ARC-AMPE Compliance 2026 — FedRAMP Authorized GRC + AI Auditor
Table of Contents
ToggleContinuum GRC delivers your Roadmap to Risk Reduction for CMS Acceptable Risk Controls for ACA, Medicaid, and Partner Entities (ARC-AMPE). Replace MARS-E and NEE GRC spreadsheets with the only FedRAMP Authorized GRC platform and the world’s first AI auditor — AITAMBot™.
The Continuum GRC ITAM SaaS platform has hundreds of plugin modules available, including dedicated ARC-AMPE modules for ACA Administering Entities (AEs), Direct Enrollment Entities (DEEs), Medicaid / CHIP programs, and CMS Hub partner entities.
Acceptable Risk Controls for ACA, Medicaid, and Partner Entities (ARC-AMPE)
ARC-AMPE is the Centers for Medicare & Medicaid Services (CMS) security and privacy framework that supersedes and replaces MARS-E and the NEE GRC Framework. It is the standard by which organizations that administer or support Affordable Care Act and Medicaid programs must manage security and privacy risk across the health coverage eligibility and enrollment lifecycle — including systems that connect to the CMS Federal Data Services Hub or process Exchange-related PII and PHI.
Volume I provides governance, scope, and continuous-monitoring guidance. Volume II is the Excel-based System Security and Privacy Plan (SSPP) that establishes the minimum control baseline derived from NIST SP 800-53 Revision 5 and SP 800-53B. Privacy is no longer a side appendix. It sits inside the same 20-family catalog as security, including two families that did not exist in MARS-E: PT — Personally Identifiable Information Processing and Transparency and SR — Supply Chain Risk Management.
ACA Administering Entities were required to implement ARC-AMPE by March 4, 2026. Direct Enrollment Entities followed in June 2026. The work does not end at initial implementation. CMS expects a living SSPP, enterprise risk management, annual Authority to Connect (ATC) or Authority to Operate (ATO) renewal, breach reporting, and continuous monitoring.
Modules include:
- ARC-AMPE Volume I governance workspace
- ARC-AMPE Volume II SSPP (Excel-native export)
- ACA Administering Entities (AE): AE 402-control baseline
- Direct Enrollment / Partner Entities: DEE 308-control baseline
- MARS-E → ARC-AMPE migration map
- EDE / NEE GRC → ARC-AMPE migration map
- Privacy Program Plan (PT family)
- Supply Chain Risk Management (SR family)
- POA&M and milestone tracking
- Continuous monitoring (CONMON) package
- AC — Access Control
- AT — Awareness and Training
- AU — Audit and Accountability
- CA — Assessment, Authorization, and Monitoring
- CM — Configuration Management
- CP — Contingency Planning
- IA — Identification and Authentication
- IR — Incident Response
- MA / MP / PE — Maintenance, Media, Physical
- PL / PM / PS — Planning, Program Management, Personnel
- RA / SA / SC / SI — Risk, Acquisition, Communications, Integrity
- ATC / ATO renewal evidence binder
ARC-AMPE Compliance Platform Comparison – 2026
| Feature | Continuum GRC | Drata | Secureframe | Vanta | PreVeil |
|---|---|---|---|---|---|
| FedRAMP Authorized Platform | ✅ | — | — | — | — |
| AI Auditor Capabilities | ✅ AITAMBot (Full AI Auditor) | ✅ Drata AI Agents | ✅ Secureframe AI | ✅ Vanta AI Agent | Partial |
| Independent CMS / ARC-AMPE Assessment Services | ✅ Direct 3PAO / Assessors | — | — | — | — |
| Dedicated AI Auditor Tool | ✅ AITAMBot | — | — | — | — |
| Number of Frameworks Supported / Mapped | 100+ | 30+ | 25+ | 35+ | CMMC-focused |
| Ability to Create Custom Frameworks | ✅ Yes | ✅ Yes | ✅ Yes | ✅ Yes | — |
| Full ARC-AMPE AE + DEE Support | ✅ 402 AE / 308 DEE controls | — | — | — | — |
| Excel Volume II SSPP Generation | ✅ | — | — | — | — |
| MARS-E / EDE / NEE Migration Maps | ✅ | — | — | — | — |
| Automated Evidence Collection | ✅ | ✅ | ✅ | ✅ | ✅ |
| Monitoring & Alerts | ✅ | ✅ | ✅ | ✅ | Partial |
| POA&M Management & Remediation Tracking | ✅ | ✅ | ✅ | ✅ | ✅ |
| Continuous Monitoring & Alerts | ✅ | ✅ | ✅ | ✅ | Partial |
| Free 14-Day Trial (No Credit Card) | ✅ | — | — | — | — |
| Free Gap Assessment / Readiness Tool | ✅ Free Modules + Full AI Auditor | — | Partial (Partner-only) | — | — |
| Built-in ARC-AMPE Templates & Policies | ✅ | — | — | — | — |
| Real-Time Compliance Dashboard | ✅ | ✅ | ✅ | ✅ | ✅ |
Why is ARC-AMPE Important for You?
ARC-AMPE matters because it is now the CMS rulebook for protecting ACA, Medicaid, and partner-entity data — not an optional upgrade to MARS-E. It is how CMS expects Exchanges, Medicaid/CHIP programs, Direct Enrollment entities, and Hub-connected partners to manage security and privacy risk for beneficiary PII and PHI.
