Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 3.4

Certification Package for Internal Controls (CPIC)

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

All business partners are required to certify their system security compliance. Certification is the

formal process by which a contractor official verifies, initially and then by annual reassessments,

that a system’s security features meet the MAC ARS controls. Business partners shall self-certify

that their organization successfully completed an annual, independent FA of their Medicare IT

systems and associated software in accordance with the terms of their Medicare agreement/contract.

Each contractor is required to self-certify to CMS its information security compliance within each

federal Fiscal Year (FY). This security certification shall be included in the CPIC or, for contracts

not required to submit CPICs, send the security certification to their appropriate CMS CORs. CMS

shall continue to require annual, formal re-certifications within each FY no later than September 30,

including validation at all levels of security as described in this manual.

System security certification shall be fully documented and maintained in the System Security

Profile. The security certification validates that the following items have been developed (i.e.,

updated and/or reviewed, as required) and are available for review in the System Security Profile:

• Certification

• FISMA Annual Security Control Assessment

• System Security and Privacy Plan for each GSS and MA (see section 3.1)

• Information Security Risk Assessment (see section 3.2)

• IT Systems Contingency Plan (see section 3.3 and Appendix A)

• Plan of Action and Milestones (see section 3.5.2)

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
1a6069ec9f9b68109f2bdc5710892178c308488cc148dac08f9d994f9a1273e1
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.
CMS Pub. 100-17, ch. 117_systems_security, § 3.4 · binding.law