Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 3.13

Cloud Computing

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

According to NIST, cloud computing is a model for enabling ubiquitous, convenient, on-demand

network access to a shared pool of configurable computing resources (e.g., networks, servers,

storage, applications, and services) that can be rapidly provisioned and released with minimal

management effort or service provider interaction. (NIST SP 800-45). FEDRAMP has implemented

security requirements for low, moderate and high risk rank systems. MACs and other business

partners that are rated as high can use CSPs with the approval of the CMS COR and concurrence of

the CMS ISSO. MACs are expected to document control implementations and confirm compliance

of CSP controls within their SSPP. If the CSP supplied controls and services are less strict than the

MAC ARS requirements, then the business partner is expected to supplement the CSP controls or

implement separate controls that meet the MAC ARS. Also, other requirements that are not

specifically documented in the MAC ARS or in an RMH document, such as the reporting of

configuration settings are not waived with the use of a CSP; therefore, this should be carefully

considered before requesting to use a CSP.

When utilizing a CSP, MACs must perform the following actions:

1. Maintain a responsibility line matrix that defines MAC control responsibility and the CSP

control responsibility. Controls that are MAC responsibility shall be documented within the

SSPP, noting the related CSP that the control text is documented for.

2. Perform periodic review of CSP risk management program to verify that the CSP is

complying with security requirements. This review should be performed at least annually.

Identified risks should be documented within the contractor risk assessment.

3. Monitor and track risks identified from the cloud service provider. Identified risks should be

documented within the contractor risk assessment.

4. Patching of vulnerabilities should be addressed in accordance with CMS defined patching

timelines as noted in section 3.10.

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
515fe5395fb52f48c5c519c7cdd9cae1c94d9625dc1153cb501a8d472474c5ef
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.