ARC-AMPE Audit & Compliance Assessment Services

Table of Contents

Lazarus Alliance provides independent ARC-AMPE audit, assessment, readiness, gap analysis and compliance services for ACA, Medicaid and CMS partner entities.

Independent ARC-AMPE Security & Privacy Assessments for ACA, Medicaid and Partner Entities

Organizations that exchange sensitive information with the Centers for Medicare & Medicaid Services (CMS) face rigorous cybersecurity, privacy, risk management and continuous monitoring requirements.

Lazarus Alliance provides independent ARC-AMPE audit, assessment, readiness and compliance services to help organizations evaluate their security and privacy controls, identify compliance gaps, prepare required evidence and demonstrate a defensible security and privacy posture.

ARC-AMPE became effective March 4, 2025, with a CMS compliance date of March 4, 2026. ARC-AMPE supersedes the legacy MARS-E framework for applicable organizations.

ARC-AMPE — Acceptable Risk Controls for Affordable Care Act (ACA), Medicaid, and Partner Entities — is the CMS security and privacy framework that succeeds the legacy MARS-E framework.

Organizations that previously maintained MARS-E compliance should evaluate their existing controls, policies, System Security and Privacy Plan (SSPP), assessment evidence and continuous monitoring processes against the ARC-AMPE requirements rather than assuming their previous MARS-E implementation remains sufficient.

Lazarus Alliance helps organizations make that transition efficiently and confidently.

What Is ARC-AMPE?

ARC-AMPE is the CMS security and privacy control framework for applicable ACA Administering Entities, Medicaid organizations and other partner entities that exchange information with CMS systems.

The framework establishes security and privacy requirements designed to protect sensitive information and manage the risks associated with systems connecting to CMS.

ARC-AMPE modernizes the previous CMS compliance approach and aligns its controls with NIST Special Publication 800-53 Revision 5.

The framework incorporates security, privacy and risk-management requirements into an integrated control structure covering areas such as:

  • Access control
  • Identification and authentication
  • Audit and accountability
  • Configuration management
  • Incident response
  • Risk assessment
  • Security assessment and authorization
  • System and communications protection
  • System and information integrity
  • Personally identifiable information processing and transparency
  • Supply-chain risk management
  • Continuous monitoring

For affected organizations, ARC-AMPE compliance is more than a documentation exercise. Controls must be appropriately implemented, supported by evidence and capable of demonstrating that security and privacy risks are being effectively managed.

CMS ARC-AMPE Regulations & Guidance
CMS ARC-AMPE guidance

CMS ARC-AMPE Volume I
ARC-AMPE Volume I

ARC-AMPE Replaced MARS-E and the NEE GRC Framework

Organizations familiar with the Minimum Acceptable Risk Standards for Exchanges (MARS-E) should recognize ARC-AMPE as a significant modernization of the CMS security and privacy framework.

MARS-E v2.2 was based primarily on NIST SP 800-53 Revision 4. ARC-AMPE moves the program to NIST SP 800-53 Revision 5 and introduces an updated approach to security, privacy, supply-chain risk and continuous monitoring.

This means organizations should not simply rename existing MARS-E documentation.

A successful transition requires evaluating existing controls and evidence against the applicable ARC-AMPE requirements.

CMS previously ran two parallel frameworks:

  • MARS-E applied to ACA Administering Entities — the Exchanges themselves and related state operators (FFE, State-based Exchanges, SBE-FPs, state Medicaid/CHIP agencies administering coverage, Basic Health Programs, etc.).
  • NEE GRC Framework (Non-Exchange Entity Governance, Risk Management, and Compliance) applied to Non-Exchange Entities — organizations that are not the Exchange operators but connect to the Hub or support ACA functions. CMS established it in 2019 after creating the Enhanced Direct Enrollment (EDE) pathway. Typical NEEs include Primary/Classic EDE entities, certain web-brokers, hybrid and service-provider partners, and other systems that process Exchange PII in non-federal environments. The NEE GRC baseline drew on NIST SP 800-171 (CUI in non-federal systems) and FedRAMP because many NEE systems are cloud-based.

ARC-AMPE consolidates both into one harmonized, enterprise-risk-driven standard covering AEs and select Partner Entities (including former NEE types such as Primary EDE entities). Some former NEE categories are now mandatory under ARC-AMPE Volume II; others may use it as an informative reference. Authorization terminology still distinguishes paths in practice: Authority to Connect (ATC) for AEs and Request to Connect (RTC) outcomes for Non-Exchange / partner entities, documented in interconnection agreements, with ongoing ISCM and annual SSPP updates.

