Qualysec
Blog

MARS-E Compliance Guide: Security Controls, ATO Requirements & ARC-AMPE Transition

Learn MARS-E compliance requirements (USA), key security controls, ATO steps, and ARC-AMPE transition rules to prepare for your 3PAO assessment.

Published on September 1, 2026
Read Time: 17 min
CONNECT WITH US

Every year, millions of Americans use the Affordable Care Act (ACA) Marketplace to enrol in health insurance. Large amounts of sensitive data are being exchanged behind these exchanges, such as Personally Identifiable Information (PII), Protected Health Information (PHI), and Federal Tax Information (FTI). The Centers for Medicare & Medicaid Services (CMS) has adopted the Minimum Acceptable Risk Standards for Exchanges (MARS-E) to ensure that all entities providing assistance to ACA marketplaces are adhering to the necessary requirements to safeguard the data.

MARS-E compliance is the process of meeting the security and privacy requirements established by the Centers for Medicare & Medicaid Services for ACA exchanges and their supporting organizations. To achieve MARS-E compliance, organisations need to identify systems that fall within the MARS-E boundary, implement security and privacy controls based on NIST SP 800-53, maintain documentation such as the System Security Plan (SSP) and Plan of Action and Milestones (POA&M), complete independent security assessments, and obtain an Authority to Operate (ATO). Failure to meet these requirements can result in penalties of up to $25,000 per violation, suspension or revocation of an Authority to Operate (ATO), and restricted access to CMS systems.

CMS has announced that MARS-E is being replaced with the Acceptable Risk Controls for ACA, Marketplace, Privacy, and Enhanced Security (ARC-AMPE) framework. Although many of the security controls are aligned with NIST SP 800-53, organizations must be aware of the change and ensure compliance.

This guide explains what MARS-E compliance is, who must comply, its key security requirements, the assessment process, common documentation, and best practices. 

What is MARS-E? 

MARS-E is called Minimum Acceptable Risk Standards for Exchanges. It is a collection of security and privacy guidelines created by the Centers for Medicare & Medicaid Services to protect sensitive personally identifiable information (PII) and protected health information (PHI that is used in the health insurance market. MARS-E was officially created specifically for ACA exchanges and partner entities and is replaced by ARC-AMPE (Acceptable Risk Controls for ACA, Medicaid, and Partner Entities) by the Centers for Medicare & Medicaid Services (CMS), effective March 4th 2026. 

MARS-E 2.2 is structured across two volumes

  1. Volume I: Harmonized Security and Privacy Framework: It defines security and privacy controls required for Affordable Care Act (ACA) systems. 
  2. Volume II: ACA Administering Entity System Security and Privacy Plan: It provides instructions for the System Security and Privacy Plan (SSP), superseding older v. 2.0 volumes III and IV. 

Who needs MARS-E Compliance? 

MARS-E compliance is required for the organisations that handle sensitive consumer data under the Affordable Care Act. These organisations are:

  1. Federal and state health insurance exchanges.
  2. State-based Health Insurance Exchanges (SBEs), State agencies that administer the Children’s Health Insurance Program (CHIP) and the Basic Health Program (BHP).
  3. Payment processors, premium billing and collection vendors, banks handling subsidy disbursements, insurers, third-party administrators (TPAs), and any subcontractors that handle personally identifiable information (PII), protected health information (PHI), or federal tax information (FTI).
  4. Organisations handling PHI may also need to consider related healthcare privacy requirements such as HIPAA, depending on their role and activities.
  5. Third-party contractors, vendors, and subcontractors working with any of the above entities.

Note: Organisations required to comply with MARS-E must also ensure that their subcontractors implement and maintain the applicable MARS-E security controls.

