Skip to content

Evidence request lists

MARS-E

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Access Control and Identity Authentication - MARS-E v2.0

MARS-E-Access-Control-Identity-Authentication-NIST-800-63-Identity-Assurance-Levels-MFA-AC-IA-Families
MARS-E Access Control + Identity + Authentication + NIST 800-63 + MFA + AC + IA Families

Implement NIST 800-53 AC Access Control family + IA Identification and Authentication family per MARS-E v2.0 catalog. NIST 800-63-3 Identity Assurance Level 2 (IAL2) + Authenticator Assurance Level 2 (AAL2) + Federation Assurance Level 2 (FAL2) for Exchange consumer authentication + IAL3 + AAL3 for administrative access. Identity proofing via Experian + LexisNexis + manual document review + biometric verification. Multi-Factor Authentication (MFA) mandatory for all administrative access + remote access + privileged operations. Role-Based Access Control (RBAC) with separation of duties (Eligibility Adjudicator + System Administrator + Privacy Officer + Security Officer). Least privilege enforcement. Account management lifecycle (provisioning + recertification + deprovisioning) with quarterly recertification. Privileged Access Management (PAM) with session recording for privileged users. R

Artefacts an auditor will ask for
  • NIST 800-63-3 IAL2 + AAL2 evidence for consumers + IAL3 + AAL3 for admin
  • MFA enforcement evidence (all admin + remote + privileged)
  • RBAC matrix with separation of duties (Eligibility Adjudicator + Sysadmin + Privacy Officer + Security Officer)
  • Quarterly access recertification records
  • Privileged Access Management (PAM) tooling and session recording evidence
  • Federal Data Services Hub + IRS + SSA + DHS trust documentation
Where this commonly fails
  • IAL2/AAL2 identity proofing relies on knowledge-based authentication (KBA) only - non-compliant post NIST 800-63-3 Rev 4
  • MFA not enforced for all admin paths (e.g. break-glass accounts)
  • Quarterly recertification missed
  • PAM session recording not retained 7 years

Audit Accountability and Continuous Monitoring - MARS-E v2.0

MARS-E-Audit-Accountability-Continuous-Monitoring-AU-Family-CM-Family-SIEM-Log-Retention-IRS-Pub-1075
MARS-E Audit + Accountability + Continuous Monitoring + AU + CM Families + SIEM + IRS Pub 1075

Implement NIST 800-53 AU Audit and Accountability family + CM Configuration Management family + Information System Continuous Monitoring (ISCM) program per MARS-E v2.0. Audit events include logon + logoff + privileged operations + access to PII or PHI or FTI + administrative actions + configuration changes + security tool events + suspected unauthorised activity. Audit log retention minimum 90 days online + 7 years offline (1 year HIPAA + 6 years HIPAA-extended + IRS Pub 1075 minimum 6 years + state retention). Centralised SIEM (Security Information and Event Management) with SOC monitoring. Audit log integrity protection via cryptographic hashing + WORM (Write Once Read Many) storage + access restrictions. Configuration management with approved baseline + change control board + drift detection. Continuous monitoring under NIST 800-137 ISCM with monthly reporting to CMS. Vulnerability sc

Artefacts an auditor will ask for
  • Audit event coverage matrix mapped to MARS-E AU-1 to AU-12
  • SIEM correlation rules + 24x7 SOC monitoring evidence
  • Audit log retention proof (90-day online + 7-year offline)
  • Log integrity protection (cryptographic hashing + WORM)
  • Configuration management baseline + change control board records + drift detection
  • Vulnerability scanning records (weekly internal + monthly external)
  • Annual 3PAO assessment report
  • IRS Pub 1075 Section 5 separate FTI audit trail
Where this commonly fails
  • Audit retention under 7 years (IRS Pub 1075 violation)
  • SIEM has no FTI-specific rules
  • Configuration baseline not maintained
  • 3PAO assessment lapsed

