HomeFrameworksHealthcare & Human ServicesARC-AMPE

Framework  Healthcare & Human Services

ARC-AMPE

Acceptable Risk Controls for ACA, Medicaid, and Partner Entities is the CMS security and privacy control framework that replaced MARS-E for state-based marketplaces, state Medicaid and CHIP agencies, and Basic Health Program agencies (called Administering Entities), and replaced the separate EDE and DE security requirements for Direct Enrollment Entities.

CMS published version 1.0 on March 4, 2025. It rebases everything on NIST SP 800-53 Revision 5, merges privacy and security into one control set, and adds overlays for federal tax information.

Volume I explains the framework and roles; Volume II is the control catalog and doubles as the format for the System Security and Privacy Plan.

In writing, a covered entity needs the SSPP for each system, an information security risk assessment, a privacy impact assessment, an incident response plan, contingency plan, configuration management plan, and the policies behind every control family, plus an authorization package built on an independent assessment.

AI-compiled
Share
Sponsored
ARC-AMPE
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with ARC-AMPE
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Administering Entities: state-based marketplaces, state Medicaid and CHIP agencies, and Basic Health Program agencies that connect to the federal data services hub, plus their contractors. Direct Enrollment Entities: web brokers, issuers, and EDE partners that enroll consumers through the federal marketplace.

What the assessor asks to see

The assessor asks for the system boundary and data flow diagrams, the SSPP in Volume II format, the risk assessment and privacy impact assessment, policies and procedures for each control family, access control and audit log evidence, vulnerability scan and penetration test results, configuration baselines, the incident response and contingency plans with test records, training records, interconnection security agreements, and the open plan of action and milestones.

Transition from MARS-E

ARC-AMPE v1.0 was published March 4, 2025 with a one-year transition. On March 4, 2026 CMS retired MARS-E v2.2 for Administering Entities. Coalfire reports a version 1.03 update to the Administering Entities volume; verify the current version on the CMS site before starting an assessment.

Assessors

Who assesses ARC-AMPE

Independent third-party security and privacy assessors engaged by the entity (security control assessment for Administering Entities; third-party auditors under the EDE program for Direct Enrollment Entities). CMS reviews the assessment package and grants the authority to connect or approval to operate. There is no certification body.

CMS defines assessor independence expectations and accepts or rejects packages.

No firm has claimed a ARC-AMPE assessor listing yet. Claim yours →

Consultants

Who helps with ARC-AMPE

A specialized consulting market that grew up around MARS-E: security assessment firms, SSPP authors, and managed compliance providers for state agencies and DE partners. Engagements typically run a MARS-E to ARC-AMPE gap analysis, re-author the SSPP in the Volume II format, and prepare for the independent assessment.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a ARC-AMPE consultant listing yet. Claim yours →

Software

Tools for ARC-AMPE

Tools that name this framework in their own material.

No firm has claimed a ARC-AMPE tool listing yet. Claim yours →

Related reading

  1. MARS-E to ARC-AMPE: A Guide for State Medicaid AgenciesSets out the three changes that stop old MARS-E documentation being relabelled, and how to remap an existing control posture.Amazon Web Services
  2. CMS Publishes ARC-AMPEAn assessor's summary of the two volumes, the AE and DEE control counts, and the compliance dates for each entity type.Coalfire

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for ARC-AMPE

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with ARC-AMPE

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.