Data Types Involved for MARS-E Compliance

  • PII: Personally Identifiable Information.
  • PHI: Protected Health Information.
  • FTI: Federal Tax Information where applicable

MARS-E vs. HIPAA vs. FedRAMP vs. FISMA

MARS-E HIPAA  FedRAMP FISMA
Minimum Acceptable Risk Standards for Exchanges  Health Insurance Portability and Accountability Act Federal Risk and Authorization Management Program Federal Information Systems Modernization Act 
It protects healthcare marketplace data and systems operated by ACA Exchanges It protects electronic Protected Health Information (ePHI) It standardises security assessment and authorization for federal cloud services It establishes a government-wide cybersecurity program for federal information systems
Compliance is mandatory on:

State-based Health Insurance Exchanges (SBEs), Federally Facilitated Exchanges (FFEs), contractors, and partners supporting ACA marketplaces

Compliance is mandatory on:

Healthcare providers, health plans, healthcare clearinghouses, and business associates

Compliance is mandatory for: Cloud Service Providers (CSPs) serving U.S. federal agencies Compliance is mandatory on:

U.S. federal agencies and organizations operating federal information systems

Regulatory authority is:

U.S. Centers for Medicare & Medicaid Services 

Regulatory authority is: 

U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR)

Regulatory authority is: 

U.S. General Services Administration (GSA) with Joint Authorization Board (JAB) and federal agencies

Regulatory authority is:

U.S. Office of Management and Budget (OMB), NIST, and federal agencies

Applicable on Healthcare insurance marketplaces Applicable to healthcare Applicable to cloud computing Applicable to the federal government

Key requirements of MARS-E compliance

MARS-E compliance is based on the NIST SP 800-53 framework, which provides security guidelines for protecting information systems. It includes 18 Security Domains to secure systems and 8 Privacy Domains to ensure sensitive data, such as PII, PHI, and FTI, is handled safely, legally, and ethically. 

State-based Health Insurance Exchanges (SBEs), the Children’s Health Insurance Program (CHIP), the Basic Health Program (BHP), and other eligible entities must incorporate the following security controls in their system:

The 18 Security Domains to Keep the Systems Safe

  1. Access Control (AC): Restricts system access to authorized users, devices, and processes.
  2. Awareness and Training (AT): Ensures personnel receive security awareness education and role-based training.
  3. Audit and Accountability (AU): Records, monitors, and reviews system activities to support accountability and detect unauthorized actions.
  4. Security Assessment and Authorization (CA): Evaluates security controls and authorizes systems for operation while ensuring continuous monitoring.
  5. Configuration Management (CM): Establishes and maintains secure configurations for hardware, software, and system components.
  6. Contingency Planning (CP): Develops and maintains backup, recovery, and disaster response plans to ensure business continuity.
  7. Identification and Authentication (IA): Verifies the identity of users, devices, and services before granting access.
  8. Incident Response (IR): Detects, analyzes, responds to, and recovers from cybersecurity incidents.
  9. Maintenance (MA): Performs secure and controlled maintenance to preserve system integrity and availability.
  10. Media Protection (MP): Safeguards physical and digital storage media from unauthorized access, disclosure, or destruction.
  11. Physical and Environmental Protection (PE): Protects facilities, equipment, and infrastructure against physical and environmental threats.
  12. Planning (PL): Develops, documents, and updates security plans to guide organizational security practices.
  13. Personnel Security (PS): Reduces security risks through employee screening, onboarding, and termination procedures.
  14. Risk Assessment (RA): Identifies, analyzes, and evaluates risks to organizational operations, assets, and information.
  15. System and Services Acquisition (SA): Integrates security requirements into the acquisition, development, and maintenance of systems and services.
  16. System and Communications Protection (SC): Protects information during transmission and secures communication channels.
  17. System and Information Integrity (SI): Identifies, manages, and remediates system flaws while protecting against malware and unauthorized changes.
  18. Program Management (PM): Establishes and oversees the organisation’s cybersecurity governance, policies, and strategic security objectives.

The 8 Privacy Domains to protect Individual Rights

Security protects systems; privacy domains protect people by ensuring their PII, PHI, and FTI are collected, used, stored, and shared responsibly.

  1. Authority and Purpose: Personal data is collected only when there is a legal reason, and individuals are informed why it is needed.
  2. Accountability, Audit, and Risk Management: A Privacy Officer oversees compliance, assesses privacy risks, and ensures staff follows privacy rules.
  3. Data Quality and Integrity: Personal information is kept accurate, complete, and up to date.
  4. Data Minimization and Retention: Only the necessary information is collected, and we securely delete it when we no longer require it.
  5. Individual Participation and Redress: Individuals can view their personal information and request corrections if it is inaccurate.
  6. Security (Privacy Safeguards): Privacy policies and technical controls work together to keep sensitive information secure and confidential.
  7. Transparency: Organizations clearly explain what information is collected, why it is collected, and how it will be used or shared.
  8. Use Limitation: Personal information is used only for authorized purposes and is not shared or reused without proper permission.