Contingency Media Protection System Integrity - MARS-E v2.0

MARS-E-Contingency-Media-Protection-System-Integrity-CP-MP-SI-Families-DR-COOP-Encryption-Sanitization
MARS-E Contingency + Media Protection + System Integrity + CP + MP + SI Families + DR + COOP

Implement NIST 800-53 CP Contingency Planning + MP Media Protection + SI System and Information Integrity families per MARS-E v2.0. Contingency Planning with Business Impact Analysis (BIA) + Recovery Time Objective (RTO) of 24 hours for Exchange consumer-facing systems + 48 hours for administrative + Recovery Point Objective (RPO) of 4 hours. Backup strategy with daily incremental + weekly full + off-site replication + tested restore quarterly. Disaster Recovery (DR) site geographically separated + tested annually full-scale. Continuity of Operations Plan (COOP) for Exchange essential functions during open enrolment + special enrolment periods. Media Protection with media marking + access controls + sanitisation per NIST 800-88 (clear + purge + destroy) + media transport protections + media accountability. Encryption FIPS 140-2 / 140-3 validated cryptographic modules for PII + PHI + FTI

Artefacts an auditor will ask for
  • BIA + RTO 24-hour consumer / 48-hour admin + RPO 4-hour evidence
  • Backup strategy + quarterly restore test logs + off-site replication
  • Annual DR full-scale test report
  • COOP for open enrolment + special enrolment
  • FIPS 140-2/140-3 cryptographic module inventory
  • TLS 1.2+ enforcement (TLS 1.3 preferred) + AES-256 at rest
  • Media sanitisation records per NIST 800-88
  • Flaw remediation SLA evidence (30-day critical + 90-day high)
Where this commonly fails
  • DR test annual but not full-scale
  • FIPS 140 modules expired or end-of-life
  • TLS 1.1 still enabled on some endpoints
  • Critical flaw remediation exceeds 30 days

Cross-Program Coordination - MARS-E v2.0

MARS-E-Cross-Program-Coordination-IRS-Pub-1075-FedRAMP-CMS-ARS-HHS-OIG-Joint-Audit-3PAO
MARS-E Cross-Program + IRS Pub 1075 + FedRAMP + CMS ARS + HHS OIG + Joint Audit + 3PAO

Coordinate MARS-E compliance with adjacent federal programmes and audit regimes. IRS Publication 1075 (Safeguarding Federal Tax Information) compliance for Federal Tax Information (FTI) processing under IRC Section 6103 + Safeguard Procedures Report (SPR) every 6 years + Safeguard Activity Report (SAFER) annually + IRS Safeguard Review (on-site) every 3 years + IRS Office of Safeguards coordination. FedRAMP Moderate Baseline for cloud-hosted Exchange components + Joint Authorization Board (JAB) Provisional ATO or Agency-issued ATO + continuous monitoring through FedRAMP Continuous Monitoring + annual 3PAO assessment + monthly POAM updates. CMS Acceptable Risk Safeguards (ARS) v3.1 / v5.0 alignment for parallel Medicare and Medicaid systems. CMS Cybersecurity and Risk Assessment Program (CRISP) integration. HHS OIG Office of Inspector General oversight authority + GAO Government Accountab

Artefacts an auditor will ask for
  • IRS Pub 1075 Safeguard Procedures Report (SPR) every 6 years + SAFER annual + IRS Safeguard Review every 3 years
  • FedRAMP Moderate ATO (JAB Provisional or Agency-issued) + continuous monitoring evidence
  • CMS ARS v3.1/v5.0 cross-walk
  • HHS OIG audit cooperation records
  • GAO audit response records
  • SBM-to-FFM Data Sharing Agreements + Computer Matching Agreements under Privacy Act 1974
  • State Medicaid + CHIP MOU coordination
  • Joint MARS-E + IRS Pub 1075 + HIPAA + FedRAMP audit calendar
Where this commonly fails
  • IRS SPR overdue
  • FedRAMP ConMon monthly POAM not submitted
  • CMS ARS cross-walk not maintained
  • Computer Matching Agreement (CMA) under Privacy Act not in place

