Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 3.3

IT Systems Contingency Plan (ITSCP)

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Key Requirements

Business partners are required to document and test an ITSCP in accordance with the

most current versions of the CMS Information Security Contingency Planning standards

and procedures available within Appendix A of this document and on the CMS web site

at: https://security.cms.gov.

All business partners are required to develop and document an ITSCP that describes the

arrangements that have been implemented and the steps that shall be taken to continue IT and

system operations in the event of a natural or human-caused disaster. The ITSCP shall be included

in management planning and shall be:

• Reviewed as part of a documented System Development Life Cycle, whenever new systems

are planned or upon significant change

• Reviewed when new safeguards are implemented

• Reviewed and approved within 365 days to ensure accuracy

• Tested within 365 days. If backup facility testing is done by Medicare contract type (i.e.,

when multiple contract types are involved [e.g., Data Center, Part A/B, DME]), each

individual Medicare contract type shall be tested every 365 days.

Approved plans, test reports (results) and appropriate dates shall be maintained in the CFACTS and

placed in the contractor’s System Security Profile. Business partner management, the SSO, and the

CMS Business Owner shall approve newly developed and/or updated ITSCPs. A newly approved

IT Systems CP shall be updated in the CFACTS and submitted to CMS within 10 business days.

Appendix A to this manual provides information on ITSCP and testing methods. Also, see Table

3.1 for additional information.

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
de64364c89970066fb62f34c8b760e45c4d7eee99ffc6610f21a7fc2475c5e28
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.