Scrutineer.ai
All posts
Cost

ARC-AMPE compliance cost and timeline

CMS charges nothing for ARC-AMPE. What the MARS-E 2.2 migration really costs, the control baselines by entity type, and what a missed deadline changes.

By the Scrutineer team

September 2026 · 8 min read

Try it while you read

No account, nothing to install.

Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.

The Scrutiny Desk

Illustrative sample · not an audit attestation

CMS charges nothing for ARC-AMPE. There is no program fee, no application fee and no assessor paid to CMS, because CMS reviews your artifacts itself and then makes a risk-informed decision about your connection to the Data Services Hub. So the entire cost is internal, and it lands in four places: mapping a MARS-E 2.2 control set onto a NIST SP 800-53 Revision 5 baseline, closing what the gap analysis finds, paying an independent assessor to test it, and carrying continuous monitoring afterwards. Both implementation deadlines have now passed, which changes what you are buying.

How much does ARC-AMPE compliance cost?

Nobody publishes a credible number, and the ones that circulate come from consultancies pricing their own delivery against a scope you do not share. We are not going to invent one. What genuinely moves your figure is below, and the largest driver is not the control count at all. It is how much of the 402 or 308 controls your existing MARS-E program already evidences, and how many systems sit inside the boundary you drew.

Cost driverAdministering EntityDirect Enrollment EntityWhat moves the number
Paid to CMSNothingNothingCMS reviews artifacts directly. There is no CMS-charged assessment fee
Minimum control baseline402 controls (reported)308 controls (reported)Both are floors. Volume I requires you to assess your own environment for additional controls
Control mapping effortRevision 4 to Revision 5 re-mapping across the whole baselineHow much of the old MARS-E evidence is current, dated and attributable rather than screenshots in a folder
Systems in the boundaryEvery system that touches the Hub connection or consumer PIIThe single largest lever. 402 controls applied to a smaller boundary is a fundamentally cheaper program
Security Assessment WorkbookRequiredNot requiredVolume I footnotes the SAW as an ACA AE document only, which DEEs routinely build anyway
Independent assessorTesting behind the Security Assessment ReportWhether the assessor is re-testing controls or discovering them, which is a function of your evidence discipline
Penetration testRequired artifact, on the cadence in your ISCM guideBoundary size and the number of externally reachable interfaces
Ongoing monitoringContinuous, not annualCMS requires ISCM results rather than a point-in-time assessment, so this is a permanent operating cost

Boundary is the line worth pausing on. Every federal-style control baseline prices by scope, and scope is the one input you still control after the framework is chosen. Before you cost the controls, it is worth stepping outside the compliance question entirely to know what you are actually running and what each system costs, because systems nobody can justify are systems you can move out of scope, and every one of those removes 402 controls' worth of evidence work in a single decision.

Is MARS-E still the framework I have to comply with?

No. This is the part that catches teams out, and it is stated plainly in the primary document rather than inferred. ARC-AMPE Volume I says that ARC-AMPE "supersedes and replaces MARS-E and the NEE GRC Framework effective upon publication." Version 1.0 published on 4 March 2025. MARS-E 2.2 has therefore not been the governing standard for eighteen months.

Two frameworks died at once. MARS-E governed ACA Administering Entities and the separate NEE GRC Framework governed Non-Exchange Entities. ARC-AMPE merged them into a single document with a tailorable overlay, which is why guidance written for a state Exchange and guidance written for a web-broker no longer come from different places.

When was the ARC-AMPE deadline?

There were two and both have passed:

  • Administering Entities: 4 March 2026. One year after publication. This covers the FFE, State-based Exchanges, SBE-FPs and state Medicaid, CHIP and Basic Health Program agencies.
  • Direct Enrollment Entities: end of June 2026. This covers Classic and Primary EDE entities, and the issuers and web-brokers that host or modify an EDE environment.

If you are reading this in the second half of 2026 and are not there, you have not lost the connection. You have changed what you are negotiating. Authorization is a risk-informed decision CMS makes on your artifacts, and CMS explicitly verifies that outstanding findings, risks, vulnerabilities and issues have been resolved or mitigated. The instrument that carries a late entity is the Plan of Actions and Milestones, with real owners and real dates against it. That shifts your spend from evidence production toward remediation and toward the credibility of the plan itself.

Why the control count is the wrong first question

Almost every published guide to this framework opens with two numbers and two dates. Neither tells you whether you are in scope, and being wrong about scope is more expensive than being wrong about anything else on this page.

ARC-AMPE Volume I splits its users across two tables. Table 2 is mandatory implementation of the Volume II control set. Table 3 is strongly recommended but not mandated. Three role names appear in both tables, and what decides which side you fall on is a technical detail of how you are built rather than what you call yourself:

  • A hybrid issuer upstream EDE entity that implements single sign-on outside the Primary EDE entity's approved environment is in the mandatory table. The identical entity without single sign-on is in the recommended table.
  • A hybrid non-issuer upstream EDE entity that adds functionality beyond minor branding changes is mandatory. One that only changes branding is a white-label user in the recommended table.
  • A service provider whose services enable ACA functions, income verification and healthcare coverage verification being the examples CMS gives, is mandatory. A service provider performing non-ACA work such as dispute resolution is in the recommended table.

