HomeGlossaryFederal Information Security Modernization Act (FISMA)
Compliance & SecurityFISMA

Federal Information Security Modernization Act (FISMA)

FISMA is the federal law requiring government agencies to develop, document, and implement information security programs protecting federal information systems and data.

Quick answer

FISMA is the federal law requiring government agencies to develop, document, and implement information security programs protecting federal information systems and data.


The Federal Information Security Modernization Act (FISMA) of 2014 is the primary US federal law governing information security for federal agencies, establishing requirements for protecting federal information and information systems and creating accountability for agency security programs.

What is FISMA?

FISMA updated the original Federal Information Security Management Act of 2002 (also called FISMA), modernizing the framework to emphasize continuous monitoring over periodic point-in-time assessments. The law applies directly to federal agencies and, by extension, to contractors who operate information systems on behalf of federal agencies or who connect their systems to federal networks.

Under FISMA, each federal agency must implement an information security program based on NIST standards - primarily NIST SP 800-53 for control selection, NIST SP 800-37 for the Risk Management Framework, and NIST FIPS 199/200 for system categorization. The program must include security categorization of all agency systems using a High/Moderate/Low impact scale, implementation of appropriate security controls from NIST SP 800-53, annual testing and evaluation of those controls, incident reporting and response capability, and annual reporting to OMB and Congress on the agency's security posture.

For contractors, FISMA's practical impact comes through contract requirements. When a contractor operates a federal information system - such as a cloud service, a managed network, or a data center holding government information - the agency's FISMA obligations flow down through contract clauses requiring the contractor to implement FISMA-compliant security controls, undergo independent assessments, obtain an Authority to Operate (ATO), and participate in the agency's continuous monitoring program. FISMA compliance for contractor-operated systems is assessed as part of the overall agency FISMA posture.

Why FISMA matters for government contractors

Contractors who operate federal information systems on behalf of agencies face FISMA-derived obligations that are as stringent as those faced by the agencies themselves. A contractor managing a federal agency's data center or operating an agency's IT systems must implement NIST SP 800-53 controls appropriate for the system's impact level, undergo assessment by an independent assessor, and obtain an ATO before the system can go live. Failure to meet FISMA requirements can result in the ATO being revoked, the contractor being directed to remediate findings, and potential contract termination if security posture is deemed unacceptable.

Example

An IT services company wins a contract to manage the Department of Labor's enterprise email and collaboration platform. The system is categorized as FISMA Moderate under FIPS 199 because unauthorized disclosure of some employee information and labor market data could have serious consequences. The contractor implements the NIST SP 800-53 Moderate baseline controls, engages an independent assessor (an Authorized Testing Organization) to conduct a Security Assessment Report (SAR), addresses findings with a POA&M, and submits an authorization package to the agency's Authorizing Official (AO). The AO issues an Authority to Operate at the Moderate level. The contractor's security team provides continuous monitoring data to the agency's security operations center monthly and undergoes annual FISMA assessment reviews.

Frequently Asked Questions

Is FISMA the same as FedRAMP?


No, though they share the same underlying NIST security control framework. FISMA applies to federal agencies and their operated or contractor-operated systems. FedRAMP is a specific program for cloud services that creates a government-wide authorization process - a cloud service authorized under FedRAMP satisfies agency FISMA requirements for that cloud service without requiring each agency to conduct its own separate assessment. FedRAMP is essentially a FISMA compliance mechanism specifically for cloud services.

What is an Authority to Operate and how does it relate to FISMA?


An Authority to Operate (ATO) is the formal decision by an agency Authorizing Official (AO) that a system's security posture is acceptable and the system is authorized to operate. ATOs are required by FISMA for all federal information systems and contractor-operated systems processing federal data. An ATO has a defined scope, conditions, and typically a three-year duration after which reauthorization is required. Operating a system without an ATO is a FISMA violation.

What are annual FISMA reporting requirements for agencies and how do contractors fit in?


FISMA requires agencies to report annually to OMB and Congress on their information security posture, including the status of all agency systems (including contractor-operated ones) against security control requirements. Contractors provide their security assessment results and continuous monitoring data to agencies, which aggregate this information in their annual FISMA reporting. Poor contractor security performance can affect an agency's overall FISMA scores, creating strong incentives for agencies to hold contractors accountable for security posture.

Does FISMA apply to grants and assistance recipients?


FISMA applies to federal information systems, which are defined as systems operated by federal agencies or on their behalf. Grant recipients who receive federal funds but do not operate systems on behalf of the federal agency are generally not directly subject to FISMA. However, grant programs involving federal data or systems may include FISMA-like security requirements in the grant terms and conditions. Cooperative agreements, where the government is substantially involved in the work, are more likely to include FISMA-derived security requirements.

How Bidovate helps

Bidovate puts Federal Information Security Modernization Act (FISMA) to work inside your capture and proposal workflow.

Federal contracting

See Bidovate in action

Book a demo and we will show you the platform using your actual contract data.