It replaced the old standard.
ARC-AMPE superseded MARS-E and the NEE GRC Framework. If an organization previously lived under MARS-E or Enhanced Direct Enrollment security rules, ARC-AMPE is the current obligation. The AE implementation date was March 4, 2026; the DEE date followed in June 2026. After those dates the work is maintenance: a living SSPP, POA&M closure, incident reporting, and annual ATC/ATO renewal.
The data in scope is high-impact.
These systems handle eligibility, enrollment, and often health coverage data tied to the CMS Federal Data Services Hub. A failure is not just an audit finding. It can mean unauthorized disclosure of PII/PHI, loss of Hub connectivity, delayed enrollment, and CMS enforcement. ARC-AMPE exists to keep that pipeline trustworthy.
MARS-E was outdated.
MARS-E sat on NIST SP 800-53 Rev. 4 (withdrawn). ARC-AMPE moves to Rev. 5, folds privacy into the same plan instead of a side appendix, and adds two families MARS-E did not have: PT (PII Processing and Transparency) and SR (Supply Chain Risk Management). The AE catalog grows from roughly 300 controls to 402; DEE is 308. The SSPP also changed from Word to Excel. That is a real program rebuild, not a rename.
CMS wanted risk management, not checkbox GRC.
Volume I is explicit: a purely compliance-based framework stays reactive. ARC-AMPE adds enterprise risk management so organizations identify emerging threats, allocate resources, and protect assets — while still meeting HIPAA, the Privacy Act, FISMA, and ACA rules such as 45 CFR 155.260 / 155.280.
The operational stakes are concrete.
| Change | Why it matters |
|---|---|
| U.S.-only data storage / processing location | Multi-region or offshore cloud patterns can break the baseline |
| One control set for cloud, on-prem, and hybrid | No lighter “cloud path” leftover from MARS-E |
| PT family | Consent, notices, SSN handling, and revocation have to be evidenced |
| SR family | Vendors and Hub partners are in the authorization boundary |
| Annual ATC/ATO | Authority to connect or operate is renewed, not granted once |
| More artifacts at audit | Larger baseline + Excel SSPP means more evidence, not less |
It also creates leverage.
ARC-AMPE is NIST 800-53 Rev. 5. That is the same family as FedRAMP, StateRAMP/GovRAMP, and much of HIPAA/NIST 800-66. Organizations that treat ARC-AMPE as a standalone spreadsheet miss the reciprocity: evidence collected once can support several frameworks. One industry mapping found a FedRAMP Moderate authorization already covers a large share of the 402 AE controls.
Our CMMC Services
ARC-AMPE is important because it is the current CMS condition for running Exchange and Medicaid eligibility systems, it raised the bar after MARS-E fell behind modern NIST and privacy expectations, and losing alignment can cost Hub access and public trust. For a GRC platform, that is why a dedicated module — Volume II SSPP, AE/DEE baselines, PT/SR, POA&M, and maps back to HIPAA and FedRAMP — is the product, not a blog post.
FAQ
ARC-AMPE — Acceptable Risk Controls for ACA, Medicaid, and Partner Entities — is the CMS security and privacy framework that replaced MARS-E and the NEE GRC Framework. Volume I is governance guidance. Volume II is the Excel SSPP and the NIST 800-53 Rev. 5 control baseline used by Administering Entities and select Partner Entities. ACA Administering Entities and select Partner Entities that administer or support Exchange, Medicaid, or CHIP operations, or that connect to the CMS Federal Data Services Hub or process Exchange-related PII. Direct Enrollment Entities follow the DEE baseline. Covered healthcare entities still also have HIPAA obligations; ARC-AMPE is designed to sit alongside HIPAA, FISMA, and the Privacy Act — not replace them. AEs were required to implement ARC-AMPE by March 4, 2026. DEE implementation followed in June 2026. After those dates the obligation is to maintain an accurate SSPP, remediate open POA&M items, report incidents, and renew ATC or ATO authority on the CMS cycle. ARC-AMPE rebases controls on NIST SP 800-53 Revision 5, increases the AE catalog to 402 controls, merges privacy into the same plan, adds the PT and SR families, requires an Excel SSPP instead of Word, and embeds enterprise risk management instead of a purely compliance-checkbox model. Yes. The ARC-AMPE subscription module is built to produce Volume II SSPP output in the Excel format CMS specified, with control implementation statements, evidence links, and POA&M status that stay synchronized as the program changes. Yes. Continuum GRC auto-maps ARC-AMPE to NIST 800-53 Rev. 5, HIPAA / NIST 800-66, FedRAMP, StateRAMP / GovRAMP, SOC 2, ISO 27001 / 27701, and the rest of the 100+ module inventory so one evidence record can satisfy multiple auditors. Yes. Continuum GRC is a FedRAMP Authorized GRC and risk-management platform — a material difference when the data in scope is Exchange PII, PHI, and Hub-connected system evidence.
What is ARC-AMPE?
Who must comply with ARC-AMPE?
What were the CMS compliance dates?
How is ARC-AMPE different from MARS-E?
Does Continuum GRC generate the Excel SSPP?
Can we map ARC-AMPE to HIPAA and FedRAMP?
Is the platform FedRAMP Authorized?
You are just a conversation away from putting the power of Continuum GRC to work for you.