That last pair is where vendors get it wrong most often, because the job title on both sides of the line is the same two words. If you sell services into this ecosystem, settle which row you occupy before you price anything, and write down the technical fact that put you there so the answer survives the next staff change. The ARC-AMPE compliance software we build records that determination alongside the control mapping for exactly this reason.

What does the assessor actually test?

Your assessor tests what your artifacts claim. Volume I gives a non-exhaustive list of fourteen documents CMS reviews before authorizing a connection, and the split between them explains where compliance budgets really go.

Seven are technical products of your security program: the System Security and Privacy Plan (which is ARC-AMPE Volume II itself), the Information System Risk Assessment, the Security Assessment Plan, the Security Assessment Report, the POA&M, the Privacy Impact Assessment and penetration test results. Add the Risk Acceptance form and the Security Assessment Workbook, the latter for Administering Entities only.

The rest are signed legal instruments: the Interconnection Security Agreement, a Data Use Agreement, an Information Exchange Agreement, a Computer Matching Agreement, an MOU or MOA, and a Change Notification form. The ISA is the one that matters most, because it is where authorization is documented. It establishes the Authority to Connect for Administering Entities and the Request to Connect for Non-Exchange Entities. Guidance written for a state Exchange describes the ATC path and will not match a vendor's, which is a small distinction that costs real weeks when you follow the wrong runbook.

How long does an ARC-AMPE migration take?

CMS gave the sector twelve months between publication and the AE deadline, and fifteen to the DEE deadline. That is the honest planning benchmark, and the sector broadly did not meet it. The work does not divide evenly across those months either. Mapping a Revision 4 control set onto Revision 5 is fast and mostly mechanical. Discovering that half your evidence is undated, unattributed or collected once a year is slow, and it is the part that determines everything after it.

The reason we push the evidence layer first is that it does not decay between submissions. CMS requires continuous monitoring output rather than a point-in-time result, so an entity that assembles evidence in the fortnight before a submission is buying the same work twice a year forever. Read-only connections to the cloud, identity and ticketing systems already in place collect most of the artifacts behind a Revision 5 baseline without anybody assembling anything.

Does ARC-AMPE replace our HIPAA obligations?

No, and Volume I is careful about this. It says ARC-AMPE includes technical controls that may facilitate adherence to the HIPAA Security, Privacy and Breach Notification rules. That is assistance, not substitution. It also matters in the other direction: many of the entities in Table 3, including state health agencies on non-ACA work and healthcare organizations accessing consumer PII, are covered entities or business associates whose actual binding obligation is HIPAA. For them ARC-AMPE is an informative reference, and a considerably more specific one than the Security Rule provides on its own. The overlap is large enough that the same evidence should serve both, which is the argument for holding one control library rather than two programs. Our HIPAA compliance software and the ARC-AMPE mapping run off the same control set for that reason.

Where ARC-AMPE sits against the other federal baselines

If your organization also sells to federal agencies you will be carrying more than one of these, and they are not interchangeable even though they descend from the same NIST catalog. ARC-AMPE governs Exchanges, Medicaid agencies and their partner entities. FISMA binds federal executive branch agencies and those operating systems on their behalf, and reaches state agencies only through program terms. The CMS Acceptable Risk Safeguards catalog, currently version 5.2, is the CMS-internal baseline applied to CMS systems, not to you. The names are close enough that entities do occasionally buy against the wrong catalog, so check which one your agreement actually names.

Where the frameworks genuinely help each other is evidence. A Revision 5 control implemented once should answer for ARC-AMPE, for HIPAA and for a customer's SOC 2 question at the same time, and if it does not, the cost you are measuring is not the framework's. It is duplication. Our note on compliance automation software pricing covers what the platforms in this space charge and which costs are never in the quote.

What to do first if you are behind

Settle scope, then evidence, then controls. In that order, because the first decision changes the size of the other two.

  1. Confirm your table. Table 2 or Table 3 of Volume I, and the specific technical fact that puts you there. Write it down.
  2. Draw the boundary honestly and then shrink it. Every system you can move out of scope removes a full baseline's worth of evidence work.
  3. Inventory what your MARS-E program already proves. Most of it transfers under a different control identifier. Re-mapping is far cheaper than re-testing.
  4. Build the POA&M before the assessor does. A late entity with a credible, owned, dated plan is in a different conversation from one presenting a list of open findings.
  5. Automate collection, not judgment. Artifact gathering, mapping and monitoring output are repeatable. Scoping, risk acceptance and the CMS decision are not.

Scrutineer holds the control library and the evidence behind it, tracks the open items your POA&M has to carry, and reuses the same artifacts across HIPAA, SOC 2 and ISO 27001. We prepare readiness evidence. We do not act as your independent assessor, and CMS grants the connection.

See Scrutineer scrutinize your posture

Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.

Scrutinize on real evidence, not stale spreadsheets

Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and scores vendor risk continuously, and returns a readiness report with a prioritized gap list. AI scrutinizes, you decide.

Automated evidence · Per-control statuses · Prioritized gap list

Mapped controls · evidence-linked rationale for every status · an accredited auditor issues the attestation.