US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.8
Authorization To Operate
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Business partners are required to acquire and maintain a CMS issued Authorization to Operate
(ATO) for each FISMA system. To maintain an ATO, the business partner is expected to maintain
all security documentation in CFACTS, and the documentation must be up to date as defined in
BPSSM table 3.1. When applying for an ATO, critical and high risk POA&Ms must be in either a
pending verification status or mitigated so the risk can be demonstrated to be moderate or low.
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
f551009856c9f7d232a83d78e5290db50dbf5116d2a71039658bac7c0acb1e7e
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.