MARS-E was the Exchange-operator baseline; NEE GRC was the partner/connector baseline; ARC-AMPE is the unified CMS successor for both.

Comparison Area MARS-E ARC-AMPE
Framework Status Legacy CMS security and privacy framework Current CMS security and privacy framework replacing MARS-E for applicable entities
Full Name Minimum Acceptable Risk Standards for Exchanges Acceptable Risk Controls for ACA, Medicaid, and Partner Entities
NIST Foundation NIST SP 800-53 Revision 4 NIST SP 800-53 Revision 5
Control Baseline Legacy MARS-E control baseline 402-control minimum baseline for ACA Administering Entities (AEs), derived from NIST SP 800-53 Revision 5
Security & Privacy Security and privacy requirements based on the legacy CMS framework Integrated security and privacy requirements aligned with the updated NIST control structure
Risk Management Primarily system-focused security and privacy risk management Expanded risk-based approach with stronger integration of enterprise risk management
Supply Chain Risk Addressed through legacy security requirements Expanded supply chain risk management requirements aligned with NIST SP 800-53 Rev. 5
SSPP Format Microsoft Word-based System Security and Privacy Plan documentation CMS ARC-AMPE Volume II Excel-based System Security and Privacy Plan (SSPP)
Documentation & Evidence Legacy documentation and assessment evidence requirements Expanded control documentation, implementation statements, ownership information, and assessment evidence
Assessment Approach Assessment against the applicable MARS-E control baseline Assessment against applicable ARC-AMPE security and privacy controls with increased emphasis on implementation evidence
Continuous Monitoring Ongoing monitoring under legacy CMS requirements Greater emphasis on continuous monitoring, ongoing risk management, evidence maintenance, and remediation
Effective Date Superseded for applicable ARC-AMPE entities March 4, 2025
AE Compliance Date Replaced by ARC-AMPE for applicable ACA Administering Entities March 4, 2026
Important: The 402-control figure shown above applies to the ARC-AMPE minimum baseline for ACA Administering Entities (AEs). ARC-AMPE requirements and control baselines can differ by entity type, so organizations should determine the CMS requirements applicable to their specific environment.

Organizations with mature MARS-E programs may have substantial control implementations that remain useful, but existing policies, procedures, technical controls, mappings and evidence should be evaluated against ARC-AMPE.

Who Needs ARC-AMPE Compliance?

ARC-AMPE applies to designated organizations participating in CMS-related ACA, Medicaid and partner-entity environments.

Depending on the organization and its relationship with CMS, applicable entities may include:

  • ACA Administering Entities
  • State Medicaid agencies
  • Children's Health Insurance Program (CHIP) environments
  • State-based marketplaces
  • Direct Enrollment entities
  • Certain CMS partner entities
  • Contractors and service providers supporting covered systems
  • Organizations connecting applicable information systems to CMS services

ARC-AMPE and Medicaid Enterprise Systems

For Medicaid Enterprise Systems, CMS states that ARC-AMPE is required for the Eligibility and Enrollment (E&E) module. As of March 4, 2026, MARS-E is no longer an option for that module. ARC-AMPE compliance artifacts may also be leveraged for applicable security and privacy requirements in other Medicaid modules.

Applicability and assessment requirements depend on the organization's specific CMS relationship, system architecture, information exchanges and contractual or regulatory obligations.

Lazarus Alliance can help organizations determine the applicable assessment scope before beginning the compliance process.

Key Change ARC-AMPE Requirement / Approach
NIST Foundation Based on NIST SP 800-53 Revision 5.
Control Baseline 402-control minimum baseline for ACA Administering Entities (AEs).
Security & Privacy Integrates security and privacy requirements within a modernized control framework.
Enterprise Risk Places greater emphasis on enterprise risk management and risk-based decision-making.
Supply Chain Risk Expands supply-chain risk management requirements aligned with NIST SP 800-53 Rev. 5.
SSPP Format Uses the CMS ARC-AMPE Volume II Excel-based System Security and Privacy Plan (SSPP).
Legacy Frameworks Supersedes applicable requirements previously addressed through MARS-E and the NEE GRC Framework.
Compliance Date March 4, 2026 for applicable ARC-AMPE requirements.
Key Takeaway: ARC-AMPE modernizes CMS security and privacy requirements around NIST SP 800-53 Rev. 5, stronger risk management, expanded evidence expectations, and updated SSPP documentation.