Incident Response and Breach Notification - MARS-E v2.0

MARS-E-Incident-Response-Breach-Notification-IR-Family-45-CFR-164-400-414-IRS-Pub-1075-Notification-CMS-IRT
MARS-E Incident Response + Breach Notification + IR Family + 45 CFR 164.400-414 + IRS Pub 1075 + CMS IRT

Implement NIST 800-53 IR Incident Response family + breach notification process integrated across HIPAA + ACA + IRS Pub 1075. Incident response capability with 24x7 SOC + Computer Security Incident Response Team (CSIRT) + incident response plan + tabletop and live exercises annually. Categorisation per US-CERT incident categories + CMS Incident Response Team (IRT) coordination + DHS/CISA reporting for major incidents. HIPAA Breach Notification Rule 45 CFR 164.400-414 (60 days to affected individuals + 60 days to HHS + media notification if 500+ residents in state). Risk Assessment (Acquisition + Unauthorised Access + Disposition + Identification) for PHI breaches per HHS guidance. ACA Section 1411 breach notification to CMS + affected consumers. IRS Pub 1075 Section 10 incident reporting (within 1 hour for known + 24 hours for suspected disclosure of FTI). State breach notification law c

Artefacts an auditor will ask for
  • Incident Response Plan + tabletop and live exercise records (annual)
  • 24x7 SOC + CSIRT structure documentation
  • HIPAA breach notification 60-day timeline evidence (individuals + HHS + media)
  • ACA Section 1411 CMS breach notification process + CMS IRT coordination protocol
  • IRS Pub 1075 Section 10 incident reporting (1-hour known + 24-hour suspected)
  • State breach notification compliance matrix (47 states + DC)
  • DHS/CISA reporting for major incidents
  • Post-incident review and lessons learned
Where this commonly fails
  • No IRS Pub 1075 1-hour reporting workflow
  • Multi-state notification not pre-mapped
  • CMS IRT escalation contact stale
  • Annual tabletop not conducted

Privacy PII PHI Protection - MARS-E v2.0

MARS-E-Privacy-PII-PHI-Minimum-Necessary-HIPAA-Privacy-Rule-NIST-800-122-45-CFR-164-Subpart-E
MARS-E Privacy + PII + PHI + Minimum Necessary + HIPAA Privacy Rule + NIST 800-122 + 45 CFR 164 Subpart E

Protect Personally Identifiable Information (PII) and Protected Health Information (PHI) handled by Exchanges. Apply NIST 800-122 PII Confidentiality Impact Level determination + minimum necessary standard for use disclosure and request + HIPAA Privacy Rule 45 CFR 164 Subpart E (Privacy of Individually Identifiable Health Information) where applicable + ACA Section 1411 information requirements + 45 CFR 155.260(a)(3) privacy and security requirements. Implement notice of privacy practices for Exchange consumers. Honor opt-out and choice mechanisms. De-identification under HIPAA Safe Harbor or Expert Determination. Limited Data Set procedures with Data Use Agreements. Tax Filing Status disclosure restrictions. Beneficiary consent for information sharing across Exchange + Medicaid + CHIP + plan issuers. Strict controls for sharing with Federal Data Services Hub. Annual privacy training. Pr

Artefacts an auditor will ask for
  • Notice of Privacy Practices for Exchange consumers
  • PII/PHI inventory + Confidentiality Impact Level per NIST 800-122
  • Minimum necessary standard documentation per use disclosure and request
  • Privacy Officer designation + Privacy Impact Assessment per OMB M-03-22 + CMS PIA template
  • De-identification procedures (Safe Harbor + Expert Determination)
  • Data Use Agreements for Limited Data Sets
  • Annual privacy training records
Where this commonly fails
  • NIST 800-122 PII confidentiality impact level not determined
  • No CMS PIA on file
  • Limited Data Set procedures missing for research uses
  • Privacy training not annual or not all-hands

Scope and Authority - MARS-E v2.0

MARS-E-Scope-CMS-CCIIO-ACA-Section-1311-Federal-Facilitated-State-Based-Marketplace-Exchange-45-CFR-155-260
MARS-E Scope + CMS + CCIIO + ACA Section 1311 + Marketplace + 45 CFR 155.260

