What Is FISMA (Federal Information Security Modernization Act)?

Also called: Federal Information Security Management Act

Related problems: A federal agency contract says our system must comply with FISMA; We operate a system on behalf of an agency and need an authority to operate; Not sure how FISMA, FedRAMP and NIST requirements fit together

The Federal Information Security Modernization Act (FISMA) is the US federal law that requires federal agencies to protect their information and information systems through a risk-based security program. It covers systems an agency runs itself and systems used or operated by contractors on its behalf. The 2014 law amended the earlier Federal Information Security Management Act of 2002, and both are commonly called FISMA. For IT buyers and providers, FISMA matters mostly through contracts: if you build, host or run a system for a federal agency, you will likely inherit FISMA-based security requirements. This entry is general information, not legal advice; confirm requirements with the contracting agency or counsel.

At a glance

  • FISMA applies to federal agencies and to systems contractors operate for them.
  • It relies on NIST standards and guidelines for how systems are categorized, secured, assessed and authorized.
  • Each system is categorized as Low, Moderate or High impact, which sets its baseline of controls.
  • Systems receive an agency authorization to operate (ATO); there is no FISMA certification.
  • Agencies report on their security programs and on major incidents to oversight bodies and Congress.

What problem it solves

Federal agencies hold enormous amounts of sensitive information and depend on thousands of systems, many built or run by contractors. Without a common legal framework, security would vary widely from one agency to another, and no one would be clearly accountable.

FISMA sets that framework. It makes agency leaders responsible for information security, requires a documented, risk-based program, and creates oversight through central agencies and inspectors general. For contractors, it means federal customers ask for consistent, well-documented security rather than ad hoc assurances.

How it works

Categorize. Each system is categorized by the potential impact of a loss of confidentiality, integrity or availability.

Select and implement controls. Controls are drawn from NIST’s federal security control catalog, tailored to the system’s impact level.

Assess. Independent assessors test whether controls are in place and working.

Authorize. A senior agency official reviews the results and risks and decides whether to grant an ATO.

Monitor and report. Systems are monitored continuously, incidents are reported, and agencies report on their programs each year, with independent evaluation by inspectors general.

Cloud services. For cloud, agencies generally rely on FedRAMP to standardize the assessment, then make their own authorization decision.

Impact levels and roles

FISMA does not certify vendors in tiers. Its closest structures are the impact level assigned to each system and the roles involved, summarized here in general terms.

Level or role What it covers How it is decided or validated Typical evidence
Low impact Systems where a breach would have limited adverse effect Agency categorization; baseline controls assessed System security plan, assessment, ATO
Moderate impact Systems where a breach would have serious adverse effect Agency categorization; larger control baseline assessed System security plan, assessment, ATO
High impact Systems where a breach would have severe or catastrophic effect Agency categorization; most extensive baseline assessed System security plan, assessment, ATO
Agency Owns the system’s risk and the ATO decision Agency leadership and authorizing official ATO letter and continuous monitoring
Contractor Builds or operates a system on the agency’s behalf Contract terms and agency assessment Security documentation and monitoring reports
Oversight bodies Set policy, guidance and operational directives, and evaluate programs OMB, CISA, NIST and inspectors general, each in its role Policy, directives, standards, annual evaluations

When it matters for buyers

  • When you run a system for a federal agency. Expect contract clauses requiring FISMA-aligned controls and an ATO.
  • When you choose cloud services for a federal workload. FedRAMP status is usually the starting point.
  • When a provider claims “FISMA compliant”. Ask which system, which impact level and which agency granted the ATO.
  • When you are a subcontractor. Requirements may flow down from the prime contract.
  • When you build a security program. NIST guidance used under FISMA is a common reference for others too.

Our governance, risk and compliance overview covers advisors and platforms that manage control documentation and assessments.

Questions to ask vendors

  • Which systems or services hold an agency ATO, at which impact level, and from which agency?
  • Do you hold FedRAMP status for the cloud services involved, and for which exact offering?
  • Which controls do you implement, and which remain our responsibility?
  • How do you report incidents to us, and how quickly?
  • Can you support continuous monitoring and annual reporting requirements in our contract?

How it differs from FedRAMP

FISMA is a law that applies to agencies’ information systems in general. FedRAMP is a program operating within that broader framework that standardizes the security assessment of cloud services so agencies can reuse it. FedRAMP status supports an agency’s FISMA decision but does not replace it. State and local buyers may use GovRAMP instead. Contractors that hold federal information on their own systems, rather than operating a system for an agency, are more often measured against NIST Special Publication 800-171, while the NIST Cybersecurity Framework (NIST CSF) is voluntary guidance for any organization. A risk assessment and a GRC platform are common tools for managing all of them.

Frequently Asked Questions

Does FISMA apply to private companies?
Not to private companies' own systems in general. It applies to federal agencies and to information systems used or operated by contractors on an agency's behalf. A contractor running a system for an agency is typically expected to meet the agency's FISMA-based requirements, as set out in the contract.
Is there a FISMA certification?
No. Compliance shows up as an agency's authorization to operate (ATO) for a specific system, based on an assessment of its controls. A provider may say a system has an agency ATO at a given impact level.
How is FISMA related to FedRAMP?
FISMA requires agencies to secure their systems, including cloud services they use. FedRAMP is the government-wide program that standardizes the security assessment of cloud services so agencies can reuse it when making their own FISMA-based decisions.
What is the difference between FISMA 2002 and FISMA 2014?
The 2002 law was the Federal Information Security Management Act. The 2014 Federal Information Security Modernization Act amended it, updating oversight roles and incident reporting. Both are commonly called FISMA.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.