Lazarus Alliance ARC-AMPE Assessment Services

Lazarus Alliance provides a structured assessment approach designed to determine whether ARC-AMPE security and privacy controls are appropriately implemented and supported by defensible evidence.

ARC-AMPE Readiness Assessment

A readiness assessment evaluates the organization's current security and privacy posture before a formal assessment or CMS review.

We evaluate applicable controls, documentation, technical implementations and available evidence to identify deficiencies that could create problems during formal assessment.

The result is a prioritized roadmap showing what should be corrected, strengthened or documented.

Readiness activities may include:

  • ARC-AMPE control applicability review
  • Security and privacy control gap analysis
  • Existing MARS-E control mapping
  • NIST SP 800-53 Rev. 4 to Rev. 5 transition analysis
  • SSPP review
  • Policy and procedure assessment
  • Technical control review
  • Evidence sufficiency analysis
  • Continuous monitoring review
  • POA&M review
  • Remediation prioritization

Independent ARC-AMPE Control Assessment

Lazarus Alliance evaluates the implementation and effectiveness of applicable ARC-AMPE security and privacy controls.

Assessment activities may include examination of documentation and evidence, interviews with responsible personnel and testing of technical or operational controls as appropriate.

The objective is not merely to determine whether a policy exists.

The assessment determines whether controls are implemented, operating as represented and supported by sufficient evidence.

ARC-AMPE Gap Assessment

Organizations beginning their ARC-AMPE journey can use a gap assessment to establish their current position against the required control baseline.

Lazarus Alliance identifies:

  • Fully implemented controls
  • Partially implemented controls
  • Controls lacking sufficient evidence
  • Documentation deficiencies
  • Technical implementation gaps
  • Governance weaknesses
  • Privacy-control deficiencies
  • Supply-chain risk issues
  • Continuous monitoring gaps
  • Areas requiring remediation

This creates a measurable baseline for the organization's compliance program.

MARS-E to ARC-AMPE Transition Assessment

MARS-E to ARC-AMPE Transition Assessment

Organizations previously operating under MARS-E should perform a structured transition assessment.

Lazarus Alliance evaluates the existing MARS-E environment and maps relevant implementations to ARC-AMPE requirements.

Our transition methodology includes:

1. Existing Environment Review: We examine the current MARS-E security program, system boundary, policies, procedures, SSPP, technical implementations and available evidence.

2. Control Mapping: Existing controls are compared with the applicable ARC-AMPE baseline and NIST SP 800-53 Revision 5 requirements.

3. Gap Identification: New, changed or insufficiently implemented requirements are identified.

4. Evidence Review: Existing evidence is evaluated to determine whether it remains sufficient to demonstrate ARC-AMPE control implementation.

5. Remediation Roadmap: Deficiencies are prioritized according to risk, compliance impact and assessment readiness.

6. Validation: Remediated controls can be retested to verify that corrective actions have addressed identified deficiencies.

The result is a structured migration from a legacy MARS-E posture to a defensible ARC-AMPE compliance program.

ARC-AMPE System Security and Privacy Plan Review

The System Security and Privacy Plan (SSPP) is a critical component of the ARC-AMPE compliance environment.

An SSPP should accurately describe the system, security boundary, information environment, control implementations, responsible parties and supporting security and privacy processes.

A common assessment problem occurs when documentation describes what an organization intends to do rather than what it actually does.

Lazarus Alliance evaluates SSPP content against actual implementations and supporting evidence.

Our review can identify:

  • Incomplete control narratives
  • Unsupported implementation claims
  • Outdated system descriptions
  • Incorrect control ownership
  • Missing inherited-control documentation
  • Inconsistent policies and procedures
  • Evidence gaps
  • Technical implementations inconsistent with documented controls

A defensible SSPP should accurately represent the operational environment.

ARC-AMPE Evidence Readiness

Compliance claims must be supported by evidence.

Lazarus Alliance helps organizations determine whether their evidence demonstrates that controls are implemented and operating as described.

Evidence may include:

  • Policies and procedures
  • System configurations
  • Access-control records
  • Authentication configurations
  • Security logs
  • Vulnerability scan results
  • Risk assessments
  • Incident-response records
  • Training records
  • Change-management records
  • Backup and recovery evidence
  • Network diagrams
  • Data-flow diagrams
  • Vendor and supply-chain documentation
  • Continuous monitoring records
  • Security testing results
  • Remediation records

We evaluate evidence for relevance, completeness, consistency and its ability to support the corresponding control implementation.

