JANUS Associates Cybersecurity Blog: Threat Reports & Industry Insights

ARC-AMPE Compliance After the Deadline: Five Actions to Strengthen Readiness

Written by Janus Associates | Sep 22, 2026, 5:49:45 PM

ARC-AMPE—the Acceptable Risk Controls for Affordable Care Act, Medicaid, and Partner Entities is the Centers for Medicare & Medicaid Services (CMS) framework for managing security and privacy risk across covered health-coverage eligibility and enrollment systems. It affects ACA Administering Entities and select partner entities, including specified Medicaid agencies, exchanges, Direct Enrollment entities, service providers, and other organizations whose role or agreements bring them within scope.

The March 4, 2026, compliance date for ARC-AMPE has passed. For organizations still remediating gaps (and for those already operating under the framework) the priority is now to maintain accurate documentation, demonstrate that controls work, address residual risk, and sustain readiness for CMS oversight and authorization activities.

For a fuller implementation roadmap, Download the ARC-AMPE Compliance Roadmap for practical checklists, System Security and Privacy Plan guidance, implementation priorities, and next steps.

Why does action still matter?

CMS released ARC-AMPE on March 4, 2025, with an effective date of March 4, 2025, and a compliance date of March 4, 2026. ARC-AMPE superseded and replaced the Minimum Acceptable Risk Standards for Exchanges (MARS-E) and the Non-Exchange Entity Governance, Risk Management, and Compliance framework upon publication.

That transition was more than a document conversion. CMS uses submitted security and privacy artifacts to support risk-informed decisions about an entity’s Authority to Connect or Request to Connect to the CMS Federal Data Services Hub. Following authorization, applicable users must maintain Volume II controls, begin information security and privacy continuous monitoring, and submit evidence according to their entity-specific CMS guidance.

Organizations should confirm obligations through the current CMS ARC-AMPE materials, applicable business or legal agreements, and current user-type guidance rather than relying on a generalized date.

What does ARC-AMPE change?

ARC-AMPE consolidates security and privacy expectations around a NIST-aligned, risk-based structure. Volume I explains scope, governance, mandatory and informative use, authorization, reporting, and continuous monitoring. For ACA Administering Entities, the current official Volume II workbook is an Excel-based System Security and Privacy Plan (SSPP) containing 402 baseline controls and control enhancements across 20 families.

The workbook is based on NIST Special Publication 800-53 Revision 5, whose catalog integrates security and privacy controls and includes dedicated families for Personally Identifiable Information Processing and Transparency and Supply Chain Risk Management. The SSPP requires more than a statement that a control exists: implementation descriptions must identify status, responsible parties, how the control satisfies requirements, review frequency, and supporting details. CMS also states that supplemental control requirements and guidance in the workbook are required for compliance, not optional.

This structure reflects the NIST Risk Management Framework lifecycle: prepare, categorize, select, implement, assess, authorize, and monitor. The practical result is an emphasis on traceable ownership, defensible evidence, privacy integration, third-party accountability, and continuous monitoring—not a one-time compliance audit.

Where may gaps remain?

An organization may have mature MARS-E policies yet still need to reconcile them with the current ARC-AMPE baseline. Common review areas include incomplete control mapping, outdated system boundaries, unclear shared-control ownership, weak implementation narratives, unsupported “implemented” statuses, and evidence dispersed across security, privacy, procurement, operations, and vendors.

Third-party environments deserve particular attention. The Volume II assumptions recognize that cloud and outsourced systems can divide implementation responsibility among several parties, while the SSPP instructions require entities to identify who implements each part of a control. Privacy obligations also require careful scoping: ARC-AMPE can include controls that facilitate HIPAA adherence, but CMS states that ARC-AMPE is not HIPAA guidance and organizations should use counsel to determine HIPAA applicability. HHS separately describes HIPAA risk analysis as an ongoing process for regulated entities, not a one-time assessment.

Five practical actions

Confirm scope and applicability

Inventory systems, applications, interfaces, data flows, cloud services, contractors, and downstream providers that connect to the CMS Hub or access PII contained in or derived from Exchange repositories. Confirm whether Volume II is mandatory through regulation, CMS designation, or contract; other ARC-AMPE users may use it as an informative reference.

