Authorization program · Last verified
Minimum Acceptable Risk Standards for Exchanges
MARS-E is CMS's security and privacy standard for ACA Administering Entities, built on the CMS Acceptable Risk Safeguards and NIST SP 800-53 Rev 4. It applies to Exchanges, state Medicaid, CHIP and Basic Health Program agencies, required under 45 CFR §§ 155.260 and 155.280.
- Class
- Authorization program
- Owner
- Centers for Medicare & Medicaid Services (CMS)
- Last verified
What it is
CMS describes MARS-E's purpose in its own words: "CMS developed, assembled, and implemented a document suite of guidance, requirements, and templates known as the Minimum Acceptable Risk Standards for Exchanges (MARS-E) in accordance with the Agency's Information Security and Privacy programs. MARS-E provides guidance on the protection of security and privacy in the ACA program environment; addresses the mandates of the ACA, including regulations 45 CFR §§155.260 and 155.280; and applies to all ACA Administering Entities (AE)."
The document suite has four volumes: Volume I (Harmonized Security and Privacy Framework), Volume II (Minimum Acceptable Risk Standards), Volume III (a control catalog) and Volume IV (a System Security Plan template).
The current version verified is Version 2.2, dated 23 February 2021. CMS's own text notes that "Version 2.0 in November 2015 was the most recent major update" — meaning versions after 2.0 are described by CMS itself as revisions rather than a further major update.
Who owns it
MARS-E is developed and issued by the Centers for Medicare & Medicaid Services (CMS).
Who assesses it
How CMS approves or verifies an Administering Entity's conformance with MARS-E — an authorization-to-operate mechanism or otherwise — was not identified in the sources reviewed as of 31 August 2026; not written here pending verification.
Levels
- Volume I — Harmonized Security and Privacy Framework
- Volume II — Minimum Acceptable Risk Standards
- Volume III — Control Catalog
- Volume IV — System Security Plan (SSP) Procedure
Who asks for it
Statutory (scoped). Verified only for ACA Administering Entities — Exchanges (federal or state), state Medicaid agencies, CHIP agencies, and state agencies administering the Basic Health Program — under 45 CFR §§ 155.260 and 155.280.
CMS defines who this applies to in its own footnote: "'Administering Entity' means Exchanges, whether federal or state, state Medicaid agencies, Children's Health Insurance Program (CHIP) agencies, or state agencies administering the Basic Health Program."
Sources
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.