ARC-AMPE and Related Compliance Frameworks

ARC-AMPE and Related Compliance Frameworks

Organizations subject to ARC-AMPE frequently operate under additional cybersecurity, privacy or regulatory requirements.

Lazarus Alliance's broader assessment experience enables organizations to identify overlapping requirements and reduce unnecessary duplication across frameworks such as:

Where appropriate, existing controls and evidence can be evaluated for reuse across multiple compliance obligations.

ARC-AMPE Continuous Monitoring

ARC-AMPE compliance does not end when an assessment is completed.

Organizations must maintain awareness of their security and privacy risk posture as systems, threats, vulnerabilities and business processes change.

An effective continuous monitoring program should provide visibility into the ongoing effectiveness of security and privacy controls.

Lazarus Alliance can evaluate continuous monitoring processes including:

  • Vulnerability management
  • Configuration monitoring
  • Security event monitoring
  • Access reviews
  • Risk assessments
  • Control assessments
  • Incident management
  • POA&M management
  • Change management
  • Third-party risk
  • Supply-chain risk
  • Security documentation maintenance

Continuous monitoring helps organizations identify control degradation before it becomes an assessment finding or security incident.

ARC-AMPE Remediation and POA&M Support

When deficiencies are identified, organizations need a structured method for managing corrective actions.

Lazarus Alliance can help organizations evaluate findings, prioritize remediation and validate corrective actions.

Our approach helps distinguish between:

  • Documentation deficiencies
  • Evidence deficiencies
  • Technical-control failures
  • Process failures
  • Governance deficiencies
  • Residual risks requiring formal treatment

Where a Plan of Action and Milestones (POA&M) is appropriate, findings should clearly identify the deficiency, responsible party, remediation activity, milestones and expected completion.

Why Choose Lazarus Alliance for ARC-AMPE Assessments?

ARC-AMPE sits at the intersection of federal cybersecurity requirements, healthcare information protection, privacy, risk management and NIST security controls.

Lazarus Alliance provides independent cybersecurity audit and compliance assessment services across complex regulatory and security environments.

Our assessment philosophy focuses on three fundamental questions:

Is the control properly designed?

Is the control actually implemented?

Can the organization prove it?

That evidence-driven approach helps organizations move beyond checklist compliance toward a defensible security and privacy posture.

Independence Statement

Lazarus Alliance, Inc., Lazarus Alliance Compliance, LLC, Continuum GRC, Inc., and the Horse Project / Lazarus Alliance Foundation are separate legal entities under common ownership. Assessment and certification activities are segregated from software licensing and from non-profit education. This structure supports impartiality requirements under ISO/IEC 17020, Cyber AB, FedRAMP, PCI SSC, and AICPA independence rules.

An ARC-AMPE readiness or control assessment from Lazarus Alliance provides an independent evaluation of applicable security and privacy controls, documentation, evidence and implementation. The scope and purpose of the engagement should be defined according to the organization's applicable CMS requirements and assessment obligations.

Frequently Asked Questions

ARC-AMPE replaced the MARS-E framework. Organizations previously operating under MARS-E should evaluate their security and privacy programs against ARC-AMPE rather than assuming their previous MARS-E implementation satisfies current requirements.

MARS-E is now a legacy framework for organizations that have transitioned into the ARC-AMPE compliance environment. Organizations should determine their current CMS obligations and applicable ARC-AMPE requirements.

Yes. ARC-AMPE uses NIST SP 800-53 Revision 5 as an important foundation for its security and privacy control requirements.

Potentially. Many existing security implementations may remain useful, but they should be mapped and evaluated against ARC-AMPE. Organizations should not assume that an existing MARS-E implementation automatically satisfies ARC-AMPE.

Organizations transitioning from MARS-E should review their existing system security and privacy documentation against current ARC-AMPE requirements and CMS-provided templates. Existing documentation may require substantial updates.

Yes. An effective assessment requires evidence demonstrating that applicable security and privacy controls are implemented and operating as represented.

ARC-AMPE incorporates ongoing assessment and continuous monitoring into its risk-management approach. Organizations should maintain visibility into their security and privacy posture rather than treating compliance as a one-time activity.

Yes. Lazarus Alliance can evaluate an organization's current environment against applicable ARC-AMPE requirements, identify gaps, review documentation and evidence, and develop a prioritized remediation roadmap.

