HomeFrameworksHealthcare & Human ServicesMARS-E

Framework  Healthcare & Human Services

MARS-E

Retired
This standard has been retired as of 4 March 2026. Use ARC-AMPE instead. Administering Entities had to meet ARC-AMPE from that date; Direct Enrollment Entities by the end of June 2026. This page is kept for reference because assessments and authorities to connect issued under MARS-E remain on file.

The Minimum Acceptable Risk Standards for Exchanges was the CMS security and privacy control framework for organizations that administer Affordable Care Act coverage programs and connect to the federal data services hub: state-based marketplaces, state Medicaid and CHIP agencies, Basic Health Program agencies, and their contractors.

It was built on NIST SP 800-53 Revision 4 with IRS Publication 1075 overlays for federal tax information. Version 2.0 was issued in November 2015 and version 2.2 in August 2021. CMS retired MARS-E on March 4, 2026 when ARC-AMPE became the required framework for Administering Entities.

MARS-E is kept here because many state contracts, procurement documents, and older authorization packages still cite it.

Under MARS-E an entity needed a System Security Plan, an information security risk assessment, a privacy impact assessment, incident response and contingency plans, interconnection security agreements, and an independent security control assessment feeding an authority to connect from CMS.

Those artifacts carry forward into ARC-AMPE, but the control catalog and the SSPP format changed, so organizations should not assume a MARS-E package remains sufficient.

AI-compiled
Share
Sponsored
MARS-E
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with MARS-E
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Historically, all ACA Administering Entities (state marketplaces, Medicaid and CHIP agencies, Basic Health Program agencies) and their contractors and subcontractors with access to marketplace or hub data. These entities now fall under ARC-AMPE.

What the assessor asks to see

Under MARS-E an assessor asked for the system boundary and data flow diagrams, the System Security Plan, the risk assessment and privacy impact assessment, control policies and procedures, access and audit log evidence, vulnerability scanning results, configuration management records, incident response and contingency plan test results, interconnection security agreements, and the plan of action and milestones.

Status

Superseded. ARC-AMPE v1.0 was published March 4, 2025 with a one-year transition, and MARS-E v2.2 ceased to be an accepted option on March 4, 2026. See the ARC-AMPE profile for current requirements.

Assessors

Who assesses MARS-E

Independent third-party security control assessors engaged by the entity, with CMS reviewing the package and issuing the authority to connect. No certification body. CMS defined assessor independence expectations.

No firm has claimed a MARS-E assessor listing yet. Claim yours →

Consultants

Who helps with MARS-E

The same security assessment and state health IT consulting firms that now serve ARC-AMPE; most have converted their MARS-E practices to the new framework and offer transition gap analyses.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a MARS-E consultant listing yet. Claim yours →

Software

Tools for MARS-E

Tools that name this framework in their own material.

No firm has claimed a MARS-E tool listing yet. Claim yours →

Related reading

  1. MARS-E to ARC-AMPE: a guide for state Medicaid agenciesWalks through what actually changed in the control catalogue and the system security plan format, written for the agencies that have to make the move.Amazon Web Services

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for MARS-E

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with MARS-E

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.