To become a CMS Access Manager, you create an account on the CMS Enterprise Portal, complete Remote Identity Proofing, and submit an Access Manager role request tied to your organization’s Legal Business Name, Tax Identification Number, and National Provider Identifier. The request is either auto-approved against your organization’s PECOS enrollment, approved by your Authorized Official, or approved by External User Services after you supply IRS documentation.1Centers for Medicare & Medicaid Services. Identity and Access Frequently Asked Questions
What the Access Manager Role Actually Is
The CMS Identity & Access system uses three organizational tiers. The Authorized Official (AO) is the person with legal authority to bind the organization and is the only role that can designate an Access Manager. The Access Manager (AM) handles day-to-day user management: inviting and managing Staff End Users, initiating or accepting surrogacy connections, and working in PECOS on the employer’s behalf. Staff End Users are individual contributors with no management authority.
One limit worth knowing before you request the role: an Access Manager cannot manage other Access Managers. Adding a second AM is always the AO’s job.2Centers for Medicare & Medicaid Services. Identity and Access System Quick Reference Guide
CMS recommends that the individuals designated as AO and AM in the I&A system be the same people identified in those roles on the organization’s PECOS enrollment. Aligning the two lets the system verify authority automatically and unlocks the fastest approval path.1Centers for Medicare & Medicaid Services. Identity and Access Frequently Asked Questions
What to Have Ready Before You Start
Missing any of the items below will stall the process, so gather them before you log in.
For identity verification, you need your legal name, date of birth, Social Security number, personal email address, home address, and personal mobile phone number. The combination of first name, last name, and email must be unique in the system, and your SSN cannot already be attached to another account.3Centers for Medicare & Medicaid Services. Quick Start Remote Identity Proofing (RIDP) User Guide If you live outside the United States, you cannot complete identity proofing online and will need to contact the application help desk.
For the role request itself, you need three organizational identifiers:
- Legal Business Name, exactly as registered with the IRS. Even small discrepancies, like an ampersand where the IRS record has “and,” will trigger a mismatch.
- Tax Identification Number used for federal filings.
- Ten-digit National Provider Identifier assigned through NPPES.
If your organization already has an approved Medicare enrollment in PECOS with your name attached as an Access Manager, keep the enrollment confirmation nearby. The system cross-references PECOS records when it decides how to route your request.1Centers for Medicare & Medicaid Services. Identity and Access Frequently Asked Questions
Create Your CMS Enterprise Portal Account
Go to portal.cms.gov and select the new user registration link. You will pick a user ID of at least six characters that contains at least one letter and does not include your SSN or nine consecutive digits, and a password of eight to twenty characters with at least one uppercase letter, one lowercase letter, and one number. Choose three security questions for account recovery.4Centers for Medicare & Medicaid Services. Enterprise Identity Data Management (EIDM) Account and Role Set Up
After registration, the portal walks you through Remote Identity Proofing (RIDP). Accept the terms, enter your personal information, and the data is checked in real time against Experian records. A successful match returns a confirmation that identity proofing is complete. A failure, most often caused by an address or name that doesn’t match credit records, cannot be retried with the same information. Contact the help desk for the alternative verification process.3Centers for Medicare & Medicaid Services. Quick Start Remote Identity Proofing (RIDP) User Guide
Set Up Multi-Factor Authentication
Before you can request the role, register at least one MFA device. The IDM system supports email one-time passwords, SMS text messages, interactive voice response phone calls, Google Authenticator, Okta Verify, YubiKey hardware tokens, and, for federal employees and some contractors, PIV cards.5Centers for Medicare & Medicaid Services. Identity Management (IDM) User Guide Email, text, and IVR options double as recovery methods, so registering at least one of those three is a practical safeguard against being locked out later.
Submit the Access Manager Role Request
Log into the portal and open the access catalog, either through “My Access” in the drop-down next to your name or through “Request Access Now.” Find the application you need, typically PECOS or the I&A system, and select “Request Access.”6Centers for Medicare & Medicaid Services. CMS Enterprise Identity Management (EIDM) User Guide
On the role selection screen, choose Access Manager from the drop-down. The system asks for your business contact information and the organizational identifiers you gathered earlier. Required fields are marked with an asterisk. Enter a short reason for the request, such as “Designated by AO to manage staff access for [Organization Name],” and select Submit.
