FISMA
What is FISMA?
FISMA is the Federal Information Security Modernization Act of 2014 (Public Law 113-283), amending the Federal Information Security Management Act of 2002 + codified at 44 USC Chapter 35 Subchapter II (sections 3551-3559). FISMA is the US federal statutory framework for information security applying to all federal agencies (excluding national-security systems covered separately) + contractors operating systems on behalf of federal agencies. It comprises 12 controls organised across 7 domains, and applies in the United States.
How FISMA maps to other frameworks
All 12 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 7 domains FISMA groups its controls into
Frameworks that share controls with FISMA
Each of these has at least one control mapped to a control in FISMA. The number is how many FISMA controls are shared, counted from the mapping graph.
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
3 shared controlsUS Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
3 shared controlsUS EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
3 shared controlsUK Defence Standard 05-138 - Cyber Security for Defence Suppliers
3 shared controlsTEFCA - Trusted Exchange Framework and Common Agreement
3 shared controlsProtective Security Policy Framework (PSPF) Release 2024
3 shared controlsPrivacy Act 1988 (Australia)
3 shared controlsPCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
3 shared controlsWhere FISMA overlaps with the standards you already hold
Where to get trained on FISMA
4 courses in the catalogue cover FISMA directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
What FISMA means in your sector
What FISMA means for your job
Questions people ask about FISMA
What is FISMA?
How many controls does FISMA have?
Where does FISMA apply?
What frameworks does FISMA map to?
How do I get started with FISMA compliance?
Query FISMA programmatically
FISMA, its 12 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
FISMA API reference and MCP config →What FISMA requires, control by control
Each page carries the requirement text for one FISMA control and what an assessor expects to see as evidence.
- FISMA-3554-AGENCY-RESPONSIBILITIES Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting
- FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda
- FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200
How ready are you for FISMA?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.