Establish MARS-E applicability scope for ACA Affordable Care Act Section 1311 Health Insurance Exchanges. CMS Centers for Medicare and Medicaid Services + CCIIO Center for Consumer Information and Insurance Oversight under HHS Department of Health and Human Services is the issuing and oversight authority. Required for all State-Based Marketplaces (SBM) + State-Based Exchanges on Federal Platform (SBE-FP) + Federally-Facilitated Marketplace (FFM) HealthCare.gov + Exchange agents and brokers + non-Exchange entities receiving Exchange data. 45 CFR 155.260 Privacy and Security Standards + 45 CFR 155.270 Use of Standards and Protocols for Electronic Transactions + 45 CFR 155.280 Oversight and Monitoring. ACA Section 1311(d)(4)(B) + Section 1411 + Section 1412 + Section 1413 statutory anchors. CMS Federal Data Services Hub interface authorization required. State Medicaid Modernization projects

Artefacts an auditor will ask for
  • MARS-E applicability assessment + Exchange categorisation (SBM + SBE-FP + FFM)
  • CMS Federal Data Services Hub Interconnection Security Agreement (ISA)
  • Authorization to Operate (ATO) Letter + System Security Plan (SSP) + Security Assessment Report (SAR) + Plan of Action and Milestones (POAM)
  • 45 CFR 155.260 / 155.270 / 155.280 compliance evidence
  • State Medicaid Modernization MARS-E cross-walk where applicable
Where this commonly fails
  • No ATO letter or expired
  • Federal Data Services Hub ISA not refreshed
  • v2.0 to v2.2 upgrade gap analysis missing
  • State Medicaid Modernization scope not assessed

Security Control Catalog NIST 800-53 Moderate Baseline - MARS-E v2.0

MARS-E-NIST-800-53-Moderate-Baseline-Catalog-v2-0-Volume-III-Tailoring-Risk-Assessment-Categorization
MARS-E NIST 800-53 Moderate Baseline + MARS-E Catalog Volume III + Tailoring + Risk Assessment + Categorization

Implement the MARS-E v2.0 Volume III Catalog of Minimum Acceptable Risk Security and Privacy Controls aligned with NIST 800-53 Moderate Baseline. FIPS 199 Security Categorization with Confidentiality Moderate + Integrity Moderate + Availability Moderate as default for Exchange systems. NIST 800-37 Risk Management Framework (RMF) 7-step process (Prepare + Categorize + Select + Implement + Assess + Authorize + Monitor). NIST 800-30 Risk Assessment + NIST 800-39 Risk Management. CMS-specific tailoring with MARS-E supplemental controls + parameter values + privacy controls overlay (Appendix J Privacy Control Families AP + AR + DI + DM + IP + SE + TR + UL based on NIST 800-53 Appendix J or NIST 800-53 Rev 5 integrated privacy). Coordination with CMS Acceptable Risk Safeguards (ARS) v3.1 + v5.0 for Medicare and Medicaid systems + FedRAMP Moderate Baseline for cloud-hosted Exchange components.

Artefacts an auditor will ask for
  • MARS-E v2.0 Volume III Catalog implementation matrix with NIST 800-53 Moderate Baseline tailoring
  • NIST 800-37 RMF 7-step process evidence (Prepare + Categorize + Select + Implement + Assess + Authorize + Monitor)
  • FIPS 199 Security Categorization documentation (C-Mod + I-Mod + A-Mod default)
  • Risk Assessment per NIST 800-30 + Risk Treatment Plan
  • CMS ARS cross-walk for hybrid systems
  • FedRAMP Moderate Baseline alignment evidence for cloud components
Where this commonly fails
  • FIPS 199 categorization not refreshed annually
  • MARS-E v2.0 catalog not fully implemented (POAM-driven)
  • FedRAMP Moderate alignment claimed but not 3PAO-attested
  • Risk Treatment Plan not board-approved
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the MARS-E framework page.