US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.13
Cloud Computing
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
According to NIST, cloud computing is a model for enabling ubiquitous, convenient, on-demand
network access to a shared pool of configurable computing resources (e.g., networks, servers,
storage, applications, and services) that can be rapidly provisioned and released with minimal
management effort or service provider interaction. (NIST SP 800-45). FEDRAMP has implemented
security requirements for low, moderate and high risk rank systems. MACs and other business
partners that are rated as high can use CSPs with the approval of the CMS COR and concurrence of
the CMS ISSO. MACs are expected to document control implementations and confirm compliance
of CSP controls within their SSPP. If the CSP supplied controls and services are less strict than the
MAC ARS requirements, then the business partner is expected to supplement the CSP controls or
implement separate controls that meet the MAC ARS. Also, other requirements that are not
specifically documented in the MAC ARS or in an RMH document, such as the reporting of
configuration settings are not waived with the use of a CSP; therefore, this should be carefully
considered before requesting to use a CSP.
When utilizing a CSP, MACs must perform the following actions:
1. Maintain a responsibility line matrix that defines MAC control responsibility and the CSP
control responsibility. Controls that are MAC responsibility shall be documented within the
SSPP, noting the related CSP that the control text is documented for.
2. Perform periodic review of CSP risk management program to verify that the CSP is
complying with security requirements. This review should be performed at least annually.
Identified risks should be documented within the contractor risk assessment.
3. Monitor and track risks identified from the cloud service provider. Identified risks should be
documented within the contractor risk assessment.
4. Patching of vulnerabilities should be addressed in accordance with CMS defined patching
timelines as noted in section 3.10.
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
515fe5395fb52f48c5c519c7cdd9cae1c94d9625dc1153cb501a8d472474c5ef
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.