HomeFrameworksHealthcare & Human ServicesCMS EDE

Framework  Healthcare & Human Services

CMS EDE

Enhanced Direct Enrollment is the CMS pathway that lets approved web brokers, insurers, and technology platforms host the entire federal marketplace application and enrollment experience on their own websites, exchanging data with the Federally Facilitated Exchange through CMS APIs.

Because these entities handle applicant tax and eligibility data, CMS requires each primary EDE entity to pass an independent third-party audit before approval and to repeat it every year. The audit has two parts: a Business Requirements Audit and a Privacy and Security Audit.

In writing, an EDE entity needs a System Security and Privacy Plan (now in the ARC-AMPE Direct Enrollment Entity format), a risk assessment, incident response and contingency plans, privacy notices and consent language, agent and broker oversight procedures, documented business processes mapped to CMS requirements, and the annual audit reports with remediation plans.

Downstream entities that use a primary entity's platform inherit most controls but still sign CMS agreements.

AI-compiled
Share
Sponsored
CMS
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with CMS EDE
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Primary EDE entities (web brokers, issuers, and platforms) that build and operate an EDE environment, and downstream EDE entities that use them. Participation is voluntary; the audits are a condition of approval.

What the assessor asks to see

Auditors ask for the SSPP and system boundary, the risk assessment and privacy impact assessment, security policies and procedures, access control and logging evidence, vulnerability scans and penetration tests, the incident response plan and records, the business process documentation and screen flows, test case results against CMS requirements, agent and broker oversight records, consumer consent and notice language, and remediation evidence for prior findings.

Framework transition

The security control set for EDE entities moved from the EDE-specific NIST 800-53 Revision 4 baseline to ARC-AMPE for Direct Enrollment Entities, with a compliance target around the end of June 2026 (verify against the current CMS EDE guidelines).

Assessors

Who assesses CMS EDE

Independent, objective third-party auditors selected by the entity that meet the qualification and independence requirements in the CMS guidelines and 45 CFR 155.221 (experience with NIST standards and HIPAA for the privacy and security audit; no system access for the business audit). CMS reviews and approves the audit results.

CMS sets auditor requirements in the annual guidelines rather than accrediting firms.

No firm has claimed a CMS EDE assessor listing yet. Claim yours →

Consultants

Who helps with CMS EDE

A niche market of marketplace technology consultants, security assessment firms, and platform providers that offer EDE-as-a-service. Engagements run through the annual cycle: build or update, readiness review, audit, submission, remediation.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a CMS EDE consultant listing yet. Claim yours →

Software

Tools for CMS EDE

Tools that name this framework in their own material.

No firm has claimed a CMS EDE tool listing yet. Claim yours →

Related reading

  1. "Direct Enrollment" in Marketplace Coverage Lacks Protections for ConsumersExplains how the EDE pathway works end to end and which marketplace safeguards a consumer loses when a private site hosts the application.Center on Budget and Policy Priorities

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for CMS EDE

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with CMS EDE

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.