FISMA compliance requirements come down to a repeatable process: rate each federal information system by the harm a breach would cause, apply the NIST security controls that match that rating, document everything in a System Security Plan, get a senior official to sign an Authorization to Operate, and then monitor the system continuously for as long as it runs. The Federal Information Security Modernization Act sets these obligations for federal executive branch agencies, and it reaches private companies through their contracts whenever they handle federal information on an agency’s behalf.1Congress.gov. Federal Information Security Modernization Act of 2014
Who the Requirements Apply To
Every federal executive branch agency is covered. Under 44 U.S.C. § 3554, each agency head is personally responsible for protecting the information the agency collects and any system the agency uses or has a contractor operate on its behalf.2Office of the Law Revision Counsel. 44 USC 3554 – Federal Agency Responsibilities That “on behalf of” language is what pulls contractors in. If your company processes, stores, or transmits federal data under a government contract, FISMA obligations flow to you through the contract.
The Federal Acquisition Regulation reinforces the chain. FAR clause 52.204-21 requires contractors handling federal contract information to implement specific safeguards, and it extends those requirements to subcontractors.3Acquisition.GOV. 52.204-21 Basic Safeguarding of Covered Contractor Information Systems State agencies that administer federal programs may face related requirements when their systems connect to federal data, but the statute itself is written around federal agencies and their contractors rather than state governments directly.
The Seven-Step Risk Management Framework
FISMA is not a checklist you finish. Compliance follows the NIST Risk Management Framework, a cycle that agencies and contractors work through continuously:4National Institute of Standards and Technology. NIST Risk Management Framework
- Prepare. Establish the organizational context, resources, and strategy for managing security and privacy risk before any technical work begins.
- Categorize. Classify the system based on the damage a breach would cause, using FIPS 199.
- Select. Choose the appropriate security controls from NIST SP 800-53 for that risk category.
- Implement. Put those controls in place and document exactly how each one is deployed.
- Assess. Test whether the controls work and actually produce the intended results.
- Authorize. A senior official reviews the whole package and makes a risk-based decision on whether to let the system operate.
- Monitor. Continuously watch for new vulnerabilities, changing threats, and failing controls after authorization.
Each step feeds the next, and the cycle repeats. New risks discovered during monitoring loop back to earlier steps rather than ending the process.
Categorizing the System Under FIPS 199
The second step is where compliance work starts to bite. FIPS 199 rates every system on three dimensions: confidentiality, integrity, and availability.5Computer Security Resource Center. FIPS 199 – Standards for Security Categorization of Federal Information and Information Systems Each dimension gets its own impact rating:
- Low impact. A breach would cause limited harm to the organization or to individuals.
- Moderate impact. A breach could cause serious damage, including significant financial loss or harm to people.
- High impact. A breach could be catastrophic, potentially threatening human life or national security.
The overall classification uses the “high water mark” rule: the system’s final impact level equals the highest of the three ratings.6National Institute of Standards and Technology. FIPS 199 – Standards for Security Categorization of Federal Information and Information Systems A system rated low for confidentiality, low for availability, and moderate for integrity is treated as moderate-impact overall. This categorization drives how many controls you need and how rigorously you have to implement them, so underrating a system builds the rest of the security program on a flawed foundation.
Selecting and Implementing Security Controls
Two companion standards govern what protections a categorized system needs. FIPS 200 sets the minimum security requirements every federal system must meet, covering areas like access control, incident response, and risk assessment.7National Institute of Standards and Technology. FIPS 200 – Minimum Security Requirements for Federal Information and Information Systems NIST Special Publication 800-53 Revision 5 provides the detailed control catalog, organized into 20 families that range from Access Control and Identification and Authentication through Supply Chain Risk Management and PII Processing and Transparency.8National Institute of Standards and Technology. NIST SP 800-53 Rev 5 – Security and Privacy Controls for Information Systems and Organizations
Nobody implements every control in the catalog. You select a baseline set matched to your FIPS 199 impact level, then tailor it to your specific environment. A high-impact system at a defense agency implements far more controls, and implements them more stringently, than a low-impact internal scheduling tool.
NIST SP 800-171 for Contractors Handling CUI
Contractors that handle Controlled Unclassified Information face a parallel standard. NIST SP 800-171 adapts the 800-53 requirements for nonfederal systems that process or store CUI.9National Institute of Standards and Technology. NIST SP 800-171 Rev 3 – Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations The practical distinction: if you operate a system on behalf of an agency, expect full 800-53 controls; if you handle CUI on your own corporate systems, 800-171 is usually the governing standard. Many contractors deal with both.
