Framework Healthcare & Human Services
CMS ARS
The CMS Acceptable Risk Safeguards is the control catalog that CMS applies to its own information systems and to every contractor and subcontractor system that processes CMS data. It is CMS's tailoring of NIST SP 800-53 for the agency's risk environment and is issued under the CMS Information Systems Security and Privacy Policy.
ARS is the baseline behind the CMS authorization to operate process for Medicare Administrative Contractors, data centers, and other CMS business partners.
In writing, a system owner or contractor needs a System Security and Privacy Plan that records how each applicable ARS control is implemented, an information security risk assessment, contingency and incident response plans, configuration management documentation, a privacy impact assessment where personal data is involved, and the policies and procedures each control family requires.
Each control carries its own review and assessment frequency, from monthly to annual.
help
Who has to comply
CMS employees, contractors, and subcontractors and their facilities that support CMS business missions, including Medicare Administrative Contractors, enterprise data centers, and application development contractors. Applicability is contractual and through the CMS authorization process.
What the assessor asks to see
Assessors ask for the system boundary and categorization, the SSPP with control implementation statements, the risk assessment, policies and procedures per control family, access and account management evidence, audit logging and monitoring records, vulnerability scans and remediation, configuration baselines and change records, contingency plan tests, incident response records, training records, and the plan of action and milestones.
Version note
The CMS security site lists ARS 5.2 as released July 1, 2026, adding zero trust implementation expectations and dedicated federal tax information and high value asset overlay fields, and notes that ARS 5.1 applicability decisions do not automatically carry forward. Verify the current version and any transition deadline on security.cms.gov.
Assessors
Who assesses CMS ARS
Security control assessors approved or contracted by CMS perform assessments; the CMS authorizing official grants the authorization to operate. Third-party assessments and continuous monitoring evaluate controls at the frequencies ARS specifies. Accredited by CMS CISO and authorizing officials.
No external accreditation body.
No firm has claimed a CMS ARS assessor listing yet. Claim yours →
Consultants
Who helps with CMS ARS
Federal health IT security consultancies and assessment firms that specialize in CMS authorization packages. Engagements typically cover SSPP authoring, control implementation, pre-assessment readiness, and continuous monitoring support.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a CMS ARS consultant listing yet. Claim yours →
Software
Tools for CMS ARS
Tools that name this framework in their own material.
No firm has claimed a CMS ARS tool listing yet. Claim yours →
Need a hand implementing it?
Find a Consultant for CMS ARS
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with CMS ARS
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.