Key Documents Required for MARS-E Compliance

Key Documents required for MARS-e compliance

To obtain an Authorization to Operate (ATO) under the CMS MARS-E framework, the eligible entities must prepare and submit the below-mentioned essential documents. 

1. The Mandatory documents 

These are the essential documents required to apply for an ATO.

  • System Security Plan (SSP): Describes the system, its security boundary, architecture, and how NIST SP 800-53 security controls are implemented.
  • Information Security Risk Assessment (ISRA): Identifies threats, vulnerabilities, and risks to the system.
  • Privacy Impact Assessment (PIA): Explains how sensitive information, such as PII, PHI, and FTI, is collected, used, stored, and protected.
  • Plan of Action and Milestones (POA&M): Lists identified security weaknesses, planned fixes, responsible personnel, and target completion dates.

2. Independent Security Assessment

CMS explicitly mandates that an independent security assessment be conducted by a Qualified Third-Party Assessment Organisation (3PAO) each year. 

  • Security and Privacy Assessment Plan (SAP): This is added to prevent low-quality audits. This document is compiled by your independent auditor before testing begins to map out every single rule, tool, and system that will be tested.
  • Security Assessment Report (SAR): Summarizes the assessment results and confirms whether security controls are working effectively.

3. Operational and Contingency Documents

These documents show that the organization is prepared to respond to incidents and maintain operations.

  • Contingency Plan (CP) and Disaster Recovery (DR) Plan: Describe a step-by-step plan on how systems and data will be restored after a disruption.
  • Contingency Plan Test Report (CPTR): Provides evidence that disaster recovery procedures have been tested.
  • Incident Response Plan (IRP): Defines how security incidents are detected, reported, and managed.
  • Security Awareness and Training Records: Demonstrate that employees have completed required security and privacy training.

4. Data Sharing Agreements

MARS-E relies heavily on legally binding federal and local data agreements, which are explicitly governed by Tier 6 of the MARS-E Harmonized Framework

These agreements govern the secure exchange of information between organizations.

  • Computer Matching Agreement (CMA): This agreement explicitly establishes legal authority to compare state system data against federal databases (like the IRS or SSA).
  • Information Exchange Agreement (IEA): This agreement governs the terms, conditions, safeguards, and procedures for exchanging information when a computer matching agreement does not cover the information exchange.
  • Interconnection Security Agreement (ISA): This agreement manages security risk exposures created by the interconnection of a system to another system owned by an external entity for connections between the organization’s systems and CMS.

Want a Sample Security Testing Report?

See how our experts document vulnerabilities, risk severity, and clear remediation steps.

Download Sample Report

Security Testing Report

MARS-E Assessment Process: From SSP to SAR

The MARS-E assessment process helps organizations demonstrate that they have implemented effective security and privacy controls. Before they receive Authorisation to Operate (ATO) from the Centers for Medicare & Medicaid Services (CMS). The process to receive :

1. System Security and Privacy Plan (SSP)

The process starts with the SSP, which is the foundational blueprint for an organisation’s security posture. The SSP describes the system’s purpose, architecture, data flows, security boundaries, responsible personnel, and how each required MARS-E security and privacy control is implemented. It documents policies, procedures, risk management practices, and supporting evidence. The SSP must be reviewed annually or whenever major system modifications occur in the system. 

2. Security Assessment Plan (SAP)

Before evaluation begins, an independent assessment team formulates the SAP. The SAP outlines the assessment scope, objectives, schedule, and specific testing procedures on the basis of established control standards such as NIST SP 800-53/800-53A.

3. Assessment Execution & Procedures

Independent security assessors or Third-Party Assessment Organizations (3PAOs)  execute the SAP using three primary methodology types: 

  • Examine: Evaluating security policies, procedures, system documentation, technical specifications, and system configurations helps verify that required controls are properly implemented.
  • Interview: Question key personnel involved in obtaining and maintaining the ATO, such as system owners, security officers, and administrators. Confirm that they understand and follow the required security processes.
  • Test: Test technical safeguards by performing activities such as vulnerability scanning, penetration testing, access control validation, and configuration reviews to verify that security controls operate effectively and protect sensitive information.