Yes. Lazarus Alliance can evaluate existing MARS-E controls, documentation and evidence against ARC-AMPE requirements and identify changes necessary to support the transition.

CMS published ARC-AMPE Version 1.0 on March 4, 2025 (Volume I Version 1.02 followed on April 9–10, 2025). CMS states that ARC-AMPE supersedes and replaces MARS-E effective upon publication. MARS-E Version 2.2 remained the prior AE baseline until organizations completed the mandated transition.

The AE minimum baseline contains 402 security and privacy controls derived from NIST SP 800-53 Revision 5. The DEE minimum baseline contains 308 controls. That is a material increase from MARS-E v2.2 (NIST SP 800-53 Rev. 4) and from the prior EDE baseline. New families with no MARS-E predecessor include PT (PII Processing and Transparency) and SR (Supply Chain Risk Management). Counts can change with CMS baseline revisions and entity-specific tailoring (PL-11).

Yes, when the system is in CMS’s mandatory user set. Volume I defines ACA Administering Entities to include state Medicaid agencies, state CHIP agencies, and agencies administering a Basic Health Program. Mandatory users include state Medicaid and CHIP agencies whose systems connect to the CMS Federal Data Services Hub, plus systems that process Exchange-related PII under 45 CFR §155.260 (including eligibility information shared between Exchanges and Medicaid/CHIP/BHP). Integrated MAGI E&E platforms that perform Hub account transfer, federal verification, or Marketplace coordination are typically in scope. A purely standalone Medicaid E&E environment that never connects to the Hub and does not process Exchange PII may fall outside mandatory Volume II implementation, but CMS still presents ARC-AMPE as an informative reference for strengthening security, privacy, and HIPAA posture. Contract language (APDs, vendor RFPs, ISAs) often extends ARC-AMPE to Medicaid E&E contractors regardless.

CMS Volume I provides a non-exhaustive artifact list used to support Authority to Connect (ATC) for AEs and Request to Connect (RTC) outcomes for Non-Exchange / partner entities. Typical assessment and authorization evidence includes:

  • Completed ARC-AMPE Volume II SSPP (Excel)
  • Information System Risk Assessment (ISRA)
  • Security Assessment Plan (SAP), Security Assessment Report (SAR), and Security Assessment Workbook (SAW)
  • Penetration test results and vulnerability scans
  • Plan of Action and Milestones (POA&M)
  • Privacy Impact Assessment (PIA) and Security Impact Assessment (SIA) where applicable
  • Risk Acceptance (RA) Form and Change Notification (CN) Form
  • Legal and interconnection agreements: ISA, DUA, CMA, IEA, MOU/MOA

After authorization, entities must perform Information Security and Privacy Continuous Monitoring (ISCM), submit recurring artifacts, and update the SSPP at least annually or upon significant change. Independent control assessments remain part of CMS oversight. Exact package contents can vary by entity type (AE vs. DEE/NEE) and by the current CMS submission instructions.

Credentials You Can Count On

  • Veteran-Owned Small Business (VOSB) | UEI: CQD9NFDH7AH4 | CAGE: 4PHZ4
  • Authorized CMMC C3PAO (CPN 10251) | A2LA ISO/IEC 17020
  • A2LA-accredited FedRAMP 3PAO
  • PCI DSS Qualified Security Assessor (QSA)
  • Delaware-licensed CPA firm — SOC 1, SOC 2, SOC 3
  • GSA MAS 47QRAA22D009A

Talk with one of our experts

Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.

We're here to answer any questions you may have.

Download our company brochure.

Prepare for ARC-AMPE Assessment

Organizations transitioning from MARS-E or preparing for their first ARC-AMPE assessment should begin by understanding their system boundary, applicable controls, existing security and privacy implementations and available assessment evidence.

Finding deficiencies before a formal assessment provides time to remediate them before they become formal findings.

Lazarus Alliance can help you determine where you stand, what needs to change and what evidence you need to demonstrate ARC-AMPE compliance.

Start Your ARC-AMPE Assessment

Prepare your organization for ARC-AMPE with an independent, evidence-driven assessment from Lazarus Alliance.

Contact Lazarus Alliance today to schedule an ARC-AMPE readiness assessment, gap assessment or independent security and privacy control assessment.

We want to be your partner and ARC-AMPE-aligned cybersecurity assessor of choice! For additional information, please call +1 (888) 896-7580.