Map the current baseline

Map existing MARS-E, NEE GRC, HIPAA, enterprise, and inherited controls to the official Volume II workbook. Record full, partial, inherited, compensated, planned, and not-applicable statuses accurately. A control should not be marked complete merely because a policy or technology exists; the implementation description should address every applicable requirement and participating owner.

Prioritize risk-based remediation

Rank gaps by data sensitivity, mission impact, exploitability, control dependencies, authorization implications, and CMS expectations. Assign accountable owners, milestones, resources, and evidence requirements. Track planned controls and unresolved weaknesses through a current Plan of Actions and Milestones rather than allowing them to remain in informal project lists.

Strengthen the SSPP and evidence

Write implementation narratives that explain what operates, where it operates, who owns it, how often it is reviewed, and how effectiveness is demonstrated. Create a controlled evidence repository that maps policies, diagrams, configurations, access reviews, logs, training records, assessments, scan results, incident-response exercises, vendor documentation, and approvals to specific controls. The JANUS eBook expands this step with practical SSPP prompts and evidence-management recommendations.

Validate and monitor controls

Use qualified, appropriately independent reviewers to test whether controls are implemented correctly, operate as intended, and produce the required outcome, the assessment objective described by NIST. Align vulnerability management, penetration testing, access reviews, configuration checks, incident response testing, risk updates, and evidence refresh cycles with the official workbook and the entity’s current CMS continuous-monitoring guide.

How JANUS supports readiness

JANUS Associates provides independent cybersecurity, compliance, privacy, and risk management guidance without tying recommendations to a preferred product platform. Engagements can begin with an ARC-AMPE readiness assessment and MARS-E-to-ARC-AMPE mapping, then progress to a transparent remediation roadmap with priorities, owners, dependencies, and measurable completion criteria.

JANUS can also support SSPP development and quality review, governance design, privacy and third-party risk integration, control-to-evidence mapping, and repository organization. Where relevant to the control environment and assessment scope, JANUS can perform vulnerability assessments, configuration reviews, and penetration testing, then help teams translate findings into risk-based remediation and defensible evidence.

Independent validation adds value when it tests both documentation and operation. JANUS can review whether control narratives match the environment, assess whether artifacts support the stated implementation, identify inconsistencies across shared owners, and help establish a sustainable continuous-monitoring cadence. The objective is not a promise of guaranteed compliance or authorization; it is clearer risk ownership, stronger evidence, better CMS audit readiness, and a more resilient security and privacy program.

Download the ARC-AMPE Compliance Roadmap for practical checklists, SSPP guidance, implementation priorities, and next steps for ACA, Medicaid, and partner entities.

If your organization is assessing unresolved ARC-AMPE gaps, updating its SSPP, or strengthening continuous monitoring, talk with JANUS about an independent readiness review.

Frequentlyently Asked Questions (FAQs)

What is ARC-AMPE?

ARC-AMPE is the CMS security and privacy risk-management framework for systems supporting health-coverage eligibility and enrollment. It replaced MARS-E and the NEE GRC Framework and incorporates updated federal requirements and NIST guidance. Volume I explains the framework; Volume II supplies the SSPP template and required baseline controls for mandatory users.

Who must comply with ARC-AMPE Volume II?

CMS requires ACA Administering Entities and select Partner Entities identified in Volume I to comply with Volume II. Listed mandatory users include state Medicaid and CHIP agencies, state-based exchanges, specified Direct Enrollment and Enhanced Direct Enrollment entities, and certain service providers. Contractual terms can also impose Volume II obligations, so each organization should confirm its own scope.

What should an organization do after the deadline?

Confirm scope, assess the current Volume II baseline, document unresolved gaps, assign remediation owners, and update the SSPP with accurate implementation details. Evidence should be mapped to controls and maintained under a continuous-monitoring process. Organizations should also verify entity-specific submission and authorization requirements in current CMS materials rather than relying on old MARS-E schedules.

What evidence does an ARC-AMPE assessment require?

The exact package depends on entity type and CMS guidance. Volume I’s non-exhaustive artifact list includes the SSPP, Information System Risk Assessment, penetration-test results, vulnerability scans, Plan of Actions and Milestones, Privacy Impact Assessment, Security Assessment Plan and Report, Security Impact Assessment, and applicable connection or data-sharing agreements.