This rigorous evaluation verifies whether the controls operate as intended and produce the desired level of protection.

4. Security Assessment Report (SAR)

The results are documented in the Security Assessment Report (SAR), which identifies any security weaknesses, their risk level, and recommendations for remediation. Findings in the SAR directly inform the Plan of Action and Milestones (POA&M), driving risk remediation to ensure continuous compliance and system authorisation.

Consequences of non-compliance with MARS-E

As we know, MARS-E is an administrative standard mandated by the Centers for Medicare & Medicaid Services (CMS). The consequences for non-compliance lie in multiple ways, such as:

ACA Civil Penalties CMS will levy civil monetary penalties of up to $25,000 per violation under the Affordable Care Act (42 U.S.C. § 18041) for improper disclosure or misuse of Personally Identifiable Information (PII).
HIPAA and HITECH Penalties If a security failure exposes PHI, the HHS Office for Civil Rights (OCR) has the right to impose penalties. For uncorrected willful neglect, fines can reach $50,000 per violation, with annual limits of approximately $2 million, depending on the circumstances.
Loss of System Access CMS will suspend, revoke, or terminate an organization’s Authority to Operate (ATO) and/or Authority to Connect (ATC) if it fails to meet MARS-E security requirements. This may ultimately hinder the organization’s access to the Federal Data Services Hub for identity verification, tax information, and/or ACA eligibility.
Criminal Penalties Federal law provides criminal penalties for releasing or using health information to obtain personal gain, including up to $250,000 in fines and up to 10 years of imprisonment.
Transition to ARC-AMPE CMS has updated MARS-E v2.2 to ARC-AMPE, which is based on NIST SP 800-53 Revision 5. 

Organizations had to make a transition in compliance with the CMS deadlines. Non-compliance with ARC-AMPE may lead to the same legal and regulatory consequences as did non-compliance with MARS-E. 

MARS-E Best Practices Checklist

  • Determine where sensitive data is collected, stored, processed, and shared and identify systems that are covered by MARS-E.
  • Evaluate current security measures against the MARS-E security requirements to uncover security gaps.
  • Develop a System Security Plan (SSP) and update it as appropriate when major changes occur in the system or environment.
  • Continuously monitor your systems and collect security evidence to support ongoing compliance and audits.
  • Make sure vendors, contractors, and subcontractors who work with MARS-E data have the same security and privacy standards.
  • Regularly educate staff about security and privacy at work and hold incident response exercises for potential incidents.
  • Have a qualified Third Party Assessment Organization (3PAO) conduct an independent evaluation prior to having your system reviewed by CMS.

How can QualySec help with MARS-E Compliance?

Knowing MARS-E compliance is one thing. Proving it with proof that your organisation actually does is another, and this is exactly where the real work and real gap lie.

QualySec is a CREST Accredited company for Penetration Testing and VAPT (Vulnerability Assessment and Penetration Testing) services in Web App, Mobile App, API, Cloud and external network compliance testing. ARC-AMPE now governs the security requirements for organizations supporting ACA exchanges and related CMS programs, succeeding MARS-E. However, both acts require organizations to demonstrate through technical validation that security controls such as access controls, encryption, and system integrity are operating effectively. This is where QualySec’s expertise can help. QualySec specialises in.

  • Technical evaluation of security measures –  Policy documents are insufficient to satisfy the families of security controls for MARS-E, such as Access Control and System & Information Integrity. One way to create the type of evidence a System Security Plan requires is by penetration testing your applications, networks, and cloud resources.
  • Pre-assessment gap identification – A quick security gap assessment will help you identify major areas of access control, encryption, or monitoring weaknesses before you formalize an audit timeline with a third-party auditor and get them involved.
  • Documentation support – Organizing raw technical findings (such as scan results or test reports) into an audit-ready format can be the key to a successful assessment. It is a common requirement in all compliance testing services, irrespective of which compliance framework you are testing against.
  • Continuous testing –  Between formal reassessments, MARS-E expects continuous monitoring. By working with a testing partner periodically, Qualysec ensures your controls are clearly effective throughout the year. 

