mission,
functions, image or reputation) or agency assets.”
3 More information about Risk Assessment Reports can be found in the CMS risk assessment procedures.
4 More information about contingency planning can be found in the latest version of the NIST SP 800-12, An
Introduction to Computer Security: The NIST Handbook, and NIST SP 800- 34, Contingency Planning Guide for
Federal Information Systems.
Requirement Frequency Send To Comments
Complete
(check when
complete)
Plan of Action
and Milestones –
Section 3.5.2
Each federal FY • ISSO
• COR
• CMS CO via
CFACTS
• System Security
Profile
POA&Ms address findings of
internal/external audits/reviews
including annual security
assessments, and, as applicable:
Statements on Standards for
Attestation Engagements (SSAE) 18
reviews, A-123, Chief Financial
Officer (CFO) controls audits, the
Section 912 evaluation, delayed
weaknesses (configuration
management, vulnerability
management) and data center tests
and reviews.
Incident
Reporting and
Response –
Section 3.6
As necessary • COR
• CMS IT Service
desk
• Medicare
Contractor
Management
Group (MCMG)
Security Mailbox
(See the latest
guidance from
CMS for more
information)
• System Security
Profile
Health Insurance Portability and
Accountability Act (HIPAA), Health
Information Technology for
Economic and Clinical Health Act
(HITECH) and the Privacy Act of
1974 addresses Incident Reporting
information.
Authorization To
Operate –
Section 3.8
As necessary to acquire
and maintain a CMS CIO-
granted Authorization to
Operate.
On file with CMS
Information Security
and Privacy Group
(ISPG), with a copy
maintained in the
CFACTS.
TABLE 3.1 LEGEND:
CFACTS
CFO
CMS FISMA Controls Tracking System
Chief Financial Officer
CO Central Office (CMS)
COR Contract Officer Representative
ITSCP IT System Contingency Plan
CPIC Certification Package for Internal Controls
FA FISMA Assessment
FY Fiscal Year
GSS General Support System
HIPAA Health Insurance Portability and Accountability Act
IT Information Technology
MA Major Application
POA&M Plan of Action and Milestones
RA Risk Assessment
SSAE Statement on Standards for Attestation Engagements
SP Special Publication (NIST)
SSO Business Partner Systems Security Officer
When documentation cannot be submitted electronically, Registered Mail™ or its equivalent
(signed receipt required) shall be used. Contact the appropriate COR or ISSO for the correct
address.
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
904577fb5aa1db5bb4e9dffe829d4790172bbc0d6b68937b6c77fd814e2e3883
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.