Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 3.8

Authorization To Operate

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Business partners are required to acquire and maintain a CMS issued Authorization to Operate

(ATO) for each FISMA system. To maintain an ATO, the business partner is expected to maintain

all security documentation in CFACTS, and the documentation must be up to date as defined in

BPSSM table 3.1. When applying for an ATO, critical and high risk POA&Ms must be in either a

pending verification status or mitigated so the risk can be demonstrated to be moderate or low.

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
f551009856c9f7d232a83d78e5290db50dbf5116d2a71039658bac7c0acb1e7e
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.