Key Takeaways

  • MARS-E is the CMS security and privacy framework for organizations handling Affordable Care Act (ACA) marketplace data. Although it has been replaced by ARC-AMPE, its security principles continue to form the foundation of CMS compliance.
  • Organizations supporting ACA exchanges or CMS programs that handle PII, PHI, or FTI must comply with MARS-E (or ARC-AMPE).
  • In order to meet the requirements of MARS-E, organizations must create the following documents: System Security Plan (SSP), Privacy Impact Assessment (PIA), Risk Assessment (ISRA), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M).
  • If you do not comply, you could be fined up to $25,000 for every offence. Regular risk assessments, penetration testing, continuous monitoring, employee training, and independent audits improve compliance and overall cybersecurity posture.

Conclusion

For organizations supporting the Affordable Care Act (ACA) Marketplace and related CMS programs, protecting sensitive data isn’t simply about meeting a compliance checklist. As a State-Based Exchange, an insurer, a contractor, or a technology provider supporting the Affordable Care Act (ACA), you can use MARS-E security controls to lower cyber risk, safeguard sensitive consumer data, and show compliance with CMS requirements. While MARS-E is no longer used, the goal of building secure systems, assessing risk continually, and enhancing security posture over time remains valid. Keeping proper records, running regular security audits, educating staff members, and fixing vulnerabilities quickly and effectively can make it easier to authorize but make systems more secure and resilient. 

Speak Directly With Qualysec’s Certified Security Experts

Discover vulnerabilities before attackers exploit them

Schedule Free Consultation

Security Expert

Frequently Asked Questions (FAQs)

1. Who needs to comply with MARS-E?

Organizations that collect, process, store, or share sensitive data under the Affordable Care Act (ACA) require MARS-E compliance. This includes Federal and State Health Insurance Exchanges, State-Based Exchanges (SBEs), agencies administering CHIP and the Basic Health Program (BHP), insurers, payment processors, contractors, vendors, and subcontractors that handle Personally Identifiable Information (PII), Protected Health Information (PHI), or Federal Tax Information (FTI). 

2. What are the key requirements of MARS-E compliance?

MARS-E requires organizations to implement 18 security domains and 8 privacy domains to protect sensitive information based on the NIST SP 800-53 framework. Other than implementing these controls, organizations must maintain documents such as the System Security Plan (SSP), Privacy Impact Assessment (PIA), Information Security Risk Assessment (ISRA), and Plan of Action and Milestones (POA&M).

3. How can organizations achieve MARS-E compliance?

Organizations can achieve MARS-E compliance by:

  • First, identify which systems handle ACA-related data and assess them against MARS-E requirements. 
  • After addressing security gaps, they must implement the required security and privacy controls.
  • Prepare the mandatory compliance documentation and undergo an independent assessment by a qualified Third-Party Assessment Organization (3PAO).

4. What are the consequences of non-compliance with MARS-E?

Non-compliance with MARS-E can result in significant financial, operational, and legal consequences. Under the Affordable Care Act, CMS may impose civil penalties of up to $25,000 per violation for the improper disclosure or misuse of Personally Identifiable Information (PII). If a security incident exposes Protected Health Information (PHI), HIPAA and the HITECH Act may impose penalties of up to $50,000 per violation, with annual fines reaching approximately $2 million, depending on the nature of the violation. CMS has the right to revoke an organization’s Authority to Operate (ATO) or Authority to Connect (ATC), preventing access to the Federal Data Services Hub.

5. How does penetration testing help with MARS-E compliance?

Penetration testing is an important part of achieving and maintaining MARS-E compliance. It provides evidence that an organization’s security controls work effectively against real-world cyberattacks. It helps meet key NIST SP 800-53 requirements by validating security controls, identifying vulnerabilities that automated scans may miss, testing incident response capabilities, and confirming that systems can detect and respond to threats.

Chandan Sahoo

About Chandan Sahoo

Chandan Kumar Sahoo is the Co-Founder and Chief Executive Officer (CEO) at Qualysec. With over 8 years of experience in security testing and software quality assurance, he leads corporate strategy and expansion, helping organizations globally secure their web, mobile, and cloud environments.

Leave a Comment.

Your email address will not be published. Required fields are marked *

Related Blogs

Subscribe to Newsletter

Get the latest cybersecurity insights, compliance tips, and vulnerability reports delivered directly to your inbox.