US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.4
Certification Package for Internal Controls (CPIC)
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
All business partners are required to certify their system security compliance. Certification is the
formal process by which a contractor official verifies, initially and then by annual reassessments,
that a system’s security features meet the MAC ARS controls. Business partners shall self-certify
that their organization successfully completed an annual, independent FA of their Medicare IT
systems and associated software in accordance with the terms of their Medicare agreement/contract.
Each contractor is required to self-certify to CMS its information security compliance within each
federal Fiscal Year (FY). This security certification shall be included in the CPIC or, for contracts
not required to submit CPICs, send the security certification to their appropriate CMS CORs. CMS
shall continue to require annual, formal re-certifications within each FY no later than September 30,
including validation at all levels of security as described in this manual.
System security certification shall be fully documented and maintained in the System Security
Profile. The security certification validates that the following items have been developed (i.e.,
updated and/or reviewed, as required) and are available for review in the System Security Profile:
• Certification
• FISMA Annual Security Control Assessment
• System Security and Privacy Plan for each GSS and MA (see section 3.1)
• Information Security Risk Assessment (see section 3.2)
• IT Systems Contingency Plan (see section 3.3 and Appendix A)
• Plan of Action and Milestones (see section 3.5.2)
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
1a6069ec9f9b68109f2bdc5710892178c308488cc148dac08f9d994f9a1273e1
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.