Framework Healthcare & Human Services
MARS-E
The Minimum Acceptable Risk Standards for Exchanges was the CMS security and privacy control framework for organizations that administer Affordable Care Act coverage programs and connect to the federal data services hub: state-based marketplaces, state Medicaid and CHIP agencies, Basic Health Program agencies, and their contractors.
It was built on NIST SP 800-53 Revision 4 with IRS Publication 1075 overlays for federal tax information. Version 2.0 was issued in November 2015 and version 2.2 in August 2021. CMS retired MARS-E on March 4, 2026 when ARC-AMPE became the required framework for Administering Entities.
MARS-E is kept here because many state contracts, procurement documents, and older authorization packages still cite it.
Under MARS-E an entity needed a System Security Plan, an information security risk assessment, a privacy impact assessment, incident response and contingency plans, interconnection security agreements, and an independent security control assessment feeding an authority to connect from CMS.
Those artifacts carry forward into ARC-AMPE, but the control catalog and the SSPP format changed, so organizations should not assume a MARS-E package remains sufficient.
help
Who has to comply
Historically, all ACA Administering Entities (state marketplaces, Medicaid and CHIP agencies, Basic Health Program agencies) and their contractors and subcontractors with access to marketplace or hub data. These entities now fall under ARC-AMPE.
What the assessor asks to see
Under MARS-E an assessor asked for the system boundary and data flow diagrams, the System Security Plan, the risk assessment and privacy impact assessment, control policies and procedures, access and audit log evidence, vulnerability scanning results, configuration management records, incident response and contingency plan test results, interconnection security agreements, and the plan of action and milestones.
Status
Superseded. ARC-AMPE v1.0 was published March 4, 2025 with a one-year transition, and MARS-E v2.2 ceased to be an accepted option on March 4, 2026. See the ARC-AMPE profile for current requirements.
Assessors
Who assesses MARS-E
Independent third-party security control assessors engaged by the entity, with CMS reviewing the package and issuing the authority to connect. No certification body. CMS defined assessor independence expectations.
No firm has claimed a MARS-E assessor listing yet. Claim yours →
Consultants
Who helps with MARS-E
The same security assessment and state health IT consulting firms that now serve ARC-AMPE; most have converted their MARS-E practices to the new framework and offer transition gap analyses.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a MARS-E consultant listing yet. Claim yours →
Software
Tools for MARS-E
Tools that name this framework in their own material.
No firm has claimed a MARS-E tool listing yet. Claim yours →
Related reading
- MARS-E to ARC-AMPE: a guide for state Medicaid agenciesWalks through what actually changed in the control catalogue and the system security plan format, written for the agencies that have to make the move.Amazon Web Services
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for MARS-E
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with MARS-E
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.