Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 3.02

Reporting Requirements

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Key Requirements

Business partners are required to provide documentation to CMS regarding the status of

their IT security program. Documentation shall be reported to CMS according to the

appropriate procedures, which are summarized in Table 3.1.

Meeting requirements does not validate the quality of a program. Managers with oversight

responsibility shall understand the processes and methodology behind the requirements. Table 3.1

identifies key requirements and their high-level descriptions. As appropriate, Table 3.1 refers to

other parts of this document that provide details on ways to accomplish each requirement.

In addition, Table 3.1 indicates how often these requirements need to be performed, the disposition

of output or documentation, comments, and a space to indicate completion or a “do by” date. The

number accompanying each entry in the requirement column indicates the section in this document

that deals with that particular requirement. Use this table as a checklist to ensure that all required IT

systems security tasks are completed on schedule. Consult the referenced sections for clarifying

details.

Table 3.1. Reporting Requirements Planning Table

Requirement Frequency Send To Comments

Complete

(check when

complete)

System Security

Profile – Section

3.7

As necessary • On file with the

Principal SSO

The System Security Profile

documents may be stored as paper

documents, electronic documents, or

any combination thereof.

CMS Annual

FISMA

Assessment (FA)

– Section 3.5.1

One third of the controls

shall be tested each year

so all controls are tested

during a 3-year period.

• COR with a copy

to CMS CO via

CFACTS

• System Security

Profile

FA results recorded in the CFACTS

are to be discussed in the

Certification Package for Internal

Controls (CPIC).

System Security

and Privacy Plan

(SSPP) – Section

3.1

The SSPP for each

General Support System

(GSS) and MA shall be

reviewed, updated, and

approved by management

every 365 days, or upon

significant change1F

2.

• CMS CO via

CFACTS

• System Security

Profile

Information system security and

privacy plans are to be generated via

CFACTS, reviewed, updated, and

approved by management and the

approved SSPP saved in CFACTS,

the CPIC and Statement of

Certification, and the System

Security Profile.

Information

Security Risk

Assessment –

Section 3.2

The information security

risk assessment for each

GSS and MA shall be

reviewed, updated, and

approved by management

every 365 days, or upon

significant change.1

• CMS CO via

CFACTS

• System Security

Profile

Information security risk assessments

are to be generated via CFACTS,

reviewed, updated, and approved by

management and saved in the

CFACTS, the CPIC and Statement of

Certification, and the System

Security Profile. The information

security risk assessment is submitted

with the system security and privacy

plan2F

3.

Certification

(CPIC) – Section

3.4

Each federal FY • COR with a copy

to CMS CO via

CFACTS

• System Security

Profile

Business Partners should include a

statement of certification as part of

their CPIC. Each year CMS will

publish in Chapter 7 (Internal

Controls) of its Financial

Management Manual (Pub 100-06)

information on certification

requirements including where, when,

and to whom these certifications shall

be submitted. All other contractors

should submit a statement of security

certification to their CMS CORs.

IT System

Contingency

Planning –

Section 3.3

CPs shall be reviewed,

updated, and approved by

management every

365 days, or upon

significant change.1

CPs shall be tested

annually.

• CMS CO via

CFACTS

• System Security

Profile

Business partner management and the

Business Owner shall approve the

CP.

The ITSCP is to be developed (in

accordance with Appendix A and

CMS RMH documents), reviewed,

updated, and approved by

management—and saved in

CFACTS, the Certification

Package/Statement of Certification,

and the System Security Profile3F

4.

2 NIST defines “significant change” as “any change that the responsible agency official believes is likely to affect the

confidentiality, integrity, or availability of the system, and thus, adversely impact agency operations (including mission,

functions, image or reputation) or agency assets.”

3 More information about Risk Assessment Reports can be found in the CMS risk assessment procedures.

4 More information about contingency planning can be found in the latest version of the NIST SP 800-12, An

Introduction to Computer Security: The NIST Handbook, and NIST SP 800- 34, Contingency Planning Guide for

Federal Information Systems.

Requirement Frequency Send To Comments

Complete

(check when

complete)

Plan of Action

and Milestones –

Section 3.5.2

Each federal FY • ISSO

• COR

• CMS CO via

CFACTS

• System Security

Profile

POA&Ms address findings of

internal/external audits/reviews

including annual security

assessments, and, as applicable:

Statements on Standards for

Attestation Engagements (SSAE) 18

reviews, A-123, Chief Financial

Officer (CFO) controls audits, the

Section 912 evaluation, delayed

weaknesses (configuration

management, vulnerability

management) and data center tests

and reviews.

Incident

Reporting and

Response –

Section 3.6

As necessary • COR

• CMS IT Service

desk

• Medicare

Contractor

Management

Group (MCMG)

Security Mailbox

(See the latest

guidance from

CMS for more

information)

• System Security

Profile

Health Insurance Portability and

Accountability Act (HIPAA), Health

Information Technology for

Economic and Clinical Health Act

(HITECH) and the Privacy Act of

1974 addresses Incident Reporting

information.

Authorization To

Operate –

Section 3.8

As necessary to acquire

and maintain a CMS CIO-

granted Authorization to

Operate.

On file with CMS

Information Security

and Privacy Group

(ISPG), with a copy

maintained in the

CFACTS.

TABLE 3.1 LEGEND:

CFACTS

CFO

CMS FISMA Controls Tracking System

Chief Financial Officer

CO Central Office (CMS)

COR Contract Officer Representative

ITSCP IT System Contingency Plan

CPIC Certification Package for Internal Controls

FA FISMA Assessment

FY Fiscal Year

GSS General Support System

HIPAA Health Insurance Portability and Accountability Act

IT Information Technology

MA Major Application

POA&M Plan of Action and Milestones

RA Risk Assessment

SSAE Statement on Standards for Attestation Engagements

SP Special Publication (NIST)

SSO Business Partner Systems Security Officer

When documentation cannot be submitted electronically, Registered Mail™ or its equivalent

(signed receipt required) shall be used. Contact the appropriate COR or ISSO for the correct

address.

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
904577fb5aa1db5bb4e9dffe829d4790172bbc0d6b68937b6c77fd814e2e3883
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.