Framework Healthcare & Human Services
CMS EDE
Enhanced Direct Enrollment is the CMS pathway that lets approved web brokers, insurers, and technology platforms host the entire federal marketplace application and enrollment experience on their own websites, exchanging data with the Federally Facilitated Exchange through CMS APIs.
Because these entities handle applicant tax and eligibility data, CMS requires each primary EDE entity to pass an independent third-party audit before approval and to repeat it every year. The audit has two parts: a Business Requirements Audit and a Privacy and Security Audit.
In writing, an EDE entity needs a System Security and Privacy Plan (now in the ARC-AMPE Direct Enrollment Entity format), a risk assessment, incident response and contingency plans, privacy notices and consent language, agent and broker oversight procedures, documented business processes mapped to CMS requirements, and the annual audit reports with remediation plans.
Downstream entities that use a primary entity's platform inherit most controls but still sign CMS agreements.
help
Who has to comply
Primary EDE entities (web brokers, issuers, and platforms) that build and operate an EDE environment, and downstream EDE entities that use them. Participation is voluntary; the audits are a condition of approval.
What the assessor asks to see
Auditors ask for the SSPP and system boundary, the risk assessment and privacy impact assessment, security policies and procedures, access control and logging evidence, vulnerability scans and penetration tests, the incident response plan and records, the business process documentation and screen flows, test case results against CMS requirements, agent and broker oversight records, consumer consent and notice language, and remediation evidence for prior findings.
Framework transition
The security control set for EDE entities moved from the EDE-specific NIST 800-53 Revision 4 baseline to ARC-AMPE for Direct Enrollment Entities, with a compliance target around the end of June 2026 (verify against the current CMS EDE guidelines).
Assessors
Who assesses CMS EDE
Independent, objective third-party auditors selected by the entity that meet the qualification and independence requirements in the CMS guidelines and 45 CFR 155.221 (experience with NIST standards and HIPAA for the privacy and security audit; no system access for the business audit). CMS reviews and approves the audit results.
CMS sets auditor requirements in the annual guidelines rather than accrediting firms.
No firm has claimed a CMS EDE assessor listing yet. Claim yours →
Consultants
Who helps with CMS EDE
A niche market of marketplace technology consultants, security assessment firms, and platform providers that offer EDE-as-a-service. Engagements run through the annual cycle: build or update, readiness review, audit, submission, remediation.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a CMS EDE consultant listing yet. Claim yours →
Software
Tools for CMS EDE
Tools that name this framework in their own material.
No firm has claimed a CMS EDE tool listing yet. Claim yours →
Related reading
- "Direct Enrollment" in Marketplace Coverage Lacks Protections for ConsumersExplains how the EDE pathway works end to end and which marketplace safeguards a consumer loses when a private site hosts the application.Center on Budget and Policy Priorities
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for CMS EDE
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with CMS EDE
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.