The Documentation You Have to Produce
Proving compliance is fundamentally a documentation exercise. Assessors and authorizing officials look for evidence that controls are planned, implemented, tested, and working. Four core pieces make up the package.
The System Security Plan (SSP) is the centerpiece. NIST SP 800-18 describes it as a document that provides an overview of the system’s security requirements, describes the controls in place or planned, defines the system boundary, and explains how the system connects to others.10National Institute of Standards and Technology. SP 800-18 Rev 1 – Guide for Developing Security Plans for Federal Information Systems For each 800-53 control the system requires, the SSP explains how your organization satisfies it. A high-impact SSP can run hundreds of pages.
A risk assessment identifies vulnerabilities and evaluates the likelihood and impact of potential threats, feeding directly into which controls need strengthening. Alongside it, an accurate system inventory of hardware, software, and information systems inside the security boundary is required. You cannot protect what you have not identified, and auditors look for completeness.
The Plan of Action and Milestones (POA&M) tracks every known weakness and spells out what will be done to fix it, who is responsible, and when. It is a living document; new vulnerabilities get added as they surface and remediated items move to closed. Authorizing officials read the POA&M closely because it shows honest risk posture.
Getting an Authorization to Operate
Once the SSP, risk assessment, POA&M, and supporting evidence are compiled, the system enters the formal Authorization to Operate process. A designated authorizing official, typically a senior executive, reviews the entire package and makes a risk-based judgment on whether the residual risk is acceptable. If it is, the official signs the ATO and the system can process government data.11Centers for Medicare and Medicaid Services. Authorization to Operate (ATO)
An ATO is not permanent. Many agencies require reauthorization every three years or whenever a major change occurs to the system.12General Services Administration. Authorization to Operate – Preparing Your Agencys Information System The timeline from initial gap analysis to a signed ATO runs into months of planning, testing, and documentation. Organizations that wait until a contract award to start security work routinely find themselves behind schedule.
Continuous Monitoring and Annual Reporting
Compliance does not stop at authorization. The 2014 modernization act made continuous monitoring a central obligation, moving away from the older model of once-a-year point-in-time assessments.13National Institute of Standards and Technology. Federal Information Security Modernization Act NIST SP 800-137 defines information security continuous monitoring as maintaining ongoing awareness of vulnerabilities, threats, and control effectiveness to support real-time risk decisions.14National Institute of Standards and Technology. NIST SP 800-137 – Information Security Continuous Monitoring for Federal Information Systems and Organizations
In practice, that means automated vulnerability scans, security log review, POA&M tracking, and reassessment of controls on an ongoing schedule. CISA supports federal agencies through its Continuous Diagnostics and Mitigation program, which provides dashboards aggregating vulnerability data, identity and access status, and network risk scores.15Cybersecurity and Infrastructure Security Agency. Continuous Diagnostics and Mitigation (CDM) Training
Reporting runs on an annual cycle. Under 44 U.S.C. § 3553(c), the OMB Director, in consultation with the Secretary of Homeland Security, submits a report to Congress by March 1 each year on the effectiveness of federal information security, including incident summaries and evaluation results.16Office of the Law Revision Counsel. 44 USC 3553 – Authority and Functions of the Director and the Secretary Individual agencies also submit annual reports to OMB and Congress summarizing their own security posture, incident history, and evaluation results.17U.S. General Services Administration. IT Security Procedural Guide – Federal Information Security Modernization Act (FISMA) Implementation Process
Cloud Services: Where FedRAMP Takes Over
If the system in question is a cloud service, FISMA’s requirements are delivered through FedRAMP. FedRAMP is mandatory for all executive agency cloud deployments and builds on the same NIST 800-53 controls, with a standardized assessment process that lets one certification be reused across agencies.18FedRAMP.gov. Is FedRAMP Mandatory A cloud service provider pursuing federal work should treat FedRAMP authorization as the operational path to satisfying FISMA in that environment.
What Happens If You Don’t Comply
For federal agencies, the consequences are primarily reputational and operational: poor FISMA results get reported to Congress and can trigger increased OMB oversight, budget scrutiny, and binding directives from CISA. For contractors, the stakes are more immediately financial. Failure to meet security requirements can lead to termination of the contract that imposed those obligations in the first place.
Beyond a single lost contract, contractors face potential suspension or debarment under FAR Subpart 9.4, which bars them from bidding on future federal work.19Acquisition.GOV. FAR Subpart 9.4 – Debarment, Suspension, and Ineligibility For a company whose revenue depends on government contracts, debarment is effectively a business-ending outcome. Even short of that, a publicized security failure costs future competitive bids.