A review screen displays everything you entered. Check it carefully. A wrong digit in the TIN or NPI will bounce the request. Select Submit once more, and the system returns a tracking number and confirms that you will receive an email when the request has been processed.6Centers for Medicare & Medicaid Services. CMS Enterprise Identity Management (EIDM) User Guide
How Your Request Gets Approved
Three approval paths exist, and the one that applies depends on your organization’s enrollment status.
- PECOS auto-approval. If your name already appears as an Access Manager on an approved Medicare enrollment record in PECOS, the system verifies this automatically. No human review is required, and PECOS access itself becomes available within about three hours after approval.
- Authorized Official approval. If you are not on the PECOS enrollment but your organization’s AO has a portal account, the AO receives a notification and approves your request from their IDM dashboard.
- External User Services approval. If neither auto-approval nor AO approval is available, you submit IRS documentation, such as a CP 575 notice or equivalent, to EUS to prove your authority. This path involves manual review and takes longer.1Centers for Medicare & Medicaid Services. Identity and Access Frequently Asked Questions
If your name is later removed from the PECOS enrollment or the enrollment is revoked, your I&A role can be deactivated along with it.
What You Can Do Once Approved
Approval unlocks an I&A management dashboard where you can invite Staff End Users, view and modify what each staff user can access, disassociate a user entirely through the “No Access” option, initiate or accept surrogacy connections that let your organization act on behalf of other providers, and work in PECOS on behalf of your employer and any providers your organization surrogates for.2Centers for Medicare & Medicaid Services. Identity and Access System Quick Reference Guide
Keeping the Role: Annual Recertification
CMS security policy requires annual recertification of every IDM role. For programmatically approved roles, meaning the ones verified against PECOS data, the certification due date is June 1st each year. Other roles are recertified on the anniversary of the original approval or the prior year’s certification.5Centers for Medicare & Medicaid Services. Identity Management (IDM) User Guide
The approver, typically your AO, confirms in IDM that you still need the role. If the approver misses the deadline, the role is automatically revoked. There is no shortcut to reinstate a lapsed certification; you go through the full role request process again. Set a calendar reminder at least 30 days before your due date. The recertification itself takes minutes. Losing the role because nobody clicked the button takes weeks to fix.
What You Are Attesting To
Submitting the Access Manager role request is a certification that you have authority to legally bind your organization and manage its CMS system access. False information on a CMS certification carries consequences under multiple federal statutes.
Under 18 U.S.C. § 1001, knowingly making a false statement to a federal agency is punishable by a fine and up to five years in prison.7Office of the Law Revision Counsel. United States Code Title 18 Section 1001 Section 1128B(a)(1) of the Social Security Act adds a penalty of up to $25,000 and five years’ imprisonment for false statements in connection with federal healthcare benefits. The Civil False Claims Act, 31 U.S.C. § 3729, imposes civil liability of three times the government’s damages plus a per-violation penalty that has been adjusted upward from the original statutory range for inflation.8Office of the Law Revision Counsel. United States Code Title 31 Section 3729 A false certification can also result in exclusion from Medicare and Medicaid participation.
Common Snags
Identity Proofing Fails
RIDP fails most often when the name or address you entered doesn’t match Experian’s records. A recent move, a legal name change, or a thin credit file can all cause it. You cannot resubmit the same information after a failed attempt. Contact the application help desk for the alternative verification path.3Centers for Medicare & Medicaid Services. Quick Start Remote Identity Proofing (RIDP) User Guide
Your Request Sits in Pending Status
If auto-approval doesn’t apply and your AO hasn’t acted, the request waits in their queue. Contact your AO directly. The system sends a notification, but it is easy to lose among other portal alerts. If your organization has no AO with an active portal account, plan on the EUS documentation path instead.
You Lose Your PECOS Enrollment Status
Because the AM role is tied to PECOS, a revocation, termination, or removal of your name from the enrollment can deactivate your I&A role.1Centers for Medicare & Medicaid Services. Identity and Access Frequently Asked Questions Fix the enrollment issue in PECOS first, then re-request the role through the portal.