US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.7
System Security Profile
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Key Requirements
The System Security Profile is a copy of the documents that are maintained in the
CFACTS and submitted to CMS as requested. These documents shall be available if
business partner management requires timely access to them without the CFACTS.
Consolidate security documentation (paper documents, electronic documents, or a combination)
into a System Security Profile that includes the following items:
• Completed FAs
• SSPP
• ISRA
• Certifications
• ITSCP
• POA&Ms for each compliance security review
• POA&Ms for other security review undertaken by Department of Health and Human
Services (DHHS) OIG, CMS, Internal Revenue Service (IRS), GAO, consultants,
subcontractors, and business partner security staff
• Incident reporting and responses
• Systems information security policies and procedures
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
57f9cb4496d444eda3709091255d3c75bb6132425aa444a921566d2085702481
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.