US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.3
IT Systems Contingency Plan (ITSCP)
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Key Requirements
Business partners are required to document and test an ITSCP in accordance with the
most current versions of the CMS Information Security Contingency Planning standards
and procedures available within Appendix A of this document and on the CMS web site
at: https://security.cms.gov.
All business partners are required to develop and document an ITSCP that describes the
arrangements that have been implemented and the steps that shall be taken to continue IT and
system operations in the event of a natural or human-caused disaster. The ITSCP shall be included
in management planning and shall be:
• Reviewed as part of a documented System Development Life Cycle, whenever new systems
are planned or upon significant change
• Reviewed when new safeguards are implemented
• Reviewed and approved within 365 days to ensure accuracy
• Tested within 365 days. If backup facility testing is done by Medicare contract type (i.e.,
when multiple contract types are involved [e.g., Data Center, Part A/B, DME]), each
individual Medicare contract type shall be tested every 365 days.
Approved plans, test reports (results) and appropriate dates shall be maintained in the CFACTS and
placed in the contractor’s System Security Profile. Business partner management, the SSO, and the
CMS Business Owner shall approve newly developed and/or updated ITSCPs. A newly approved
IT Systems CP shall be updated in the CFACTS and submitted to CMS within 10 business days.
Appendix A to this manual provides information on ITSCP and testing methods. Also, see Table
3.1 for additional information.
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
de64364c89970066fb62f34c8b760e45c4d7eee99ffc6610f21a7fc2475c5e28
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.