All articlesCompliance

ARC-AMPE's Second Deadline: Why Most Organizations Still Are Not Ready

March 24, 20268 min readMaverc Technologies · Risk & Compliance Advisory
ComplianceGovernmentVulnerabilitiesCloud Security
ARC-AMPE's Second Deadline: Why Most Organizations Still Are Not Ready

The first ARC-AMPE deadline came and went, and assessors spent the weeks leading up to it flagging the same gaps over and over. Direct Enrollment entities and partner organizations are next, and they are repeating the mistakes the administering entities just made. Here is what keeps going wrong and how to get ahead of it.

Share

The first ARC-AMPE deadline has passed, and the honest summary is that a lot of organizations were not ready for it.

CMS published ARC-AMPE, the Acceptable Risk Controls for ACA, Medicaid, and Partner Entities, about a year ago as the replacement for MARS-E. Administering entities, meaning state-based marketplaces and Medicaid agencies, were the first group on the clock. In the weeks leading up to that date, assessors were openly flagging readiness gaps across the board. Not edge cases. The same handful of problems, showing up in package after package.

Now the second wave is forming. Direct Enrollment entities, web brokers, issuers, and the vendors that sit behind them all have their own compliance date coming, and from what we are seeing, most of them are following the identical path that just tripped up the agencies ahead of them. That is the frustrating part. The failure modes are already documented. Nobody needs to discover them again.

Why "we already did MARS-E" is the wrong starting point

The most common assumption we hear is that ARC-AMPE is basically MARS-E with a new cover page. It is not.

MARS-E was built on NIST SP 800-53 Revision 4, a catalog written in 2013. ARC-AMPE rebases the whole program on Revision 5. Rev 5 reorganized control families, retired and renumbered controls, rewrote many of them in outcome-based language, and pulled privacy out of a side appendix into the core catalog. On top of that, ARC-AMPE merges what used to be separate security and privacy tracks into a single unified plan, and it introduces two control families that have no MARS-E ancestor at all: PII processing and transparency, and supply chain risk management.

The practical translation is that your existing control narratives are not evidence of anything until you have checked each one against its Rev 5 equivalent. Plenty of them changed meaning. A control that used to ask whether you had a policy now asks whether you can demonstrate an outcome. Copying forward the old language produces a package that looks finished and then falls apart the first time an assessor asks for proof.

The five gaps assessors keep finding

Across the first wave, the findings clustered. If you are in the second group, assume you have at least three of these right now.

The crosswalk was never actually done. Teams mapped the easy controls, assumed the rest carried over, and never separated "unchanged" from "restated" from "no equivalent." That third bucket is where the real work lives, and it stays invisible until someone reads the package closely.

Privacy has no owner. Under MARS-E, privacy often sat with general counsel or program integrity while security sat with IT. Two calendars, two evidence sets, two sets of assumptions. ARC-AMPE requires one plan with one accountable owner. Most organizations have not made that decision, and the gap surfaces during fieldwork instead of during planning.

Supply chain is treated as a questionnaire. The new SR family is not a vendor survey. It reaches into acquisition language, component documentation, and provenance expectations, which means procurement has to change its templates. In state government and in large issuers, procurement does not report to security and does not move quickly. If that conversation has not started, the deadline is already at risk.

PII handling was scoped as policy work. The PT family lands squarely in the application and data layer. Inventory of what you collect, minimization, classification across storage, retention enforcement, disclosure tracking, field-level protection for identifiers like SSNs. That is engineering work on a release calendar. A memo does not satisfy it.

Continuous monitoring is a quarterly scan wearing a costume. ARC-AMPE expects a functioning continuous monitoring program for both security and privacy. A quarterly vulnerability scan plus an annual review is not that, and an assessor reading Rev 5 language will say so plainly.

What the first wave should have taught everyone

Two lessons are worth stealing outright.

The first is that inherited controls are your biggest lever, and almost nobody sorts for them early enough. Because ARC-AMPE and FedRAMP share the same underlying catalog, a meaningful share of your controls can be satisfied by your cloud provider's existing authorization. Physical and environmental protection, most of media protection, and large parts of the infrastructure families come down to citing provider artifacts rather than building anything. Sort every control into provider-inherited, shared, and fully yours before you estimate a single hour of effort. Skipping that step is how organizations end up planning to implement four hundred controls from scratch and then running out of runway in month two.

The second is that the plan format itself is a work item. The move from a narrative document to a structured workbook changes how evidence is referenced and maintained. Teams that leave the format conversion for the end reliably lose weeks to it, right when they have the least slack.

A realistic sequence if you are in the second wave

Start with a real crosswalk, and let it produce a gap list rather than a reassurance. Every control gets one of three labels: carried forward as-is, carried forward with changed intent, or no equivalent. Only the last two consume budget.

Decide governance in writing next. One owner for the unified plan, one evidence repository, one assessment calendar. This costs nothing and unblocks everything downstream.

Then run three workstreams in parallel rather than in sequence, because they depend on different teams. Engineering takes PT: data inventory, classification, retention, and field-level protections. Procurement takes SR: contract language, vendor requirements, component documentation. Security operations takes continuous monitoring, and the goal there is specific. Configure your posture management tooling to evaluate against NIST 800-53 Rev 5 so that findings come out labeled with the same control identifiers your assessor will reference. Evidence that already speaks the assessor's dialect removes an entire translation layer from the assessment, and translation layers are where authorization timelines die.

Finally, do a dry run before fieldwork. Pick fifteen controls at random, weighted toward PT and SR, and have someone outside the compliance team try to produce the evidence. Whatever they cannot find in an afternoon is what the assessor will find too.

The part nobody wants to hear

Missing the date is not the real risk. The real risk is submitting a package that looks complete, passing the internal review, and then failing fieldwork on the two families nobody owned. That outcome costs more than a delay, because it burns the assessor relationship and the remediation window at the same time.

The organizations that got through the first deadline cleanly were not the ones with the largest budgets. They were the ones that separated inherited controls from owned controls early, named a single accountable owner for the unified plan, and put privacy and supply chain on engineering and procurement calendars instead of compliance ones.

Maverc supports state agencies, issuers, and their integrators through exactly this work: Rev 5 control crosswalks, plan reconstruction in the required structure, continuous monitoring architecture, and assessment readiness for systems handling beneficiary data at scale. If your ARC-AMPE gap assessment is still a set of assumptions, we can turn it into a defensible plan before your date arrives.

Share